Compliance & Risk
Residency · —
Online

GRC & Risk Management

🇮🇳 India Compliance Hub
Built for the five regulators that matter in India: CERT-In (6-hour incident mandate), DPDP Act 2023 (full compliance 2027-05-13), RBI (2–6h by severity), SEBI CSCRF (quarterly reports), IRDAI (24-hour window). Pick a regulator below to open its tools.
Posture — your tenant
Live across all 5 regulators. Click any tile to open its tools.
Loading regulator posture…
CERT-In
6-hour
Report cyber incidents to CERT-In within 6 hours of detection. Escalation engine nudges via WhatsApp/email; submission only on your explicit approval.
Open tools →
DPDP Act 2023
2027 full
Rules notified 2025-11-13. Scan forms, consent, notices, SDF checklist, DSAR queue, data-flow diagram.
Open tools →
RBI
2/4/6h
Cyber incident reporter (severity-based window) + NBFC controls picker by layer.
Open tools →
SEBI
CSCRF
Quarterly CSCRF report draft for market intermediaries — VAPT, CCI, audit findings.
Open tools →
IRDAI
24-hour
24-hour incident countdown + draft report for gro@irdai.gov.in.
Open tools →
CERT-In · 6-hour incident mandate
Rule 12, CERT-In Directions 2022 · incident@cert-in.org.in

Active CERT-In Incident

Live from /aegis/comply/certin/incident/{id}
Escalation timeline — the escalation engine fires each step once when a channel and recipient are configured; otherwise the step is recorded as skipped with the reason. Submission to CERT-In always requires your explicit approval (one-tap link or Submit).
Bind an incident to see per-step status.

Retention & Jurisdiction Proof

Loading retention position from /aegis/comply/certin/retention

Open Incidents

  • Loading from /aegis/comply/certin/incidents
Click any incident to bind its 6-hour clock + auto-draft Annexure-II.

Open a New Incident · 6-hour clock starts immediately

Annexure-II Draft

Click an open incident or create a new one to generate the Annexure-II draft.
DPDP Act 2023 · Scanners & Inventory
Rules notified 2025-11-13 · Full compliance deadline 2027-05-13

Live DPDP Scanners

Roadmap
DPDP URL scanners (forms / consent / notice / children) — coming after first BFSI pilot signs. The DPDP §8(6) breach drafter below (POST /aegis/comply/actions/execute, action_type=draft_dpdp_breach_report) is real and grounded in the DPDP Act with an LLM. The URL-scanner rule sets need pilot validation against a real Data Fiduciary's consent UX before we ship them.

Data Inventory · Record of Processing (DPDP §5)

Loading from /aegis/comply/dpdp/inventory
Add new record

Data Subject Access Requests (DSAR)

Loading DSAR queue…
New DSAR

Personal Data Breach Report · DPDP §8(6)

SDF Checklist (Significant Data Fiduciary)

Loading from /aegis/comply/dpdp/sdf

Data-Flow Diagram (Mermaid)

graph LR will appear here
RBI · Cyber Incident Reporter
2h / 4h / 6h by severity · cyberincident@rbi.org.in

Draft Incident Report

Roadmap
RBI 2h/4h/6h incident drafter — coming after first BFSI pilot signs. The DPDP §8 and CERT-In Rule 12 LLM drafters (POST /aegis/comply/actions/execute) prove the pattern. RBI-specific report format requires validation against a live RBI-regulated entity's CISO workflow before we ship it.

NBFC Controls

Loading applicable controls…
SEBI · CSCRF Quarterly Report
Cyber Security & Cyber Resilience Framework · market intermediaries

Quarterly Report Draft

Roadmap
SEBI CSCRF quarterly drafter — coming after first market-intermediary pilot signs. The DPDP §8 and CERT-In Rule 12 LLM drafters (POST /aegis/comply/actions/execute) prove the pattern. CSCRF report format (VAPT / CCI / audit findings) needs validation with a real stockbroker / AMC / KRA before shipping.
IRDAI · 24-Hour Incident Window
Insurance Regulatory & Development Authority · gro@irdai.gov.in

Countdown Clock

Green >12h · Amber 6–12h · Red <6h · Breached = past deadline. (24h window)

Incident Draft · gro@irdai.gov.in

Fills the IRDAI incident-report template from the fields below. Nothing is sent to IRDAI — Aria produces the draft and the missing-field list; a human reviews and files it.
Uses the “Detected at” timestamp from the countdown above.
Fill the fields and click “Draft IRDAI report”.
👆 Click any regulator card above to open its tools.
All data is live from the backend. Empty states mean the endpoint is unavailable — no fabricated numbers.

Compliance Calendar — all India regulators

Loading milestones…

Evidence Vault — immutable ledger

Every compliance action writes an immutable row here — audit-ready for CERT-In / DPDP / RBI reviewers.
Loading evidence ledger…

Framework & Controls

Evidence Checklist

Organization Details

Security Posture Evidence

FAIR Scenario Parameters

ROADMAP Target capabilities — not live data. Aria's live, real compliance workflow is the 🇮🇳 India Compliance tab (CERT-In / DPDP drafting + filing). The governance controls below are on the roadmap; none renders customer data yet.

📚 Governance & Risk-Management — roadmap (T370–T378)

The governance layer Aria is building toward. Each row is a planned control, not an implemented one — no numbers here are measured from your environment.

IDCapabilityIntentState
T370Control-framework mappingOne evidence set mapped across ISO 27001 / SOC 2 / PCI / DPDPPLANNED
T371Evidence automationAuto-collect screenshots/JSON/logs, link to control IDs, track expiryPLANNED
T372IR retainer trackingIncident-response retainer + escalation contacts on filePLANNED
T373Cyber-insurance postureMap controls to policy requirements + renewal readinessPLANNED
T374Tabletop + playbook libraryReusable exercise scenarios + response playbooksPLANNED
T375Third-party risk (TPRM)Vendor tiering, security-review tracking, questionnaire workflowPLANNED
T376Breach-notification workflowPer-regulator deadline clocks + materiality decision treePARTIAL — live for India (CERT-In 6h) in the India tab
T377Policy libraryVersioned policies mapped to controls with attestationPLANNED
T378Privacy / DSR handlingData-subject-request intake + fulfilment (DPDP / GDPR)PLANNED
ROADMAP Target capabilities — not live data. Security-program & culture practices Aria is building toward. Nothing here is measured from your organisation.

🎓 Program & Culture — roadmap (T410–T416)

Culture beats controls. These are the program practices Aria intends to operationalise; each is planned, not implemented.

IDPracticeIntentState
T410Quarterly tabletopExec-attended scenario exercises on a cadencePLANNED
T411Annual full-simulationEnd-to-end incident simulation once a yearPLANNED
T412Blameless post-mortem5-whys + owned action items per incidentPLANNED
T413Skill matrix + retentionTrack team capabilities + coverage gapsPLANNED
T414ISAC membershipSector threat-sharing participationPLANNED
T415Bug-bounty / VDPVulnerability-disclosure program intakePLANNED
T416Internal red-teamScheduled offensive validation of controlsPLANNED