We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

A Free Compliance Assistant That Cites the Official Texts

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

We Rebuilt Our Compliance Assistant on Our Own AI Platform — Free Answers, Cited From the Official Texts

Most compliance chatbots have the same two failure modes. Either they answer everything — including things they are inventing, complete with confident but wrong clause numbers — or they answer almost nothing and route every second question to a contact form. We ran the second kind on our own website for months, deliberately: it answered only from a small registry of verified facts, and refused the rest. Honest, but limited. This month we replaced the engine behind it, and the difference is worth explaining because the how matters more than the marketing.

What changed

The assistant at cybersigmacs.com/compliance-assistant now runs on the same AI platform our own consultants use internally. Instead of ~180 summary facts, it answers from a corpus of over 2,400 passages of the actual official texts: the DPDP Act 2023 and DPDP Rules, the GDPR in full, RBI's Cyber Security Framework and the 2023 IT Governance Master Direction, SEBI's CSCRF, the CERT-In directions of April 2022, NIST publications including CSF 2.0 and the SP 800 series, the IT Act 2000, CCPA, SAMA's Cyber Security Framework and the OWASP Top 10. Where the law is public, we ingested the law itself — not someone's summary of it.

Ask it something the old version could not answer

QuestionOld assistantNow
How often does SEBI CSCRF require VAPT?Not covered — contact an expertAnswered from the CSCRF text itself, with citations
What does the RBI IT Governance Master Direction require of an IT Strategy Committee?Not coveredGrounded in the Master Direction
Within what time must incidents reach CERT-In?Covered (single fact)Answered from the directions, six hours, with the source
What are Singapore's MAS TRM expectations?Not coveredResearched live from public sources, cited, marked as web-sourced

The three honesty mechanisms

1. Machine-verified citations

Every clause or requirement number the assistant cites is checked — by code, not by another AI — against the source corpus. A number the corpus cannot confirm gets a visible flag telling you to verify it with an assessor. This matters because inventing plausible clause numbers is the single most common failure of AI compliance tools, and the fix cannot itself be an AI's opinion.

2. Copyrighted standards stay summarised

PCI DSS, the ISO standards, CIS and similar are copyrighted works. The assistant describes their requirements from verified summary facts and tells you when exact numbering needs an assessor's confirmation — it does not quote text it has no right to hold. If an AI tool quotes ISO 27001 control text at you verbatim, it is worth asking where that text came from.

3. When it does not know, it looks — and says so

Questions outside the corpus no longer dead-end. The assistant searches the live web, reads the top sources, answers from them, and labels the answer as web-sourced with the links. If even that fails, it says plainly that a consultant should take the question. No guesses dressed as knowledge.

It runs on our own infrastructure

The models behind the assistant run on CyberSigma's own GPU servers — the same private AI platform that drafts our proposals and grounds our internal research. Your questions are not forwarded to a third-party AI provider; they are answered on hardware we control, and we log only the question itself (anonymised) so we can keep improving coverage. For a security firm, that architecture is not a footnote. It is the point.

What it is not

It is not legal advice, and it is not a scoped engagement. It will tell you what the DPDP Rules require of a Data Fiduciary; it cannot tell you whether your consent flows meet them — that takes an assessment. Where the assistant's answer ends and the engagement begins is exactly the line the tool is honest about, and every answer that reaches that line says so.

Try it

The assistant is free and needs no signup: cybersigmacs.com/compliance-assistant. Ask it the question you would ask us on a first call. If it answers well, you have saved a call. If it hands you to a human, that human is a senior auditor — which is rather the idea.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity and privacy firm and PCI QSA company helping organisations with DPDP readiness, ISO 27001, PCI DSS, SOC 2, SEBI CSCRF and VAPT — delivered by senior auditors.

Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →