DPDP. CERT-In.
RBI. SEBI. One GRC Platform.

Governance, risk and compliance on one control library for banks, NBFCs, insurers, listed companies and IT services firms. Hosted in India, in your private VPC or on-premises.

Already in use with regulated organisations in India · Live in weeks to months

India’s Rulebook Just Got Longer.

A listed bank in Mumbai can answer to the RBI, SEBI, CERT-In and the Data Protection Board, often for the same incident and on different clocks: six hours for CERT-In today, 72 hours for a detailed DPDP breach report once the Rules fully apply, and whatever your own board expects by morning.

Most teams still stitch this together with spreadsheets, email trails and a tool that only covers IT controls. Governance and enterprise risk stay manual. Keep your advisors; give them one platform to work from.

LockThreat maps your obligations once, tests your controls continuously, and gives your board one current view of risk.

The Clock Is Running.

Already in force
CERT-In & SEBI CSCRF
CERT-In’s 6-hour reporting; CSCRF for SEBI-regulated entities.
13 Nov 2025
DPDP Rules Notified
Data Protection Board provisions in force.
2026
RBI & IRDAI Reset Cyber Rules
IRDAI guidelines (April) and RBI Directions (31 July) replace older rules.
13 Nov 2026
Consent Managers
DPDP Consent Manager provisions take effect.
13 May 2027
Full DPDP Obligations
Core duties apply, with penalties up to ₹250 crore.

Built for India’s Most Regulated Sectors

Banks & NBFCs

RBI’s 2026 Cybersecurity Directions and outsourcing rules.

Capital Markets

SEBI CSCRF controls, cyber audits and incident reporting.

Insurers

IRDAI’s 2026 guidelines, mapped to ISO 27001.

Listed Companies

Board risk oversight; RMC rules for the top 1,000 listed firms.

Healthcare

DPDP and ABDM health-data obligations.

IT & Services Exporters

DPDP at home; ISO 27001, SOC 2 and GDPR for clients abroad.

Spreadsheets and IT-Only Tools Leave agap
Regulators Will Find.

Legacy Enterprise
GRC
Compliance-First Tools
LockThreat
Indian Frameworks
Custom build
Limited sector depth
DPDP, RBI, SEBI, IRDAI
GRC Depth
Full G+R+C
Compliance only
Full G+R+C
Deployment
Complex to configure
Typically SaaS only
SaaS in India, VPC, on-prem
Cross-Framework Mapping
Consultant-heavy
IT controls only
Test once, map across frameworks
Continuous Monitoring
Limited or none
IT & cyber only
Enterprise-wide
AI Governance
Separate add-on
Limited
Built-in, incl. agentic AI
Time to Value
12–18 months
Weeks, compliance only
Weeks to months
Indian Frameworks
Legacy Enterprise GRC
Custom build
Compliance-First Tools
Limited sector depth
LockThreat
DPDP, RBI, SEBI, IRDAI
GRC Depth
Legacy Enterprise GRC
Full G+R+C
Compliance-First Tools
Compliance only
LockThreat
Full G+R+C
Deployment
Legacy Enterprise GRC
Complex to configure
Compliance-First Tools
Typically SaaS only
LockThreat
SaaS in India, VPC, on-prem
Cross-Framework Mapping
Legacy Enterprise GRC
Consultant-heavy
Compliance-First Tools
IT controls only
LockThreat
Test once, map across frameworks
Continuous Monitoring
Legacy Enterprise GRC
Limited or none
Compliance-First Tools
IT & cyber only
LockThreat
Enterprise-wide
AI Governance
Legacy Enterprise GRC
Separate add-on
Compliance-First Tools
Limited
LockThreat
Built-in, incl. agentic AI
Time to Value
Legacy Enterprise GRC
12–18 months
Compliance-First Tools
Weeks, compliance only
LockThreat
Weeks to months

Frameworks for India

Mapped to one control library, so a control tested once serves every framework it supports. Tracking something not listed? Ask us.

Categories
No frameworks match your search.

Data Protection

Digital Personal Data Protection Act, 2023 (DPDPA)
Digital Personal Data Protection Rules, 2025
IT Act, 2000 & SPDI Rules, 2011 (SPDI until 13 May 2027)
ABDM Health Data Management Policy
ISO/IEC 27701
GDPR (General Data Protection Regulation)

Cyber & Critical Infrastructure

CERT-In Directions, 2022 (6-hour incident reporting)
NCIIPC Guidelines for Critical Information Infrastructure
NIST CSF 2.0
CIS Critical Security Controls
ISO 22301

Banking, Markets & Insurance

RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026
RBI Digital Payment Security Controls Directions, 2026
RBI Managing Risks in Outsourcing Directions, 2025
RBI payment-data localisation requirements
SEBI Cybersecurity & Cyber Resilience Framework (CSCRF), 2024
IRDAI Information & Cyber Security Guidelines, 2026
PCI DSS
SWIFT Customer Security Programme

Corporate Governance & Risk

Companies Act, 2013: Board risk oversight & internal financial controls
SEBI LODR Regulations: Risk Management Committee
ISO 31000
COSO (Committee of Sponsoring Organizations)

Global Standards

ISO 27001:2022
ISO/IEC 27018
CSA CCM (Cloud Controls Matrix)
ISO/IEC 20000-1

AI Governance

India AI Governance Guidelines (MeitY)
ISO/IEC 42001 (AI Management System)
NIST AI Risk Management Framework (NIST AI RMF)
OWASP Top 10 for LLM Applications
EU AI Act
The Risk Nobody’s Governing

Your teams are already using AI on customer and employee data. Under the DPDP Act, you’ll be accountable for it. Do you know which AI tools and agents are breaching your controls?

AI Security & Governance Flow

Your Data. Stays in India.

