The tools behind the work —
and what you can use today
Compliance work that is implemented rather than reported needs tooling, so we built our own. Each one below says plainly what it is and how you can use it right now — including the one that is still a pilot.
Compliance platform
Your obligations, your evidence, your documents — in one place
Availability
Free regulatory profile · full workspace with an engagement
Create an account and find out which regulations apply to your business and which do not, at no cost. Take an engagement and the same workspace carries the obligations, the evidence and the documents your auditors and customers ask for.
- ·Regulatory profile — what applies to you, what does not, and what would trigger it
- ·Obligation tracker with per-item status and evidence notes
- ·CERT-In incident reporting with a live six-hour countdown and a real send path
- ·Document pack — policies, notices and procedures, downloadable as QMS-ready PDFs
- ·Risk register and a dated, client-visible verification page
Security scanner
See what an attacker sees, before you talk to anyone
Availability
Free · no account needed
Point it at a website or a repository and it reports what is exposed. No signup for the summary; a work email gets you the full report.
- ·Website scan — TLS, security headers, DNS, SPF/DKIM/DMARC, exposed services
- ·Code scan — dependency and secret findings across a repository
- ·Cookie and tracker audit mapped to DPDP consent obligations
- ·Accessibility checks against WCAG 2.1 Level A
- ·DPDP readiness graded against the Act and the 2025 Rules, with the operative section cited
Kaitara Monitor
On requestEndpoint and server telemetry, retained in India
Availability
Pilot — stood up per engagement
A monitoring stack built from permissively-licensed parts, so it can run in your own cloud account or on your own hardware rather than shipping your telemetry to a vendor. It is stood up per engagement; there is no shared service to sign up for.
- ·Threat detection across endpoints, servers and cloud
- ·File-integrity monitoring
- ·180-day log retention within Indian jurisdiction, per CERT-In Direction 20(3)/2022
- ·Detection rules mapped to CERT-In reportable incidents and DPDP breach signals
- ·Runs on any Linux host you control — your AWS, Azure or GCP account, your own hardware, or hosted by us
How these fit with an engagement
The scanner and the regulatory profile are free, and you can use both without talking to us. Everything past that — the implementation, the documents, the evidence, a monitoring pilot — is delivered as a fixed-fee engagement, and the platform is where that work lands. We do not sell the tooling on its own.