M ManySignal

India

SOC platform built for India's regulatory landscape

India's DPDP Act 2023, CERT-In 6-hour incident reporting, RBI Cybersecurity Framework, and SEBI CSCRF create a complex compliance environment. ManySignal stores all India data in AWS Mumbai, automates 6-hour CERT-In incident reporting, and provides continuous monitoring for India's financial sector regulators.

India data residency guarantees

Storage region

AWS AP-SOUTH-1 (Mumbai) — all customer log data, entity graph, case records, and analytics data stored within India. No transfer outside India under default deployment.

Processing boundary

All detection, AI inference, and report generation runs within AWS Mumbai infrastructure. ManySignal's AI models are deployed in-region for India customers.

Cross-border transfer

Cross-border data transfer permitted only with explicit customer instruction and in compliance with DPDP Act Section 16. ManySignal maintains SCCs and transfer impact assessments for any incidental support access.

India regulatory frameworks supported

DPDP Act 2023

Digital Personal Data Protection — data processing on instructions from Data Fiduciary, breach notification support, data principal rights

CERT-In Directions 2022

6-hour incident reporting for 20 categories of cybersecurity incidents — automated countdown and pre-populated notification template

RBI Cybersecurity Framework

SOC monitoring for RBI-regulated banks and NBFCs — 24x7 coverage, log management, incident reporting to RBI CSITE

SEBI CSCRF

Cyber Security and Cyber Resilience Framework for registered intermediaries — 24x7 SOC, 1-year log retention, incident reporting

IRDAI Cybersecurity Guidelines

Insurance Regulatory and Development Authority of India cybersecurity guidelines for insurers

IT Act 2000 / SPDI Rules 2011

Sensitive Personal Data and Information rules — data security practices for SPDI including financial and health information

Breach notification timelines — India

6 hours

CERT-In Directions 2022 — Reportable cybersecurity incidents (20 categories including ransomware, data breach, DDoS)

72 hours (expected)

DPDP Act 2023 — Breach notification to Data Protection Board (rules pending finalisation)

ASAP

RBI Cybersecurity Framework — Cyber security incident reporting to RBI CSITE

India sales and support contact

India enterprise sales: [email protected]

Support: 24x7 in-country support team based in Bangalore and Mumbai

Data protection queries: [email protected]

India data residency — common questions

Where is India customer data stored and processed?

India customer data is stored and processed in AWS AP-SOUTH-1 (Mumbai). No India customer data is transferred outside India under default deployment. Cross-border transfer is only permitted with explicit customer consent and subject to the DPDP Act's provisions on cross-border data transfer (Section 16), which require either central government approval of the destination country or consent from the data principal.

How does ManySignal comply with the Digital Personal Data Protection (DPDP) Act 2023?

ManySignal acts as a Data Processor (Data Fiduciary's processor) under the DPDP Act 2023. We process personal data only on documented lawful instructions from the Data Fiduciary (the customer). ManySignal's DPA is being updated to align with the DPDP Act Rules (expected 2025). The platform supports data principal rights — access, correction, and erasure — through the customer's data subject request workflow.

How does ManySignal support CERT-In compliance for 6-hour incident reporting?

The CERT-In Directions (2022) require reportable cybersecurity incidents to be reported within 6 hours of detection. ManySignal's incident management module tracks the detection timestamp and starts a 6-hour countdown for CERT-In reportable incident types (ransomware, data breach, DDoS, phishing compromising systems). The notification template pre-populates with CERT-In's required fields: incident type, affected systems, initial analysis, and contact details.

Does ManySignal support RBI Cybersecurity Framework requirements for Indian banks?

Yes. ManySignal maps to the RBI Cybersecurity Framework (2016) and RBI's subsequent circulars on IT risk and cybersecurity. For banks, ManySignal addresses: security operations (SOC) requirements, cyber incident monitoring and reporting to RBI CSITE, and log management requirements. Evidence packages are formatted for RBI inspection readiness.

What is ManySignal's support for SEBI CSCRF for registered intermediaries?

ManySignal addresses the SEBI Cyber Security and Cyber Resilience Framework (CSCRF) requirements for stock brokers, depositories, mutual funds, and other registered intermediaries. Specifically: 24x7 SOC capability (via the ManySignal agentic SOC), minimum 1-year log retention, VAPT evidence (via integration with pen testing workflows), and incident reporting to SEBI within the prescribed timelines.

Deploy ManySignal in India

Speak with our India team about AWS Mumbai deployment, CERT-In incident reporting automation, and RBI/SEBI compliance monitoring — in one session.