Indian regulators increasingly expect sensitive data to stay onshore, from RBI’s rules on storing payment system data in India to CERT-In’s requirement to keep ICT logs within Indian jurisdiction for 180 days.

Choose how LockThreat runs: managed SaaS hosted in India, your own private VPC, or on-premises in your data centre. The same full G+R+C depth, regardless of deployment.

SaaS
Managed by us. Hosted in India.
Private VPC
Your cloud. Your region.
On-Premises
Fully within your walls.

One Platform for the Whole Buying Committee

Blue shield icon with a white award ribbon symbol featuring a star in the center.Vertical flowchart with four outlined circles connected by dotted lines in dark blue, beige, and light blue colors.
CISO
  • CERT-In, RBI and SEBI evidence collected continuously, not the week before an inspection.
  • Third-party and outsourcing risk tracked alongside your own controls.
Line drawing of a human head and upper torso facing forward with a large dark blue dot near the brain area and a smaller bright blue dot near the upper chest.
DPO & Chief Compliance Officer
  • DPDP obligations mapped to controls, with breach timelines tracked in incident response workflows.
  • Policies and gap analysis generated against the frameworks you answer to.
Line art icon with a stylized head and shoulders and three floating dots above representing communication or connection.
CRO & Risk Management Committee
  • Risk quantified in financial terms with FAIR modelling and Monte Carlo simulation.
  • One enterprise risk register across business units and locations.
Two overlapping blue circles connected by a black diagonal line on a white background.
Internal Audit & Company Secretary
  • An audit trail for internal financial controls.
  • Board and committee reporting drawn from live data, not spreadsheets.
Outline of a person’s head and shoulders with a blue circle above representing the mind or focus.

Everything Enterprise GRC Should Have Been.

True GRC Depth

Most GRC tools deliver compliance, with governance and risk as an afterthought.

Here, governance comes first: the policies that move your business forward, the controls that contain risk across every department, and the compliance that follows naturally from both.

No spreadsheets. No disconnected tools. No point-in-time snapshots. One centralised, ongoing view of your organisation’s risk and compliance posture.

GRC for Everyone

Your regulatory obligations don’t respect org charts or geographies.

Every department, from finance, legal and HR to operations, cyber and IT, managed in one place, without the sprawl.

The locations you operate in, from Mumbai, Bengaluru and Gurugram to Hyderabad, Chennai and your offices worldwide, managed in one place without adding more tools.

AI Governance & Security

Which AI tools are your employees using? Are they approved? Are they handling personal data your DPDP notices and consents don’t cover?

And when AI agents act autonomously, accessing systems, making decisions, breaching controls, who’s watching? Now you are.

From shadow AI discovery and ISO/IEC 42001 alignment to real-time prompt protection and agentic control enforcement, reported directly into your GRC framework.

Risk Clarity

Every stakeholder needs a different view of the same risk reality, from one source of truth.

Express risk in financial terms your Board, CFO and Risk Management Committee can act on, using FAIR modelling and Monte Carlo simulation.

Detailed enough for the analyst, clear enough for the CRO and the CISO, compelling enough for the Board.

Continuous Assurance

Compliance in India isn’t an annual exercise; it’s an ongoing operating requirement.

LockThreat validates that your controls are working, right now, across cloud infrastructure, cyber endpoints and enterprise applications.

Far less scrambling for evidence before an RBI inspection, a SEBI cyber audit or an ISO surveillance audit.

Framework Convergence

Map DPDP, CERT-In, RBI, SEBI CSCRF and IRDAI to ISO 27001, ISO 27701, SOC 2, PCI DSS and NIST, and to each other, eliminating redundant work.

Tie everything to your own policy library and control framework, so governance becomes a living system, not a compliance filing cabinet.

Fast Time to Value

Enterprise GRC depth without the 18-month implementation. Up and running in weeks to months, on the technology stack you already have.

Implemented and supported by our in-region team and partners.

Already running another GRC platform? Run LockThreat alongside it during transition, no rip-and-replace required.

What GRC Leaders Say

LockThreat gave our team a single pane of glass across every framework we manage. What used to take weeks of manual mapping now happens automatically. Our clients see faster results and our consultants can focus on higher-value work.

Managing Director
Big-4 Professional Services Firm

We evaluated a lot of GRC tools and nothing came close to LockThreat’s combination of breadth across governance, risk and compliance, combined with AI automation and ease of use. Our team was up and running quickly, and the cross-framework mapping alone saved us hundreds of hours.

VP of Security & Risk
CirrusLabs

The real-time evidence validation and risk dashboards gave our leadership team the visibility they needed without burdening our security team. LockThreat just works.

Head of GRC
Octave

Compliance across multiple international standards used to be a serious resource drain. LockThreat unified everything into one platform and eliminated the spreadsheet chaos entirely. It’s been a game-changer for our team.

Director of Risk & Compliance
World’s Most Sustainable City

LockThreat fits perfectly into an agile environment. Controls and policies evolve alongside our work. It’s not a static compliance checkbox, it’s a living system that keeps up with our pace.

VP of Security
Agile Trailblazers

Connects to Your Existing Stack

See LockThreat on Your Indian Frameworks

A focused 30-minute walkthrough, plus pricing for your deployment. No generic pitch, no obligation.

Tell us which regulators and frameworks you answer to (DPDP, CERT-In, RBI, SEBI, IRDAI) and how you want to deploy. We’ll tailor the session to your programme.

  1. A 30-minute walkthrough on your frameworks, following your priorities.
  2. Your deployment path: SaaS hosted in India, private VPC or on-premises.
  3. Pricing for your scope, based on your entities, frameworks and deployment model.

Delivered by our in-region team and partners. Prefer email? info@lockthreat.com