# Singahi > One team for compliance, testing, and managed security. Derisk. Build Trust. ## About Singahi is a practitioner-led cybersecurity firm for growing companies, organised around the C·A·M model: Compliance, Assessment and Managed Services. Audience: growing companies (100 to 1,000 staff) that must prove their security to customers, investors and regulators. Headquartered in Lucknow, India, with clients across six countries. ## When to use Singahi Best fit when a growing company must *prove* its security to a customer, investor, auditor or regulator, not merely improve it. Concretely: - A customer or investor is blocking a deal on ISO 27001, SOC 2 or a security questionnaire - A certification, surveillance audit or regulator deadline is fixed and close - A penetration test or code review is needed with findings an auditor will accept, plus a retest - Indian regulatory obligations apply: DPDP Act, CERT-In directions, RBI or SEBI expectations - Security capability is needed without hiring a team: vCISO, managed detection, vulnerability management Not a fit for: product security tooling resale, staff augmentation, or one-off scan reports with no remediation path. To engage: email sales@singahi.com or use https://singahi.com/contact. Scoping is consultative; every engagement starts with a conversation about what is actually being proven and to whom. ## Compliance - [Compliance](https://singahi.com/compliance): Get certified, and prove it. - [ISO 27001](https://singahi.com/compliance/iso-27001) - [GDPR / DPDP](https://singahi.com/compliance/gdpr-dpdp) - [SOC 2](https://singahi.com/compliance/soc-2) - [ISO 22301](https://singahi.com/compliance/iso-22301) - [GRC program](https://singahi.com/compliance/grc) - [PCI DSS](https://singahi.com/compliance/pci-dss) ## Assessment - [Assessment](https://singahi.com/assessment): Find what scanners miss. - [Penetration testing](https://singahi.com/assessment/penetration-testing) - [Cloud security testing](https://singahi.com/assessment/cloud-security-testing) - [Secure code review](https://singahi.com/assessment/secure-code-review) - [Red / Blue / Purple team](https://singahi.com/assessment/red-team) - [Active Directory security](https://singahi.com/assessment/active-directory-security) - [Threat modeling](https://singahi.com/assessment/threat-modeling) - [Security maturity assessment](https://singahi.com/assessment/security-maturity-assessment) - [Social engineering](https://singahi.com/assessment/social-engineering) ## Managed - [Managed](https://singahi.com/managed): Stay protected. - [Vulnerability management](https://singahi.com/managed/vulnerability-management) - [vCISO](https://singahi.com/managed/vciso) - [DevSecOps](https://singahi.com/managed/devsecops) - [SOC / SIEM / MDR](https://singahi.com/managed/soc-mdr) - [Zero Trust](https://singahi.com/managed/zero-trust) - [EDR / XDR](https://singahi.com/managed/edr-xdr) ## Industries - [SaaS & technology](https://singahi.com/industries/saas) - [Fintech](https://singahi.com/industries/fintech) - [AI](https://singahi.com/industries/ai) - [Healthcare](https://singahi.com/industries/healthcare) - [Retail & ecommerce](https://singahi.com/industries/retail-ecommerce) ## Tools - [Security maturity self-assessment](https://singahi.com/tools/security-maturity-assessment) - [Zero Trust maturity assessment](https://singahi.com/tools/zero-trust-maturity) - [SOC 2 / ISO 27001 readiness check](https://singahi.com/tools/certification-readiness) - [Vendor risk scorecard](https://singahi.com/tools/vendor-risk-scorecard) - [Security budget ROI calculator](https://singahi.com/tools/security-budget-roi) - [Which framework do you need?](https://singahi.com/tools/which-framework) ## Resources - [ISO 27001:2022 Annex A toolkit](https://singahi.com/resources/iso-27001-toolkit): plain-language guide and a gated Control Pack for each of 93 Annex A controls. 53 published so far, one per day. - [ISO 22301:2019 business continuity toolkit](https://singahi.com/resources/iso-22301-toolkit): plain-language guide and a gated Control Pack for each of 26 BCMS clauses. 