Engagement models
Three ways to work with us.
Fixed scope, fixed timeline, one point of contact. Every engagement starts with a scoping call, not a price list.
Starter
DPDP Gap Assessment
Understand your current exposure before spending on remediation. A structured audit of where you stand against all 8 DPDP obligations.
2–4 weeks
- Data inventory & flow mapping
- Consent & notice mechanism review
- Data principal rights check
- Security controls baseline
- Cross-border transfer analysis
- Prioritised gap report
- Executive brief (board-ready)
Most Popular
DPDP Readiness + VAPT
Close the gaps and prove it. VAPT on your primary application combined with full DPDP compliance remediation — issued with a certificate.
6–10 weeks
- Everything in Gap Assessment
- Full VAPT — web, API, mobile
- Remediation support & re-test
- DPDP-compliant privacy policy
- Data Processing Agreement templates
- Breach notification runbook
- Certificate of DPDP Readiness
Ongoing
Continuous Compliance Retainer
Stay compliant as DPDP rules evolve. Monthly coverage, rules monitoring, and priority incident response — so you never fall out of compliance.
Monthly
- Quarterly re-test of all findings
- DPDP rules monitoring & alerts
- New vendor / data flow reviews
- Annual full re-assessment
- Priority breach response (72hr)
- Annual certificate renewal
All engagements include a signed Authorization Letter, NDA, and Rules of Engagement before any testing begins.
Every quote is fixed-fee, scoped to your application complexity, team size, and cloud footprint — talk to us for a number.