India
SOC platform built for India's regulatory landscape
India's DPDP Act 2023, CERT-In 6-hour incident reporting, RBI Cybersecurity Framework, and SEBI CSCRF create a complex compliance environment. ManySignal stores all India data in AWS Mumbai, automates 6-hour CERT-In incident reporting, and provides continuous monitoring for India's financial sector regulators.
India data residency guarantees
Storage region
AWS AP-SOUTH-1 (Mumbai) — all customer log data, entity graph, case records, and analytics data stored within India. No transfer outside India under default deployment.
Processing boundary
All detection, AI inference, and report generation runs within AWS Mumbai infrastructure. ManySignal's AI models are deployed in-region for India customers.
Cross-border transfer
Cross-border data transfer permitted only with explicit customer instruction and in compliance with DPDP Act Section 16. ManySignal maintains SCCs and transfer impact assessments for any incidental support access.
India regulatory frameworks supported
DPDP Act 2023
Digital Personal Data Protection — data processing on instructions from Data Fiduciary, breach notification support, data principal rights
CERT-In Directions 2022
6-hour incident reporting for 20 categories of cybersecurity incidents — automated countdown and pre-populated notification template
RBI Cybersecurity Framework
SOC monitoring for RBI-regulated banks and NBFCs — 24x7 coverage, log management, incident reporting to RBI CSITE
SEBI CSCRF
Cyber Security and Cyber Resilience Framework for registered intermediaries — 24x7 SOC, 1-year log retention, incident reporting
IRDAI Cybersecurity Guidelines
Insurance Regulatory and Development Authority of India cybersecurity guidelines for insurers
IT Act 2000 / SPDI Rules 2011
Sensitive Personal Data and Information rules — data security practices for SPDI including financial and health information
Breach notification timelines — India
6 hours
CERT-In Directions 2022 — Reportable cybersecurity incidents (20 categories including ransomware, data breach, DDoS)
72 hours (expected)
DPDP Act 2023 — Breach notification to Data Protection Board (rules pending finalisation)
ASAP
RBI Cybersecurity Framework — Cyber security incident reporting to RBI CSITE
India sales and support contact
India enterprise sales: [email protected]
Support: 24x7 in-country support team based in Bangalore and Mumbai
Data protection queries: [email protected]
India data residency — common questions
Where is India customer data stored and processed?
India customer data is stored and processed in AWS AP-SOUTH-1 (Mumbai). No India customer data is transferred outside India under default deployment. Cross-border transfer is only permitted with explicit customer consent and subject to the DPDP Act's provisions on cross-border data transfer (Section 16), which require either central government approval of the destination country or consent from the data principal.
How does ManySignal comply with the Digital Personal Data Protection (DPDP) Act 2023?
ManySignal acts as a Data Processor (Data Fiduciary's processor) under the DPDP Act 2023. We process personal data only on documented lawful instructions from the Data Fiduciary (the customer). ManySignal's DPA is being updated to align with the DPDP Act Rules (expected 2025). The platform supports data principal rights — access, correction, and erasure — through the customer's data subject request workflow.
How does ManySignal support CERT-In compliance for 6-hour incident reporting?
The CERT-In Directions (2022) require reportable cybersecurity incidents to be reported within 6 hours of detection. ManySignal's incident management module tracks the detection timestamp and starts a 6-hour countdown for CERT-In reportable incident types (ransomware, data breach, DDoS, phishing compromising systems). The notification template pre-populates with CERT-In's required fields: incident type, affected systems, initial analysis, and contact details.
Does ManySignal support RBI Cybersecurity Framework requirements for Indian banks?
Yes. ManySignal maps to the RBI Cybersecurity Framework (2016) and RBI's subsequent circulars on IT risk and cybersecurity. For banks, ManySignal addresses: security operations (SOC) requirements, cyber incident monitoring and reporting to RBI CSITE, and log management requirements. Evidence packages are formatted for RBI inspection readiness.
What is ManySignal's support for SEBI CSCRF for registered intermediaries?
ManySignal addresses the SEBI Cyber Security and Cyber Resilience Framework (CSCRF) requirements for stock brokers, depositories, mutual funds, and other registered intermediaries. Specifically: 24x7 SOC capability (via the ManySignal agentic SOC), minimum 1-year log retention, VAPT evidence (via integration with pen testing workflows), and incident reporting to SEBI within the prescribed timelines.
Deploy ManySignal in India
Speak with our India team about AWS Mumbai deployment, CERT-In incident reporting automation, and RBI/SEBI compliance monitoring — in one session.