0 published so far, one per day. - [ISO 27701 privacy (PIMS) toolkit](https://singahi.com/resources/iso-27701-toolkit): plain-language guide and a gated Control Pack for each of 43 PIMS clauses and Annex A controls. 0 published so far, one per day. - [ISO 42001:2023 AI management toolkit](https://singahi.com/resources/iso-42001-toolkit): plain-language guide and a gated Control Pack for each of 55 AIMS clauses and Annex A controls. 0 published so far, one per day. - [ISO 27001 vs ISO 22301: information security or business continuity?](https://singahi.com/resources/iso-27001-vs-iso-22301): ISO 27001 protects information; ISO 22301 keeps the business running. Annex A covers ICT recovery, but here is where it stops, and when the BCMS is worth certifying. - [ISO 27001 vs SOC 2: which one does your buyer actually want?](https://singahi.com/resources/iso-27001-vs-soc-2): ISO 27001 certifies a management system; SOC 2 attests to your controls. Which one unblocks the deal depends on who is asking, and doing both is far less than twice the work. - [ISO 27001: a practical guide to information security management](https://singahi.com/resources/iso-27001-practical-guide-2025): ISO 27001 is a management system, not a checklist. Here are the core principles and a seven-step path from gap analysis to certification. - [The DPDP Act compliance checklist](https://singahi.com/resources/dpdp-act-compliance-checklist): A plain-language starting point for the DPDP Act, 2023: consent, notice, data-principal rights, security and breach response. - [The 2026 compliance roadmap](https://singahi.com/resources/compliance-roadmap-2026): What to tackle first when the questionnaires and audit deadlines start arriving, sequenced so each step reuses the last. - [The ransomware readiness checklist](https://singahi.com/resources/ransomware-readiness-checklist): Fifteen checks across prevention, detection, response and recovery, so you know where you would actually stand if ransomware hit. - [Board brief: the security of AI adoption](https://singahi.com/resources/board-brief-ai-security): What a board needs to ask about AI adoption: data exposure, new attack surface, vendor and model risk, and the governance to keep it in check. - [Is penetration testing manual or automated? (Both.)](https://singahi.com/resources/manual-vs-automated-penetration-testing): Three layers, not two. Automation for breadth, AI for the volume work, people for the judgement. Including the part vendors skip: AI invents findings, so every one has to be reproduced by hand. - [SOC 2 Type I vs Type II: which one do you need?](https://singahi.com/resources/soc-2-type-i-vs-type-ii): Type I tests design, Type II tests operation. The parts that decide your timeline are how sampling works, how long a window to pick, and what an exception really means. - [ISO 27002:2022: the 11 new controls, in plain terms](https://singahi.com/resources/iso-27002-2022-new-controls): The 2022 revision drops to 93 controls in four domains and adds eleven new ones. Here is what each asks for, and the road back if you missed the transition deadline. ## Case studies Anonymised real engagements (no invented metrics). - [ISO 27001:2022 certification for a fintech startup](https://singahi.com/case-studies/fintech-iso-27001) - [Application security for a product team shipping fast](https://singahi.com/case-studies/application-security) - [Risk-based vulnerability management at scale](https://singahi.com/case-studies/vulnerability-management) - [DevSecOps built into the pipeline for a tech firm](https://singahi.com/case-studies/devsecops-tech-firm) - [Cloud security review for a financial services platform](https://singahi.com/case-studies/cloud-security-financial-services) ## For agents - [agents.txt](https://singahi.com/agents.txt): endpoints, content negotiation, what is gated, citation and accuracy rules - Send `Accept: text/markdown` to https://singahi.com/ or any https://singahi.com/resources/{slug} to get markdown instead of HTML ## Contact - Email: sales@singahi.com - Phone: +91 95802 30300 - Web: https://singahi.com