GRC & Risk Management
🇮🇳 India Compliance Hub
Built for the five regulators that matter in India: CERT-In (6-hour incident mandate),
DPDP Act 2023 (full compliance 2027-05-13), RBI (2–6h by severity),
SEBI CSCRF (quarterly reports), IRDAI (24-hour window).
Pick a regulator below to open its tools.
Posture — your tenant
Live across all 5 regulators. Click any tile to open its tools.
Loading regulator posture…
CERT-In
6-hour
Report cyber incidents to CERT-In within 6 hours of detection. Escalation engine nudges via WhatsApp/email; submission only on your explicit approval.
Open tools →
DPDP Act 2023
2027 full
Rules notified 2025-11-13. Scan forms, consent, notices, SDF checklist, DSAR queue, data-flow diagram.
Open tools →
RBI
2/4/6h
Cyber incident reporter (severity-based window) + NBFC controls picker by layer.
Open tools →
SEBI
CSCRF
Quarterly CSCRF report draft for market intermediaries — VAPT, CCI, audit findings.
Open tools →
IRDAI
24-hour
24-hour incident countdown + draft report for
gro@irdai.gov.in.Open tools →
CERT-In · 6-hour incident mandate
Rule 12, CERT-In Directions 2022 · incident@cert-in.org.in
Active CERT-In Incident
Live from
/aegis/comply/certin/incident/{id}
Escalation timeline — the escalation engine fires each step
once when a channel and recipient are configured; otherwise the step is
recorded as skipped with the reason. Submission to CERT-In always requires
your explicit approval (one-tap link or Submit).
Bind an incident to see per-step status.
Retention & Jurisdiction Proof
Loading retention position from
/aegis/comply/certin/retention…
Open Incidents
- Loading from
/aegis/comply/certin/incidents…
Click any incident to bind its 6-hour clock + auto-draft Annexure-II.
Open a New Incident · 6-hour clock starts immediately
Annexure-II Draft
Click an open incident or create a new one to generate the Annexure-II draft.
DPDP Act 2023 · Scanners & Inventory
Rules notified 2025-11-13 · Full compliance deadline 2027-05-13
Live DPDP Scanners
Roadmap
DPDP URL scanners (forms / consent / notice / children) — coming after first BFSI pilot signs.
The DPDP §8(6) breach drafter below
(
POST /aegis/comply/actions/execute,
action_type=draft_dpdp_breach_report)
is real and grounded in the DPDP Act with an LLM. The URL-scanner
rule sets need pilot validation against a real Data Fiduciary's
consent UX before we ship them.
Data Inventory · Record of Processing (DPDP §5)
Loading from
/aegis/comply/dpdp/inventory…
Add new record
Data Subject Access Requests (DSAR)
Loading DSAR queue…
New DSAR
Personal Data Breach Report · DPDP §8(6)
SDF Checklist (Significant Data Fiduciary)
Loading from
/aegis/comply/dpdp/sdf…
Data-Flow Diagram (Mermaid)
graph LR will appear here
RBI · Cyber Incident Reporter
2h / 4h / 6h by severity · cyberincident@rbi.org.in
Draft Incident Report
Roadmap
RBI 2h/4h/6h incident drafter — coming after first BFSI pilot signs.
The DPDP §8 and CERT-In Rule 12 LLM drafters
(
POST /aegis/comply/actions/execute)
prove the pattern. RBI-specific report format requires validation against
a live RBI-regulated entity's CISO workflow before we ship it.
NBFC Controls
Loading applicable controls…
SEBI · CSCRF Quarterly Report
Cyber Security & Cyber Resilience Framework · market intermediaries
Quarterly Report Draft
Roadmap
SEBI CSCRF quarterly drafter — coming after first market-intermediary pilot signs.
The DPDP §8 and CERT-In Rule 12 LLM drafters
(
POST /aegis/comply/actions/execute)
prove the pattern. CSCRF report format (VAPT / CCI / audit findings) needs
validation with a real stockbroker / AMC / KRA before shipping.
IRDAI · 24-Hour Incident Window
Insurance Regulatory & Development Authority · gro@irdai.gov.in
Countdown Clock
Green >12h · Amber 6–12h · Red <6h · Breached = past deadline. (24h window)
Incident Draft · gro@irdai.gov.in
Fills the IRDAI incident-report template from the fields below.
Nothing is sent to IRDAI — Aria produces the draft and the missing-field
list; a human reviews and files it.
Uses the “Detected at” timestamp from the countdown above.
Fill the fields and click “Draft IRDAI report”.
👆 Click any regulator card above to open its tools.
All data is live from the backend. Empty states mean the endpoint is unavailable — no fabricated numbers.
All data is live from the backend. Empty states mean the endpoint is unavailable — no fabricated numbers.
Compliance Calendar — all India regulators
Loading milestones…
Evidence Vault — immutable ledger
Every compliance action writes an immutable row here — audit-ready for CERT-In / DPDP / RBI reviewers.
Loading evidence ledger…
Framework & Controls
Evidence Checklist
Organization Details
Security Posture Evidence
FAIR Scenario Parameters
ROADMAP
Target capabilities — not live data. Aria's live, real compliance workflow is the 🇮🇳 India Compliance tab (CERT-In / DPDP drafting + filing). The governance controls below are on the roadmap; none renders customer data yet.
📚 Governance & Risk-Management — roadmap (T370–T378)
The governance layer Aria is building toward. Each row is a planned control, not an implemented one — no numbers here are measured from your environment.
| ID | Capability | Intent | State |
|---|---|---|---|
| T370 | Control-framework mapping | One evidence set mapped across ISO 27001 / SOC 2 / PCI / DPDP | PLANNED |
| T371 | Evidence automation | Auto-collect screenshots/JSON/logs, link to control IDs, track expiry | PLANNED |
| T372 | IR retainer tracking | Incident-response retainer + escalation contacts on file | PLANNED |
| T373 | Cyber-insurance posture | Map controls to policy requirements + renewal readiness | PLANNED |
| T374 | Tabletop + playbook library | Reusable exercise scenarios + response playbooks | PLANNED |
| T375 | Third-party risk (TPRM) | Vendor tiering, security-review tracking, questionnaire workflow | PLANNED |
| T376 | Breach-notification workflow | Per-regulator deadline clocks + materiality decision tree | PARTIAL — live for India (CERT-In 6h) in the India tab |
| T377 | Policy library | Versioned policies mapped to controls with attestation | PLANNED |
| T378 | Privacy / DSR handling | Data-subject-request intake + fulfilment (DPDP / GDPR) | PLANNED |
ROADMAP
Target capabilities — not live data. Security-program & culture practices Aria is building toward. Nothing here is measured from your organisation.
🎓 Program & Culture — roadmap (T410–T416)
Culture beats controls. These are the program practices Aria intends to operationalise; each is planned, not implemented.
| ID | Practice | Intent | State |
|---|---|---|---|
| T410 | Quarterly tabletop | Exec-attended scenario exercises on a cadence | PLANNED |
| T411 | Annual full-simulation | End-to-end incident simulation once a year | PLANNED |
| T412 | Blameless post-mortem | 5-whys + owned action items per incident | PLANNED |
| T413 | Skill matrix + retention | Track team capabilities + coverage gaps | PLANNED |
| T414 | ISAC membership | Sector threat-sharing participation | PLANNED |
| T415 | Bug-bounty / VDP | Vulnerability-disclosure program intake | PLANNED |
| T416 | Internal red-team | Scheduled offensive validation of controls | PLANNED |