These are the frameworks that shape our control set. We are deliberately precise about the verb: aligned to and designed against mean we build to the requirement. Certified would mean an accredited third party had examined us and said so, and no one has. Nothing on this page is a certification, attestation or audit opinion.
SEBI CSCRF
The Cybersecurity and Cyber Resilience Framework is the control set our clients are measured against, so we design the platform to survive their diligence: governance, access control, encryption, tenant segregation, logging and incident response. We are not a SEBI-registered intermediary and do not self-certify under CSCRF.
RBI IT-outsourcing expectations
Regulated clients who outsource IT services carry audit, inspection and exit-plan obligations that reach their service providers. We build to be audit-ready for that: documented controls, a reconstructable audit trail, and data you can take with you.
CERT-In directions
The 2022 directions set India's incident-reporting and log-retention expectations. Centralised log retention is being built out now and is listed honestly in the roadmap below.
DPDP Act 2023
Consent is purpose-coded and verified per request; you are the data fiduciary for your end customers and we process their data only on your instruction. Rights, retention and grievance handling are set out in our Privacy Policy.
NIST CSF 2.0
Used as the organising spine for our control set — Govern, Identify, Protect, Detect, Respond, Recover. It is where our own gap analysis is scored.
OWASP ASVS
Used as the application-level checklist for authentication, session handling, access control, cryptographic storage and error handling.
ISO/IEC 27001
A roadmap target, not a held certification. We have no ISMS certified today and say so plainly.
Grappi is a technology provider to regulated entities and is not itself a SEBI-registered intermediary or an RBI-regulated entity. Where a framework binds you rather than us, we aim to give you the artefacts your own regulator will ask for. This page is not legal advice.