We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

GoalsMate case study hero background

GoalsMate: Achieves Data Security and Compliance with CyberSigma's Support

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Executive Summary

Fast-growing digital platforms must protect personal data, secure payments, and demonstrate compliance to partners and regulators. GoalsMate (client name used with permission) engaged CyberSigma to address overlapping gaps across DPDPA, PCI DSS, and security testing—turning fragmented controls into an audit-ready program.

Client Overview

GoalsMate is a digital platform serving users across India with subscription and payment flows. Leadership needed a unified compliance and security program rather than point fixes for individual audit findings.

  • Industry: Digital Platform / SaaS
  • Region: India
  • Scope: DPDPA, PCI DSS alignment, VAPT, ISO 9001 governance

Challenge

GoalsMate faced non-compliance across PII handling, PCI DSS expectations from payment partners, and DPDPA requirements—with no structured VAPT program and elevated legal and reputational risk.

  • No formal DPDPA privacy program or RoPA
  • PCI DSS gaps in card data handling and tokenization
  • No recurring VAPT or remediation tracking
  • Inconsistent policies and control ownership
  • Pressure from partners to demonstrate compliance quickly

Objectives

  • Establish DPDPA-aligned privacy and security controls
  • Achieve PCI DSS readiness with CDE tokenization
  • Implement ISO 9001 quality governance for delivery consistency
  • Complete full VAPT and close critical findings
  • Build executive-ready evidence for partners and auditors

Our Approach

1. Compliance Scoping & Gap Assessment

We mapped data flows, processing activities, and payment touchpoints—identifying gaps across DPDPA, PCI DSS, and operational security in a single prioritised roadmap.

2. DPDPA & Privacy Controls

CyberSigma implemented consent workflows, RoPA, retention rules, and vendor review checkpoints aligned to India’s DPDP Act expectations.

3. PCI DSS-Aligned Payment Architecture

We designed tokenization and scope-reduction measures so cardholder data exposure was minimised and partners could validate PCI readiness.

4. VAPT & Remediation

External and application-focused VAPT was executed with tracked remediation SLAs until critical and high findings were closed.

5. ISO 9001 Governance & Training

Process documentation, control owners, and team training established repeatable quality and security operations.

Solution

  • Implemented ISO 9001 quality governance for process consistency.
  • Established DPDPA-aligned controls, RoPA, and accountability.
  • Enabled PCI DSS readiness with card data environment tokenization.
  • Completed full VAPT cycle and remediation closure.
  • Delivered policy packs and executive compliance reporting.

Results

  • 100% compliance against defined control set
  • 91% reduction in identified security risk exposure
  • Increased trust-driven business growth and stronger customer confidence
  • Repeatable audit and testing cadence for ongoing assurance

Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.

What We Delivered

  • Scoped test plan across the agreed surface (web, API, mobile, infrastructure as applicable)
  • CERT-In empanelled testing with combined automated and senior manual coverage
  • Findings report with reproduction steps, severity rationale and OWASP mapping
  • Developer-ready remediation guidance and retest verification
  • Safe-to-host / submission-ready certificate where required

The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.

Lessons Learned

  • The findings that mattered came from manual testing of business logic — automation set the floor, seniors found what attackers actually use.
  • Retest discipline separated a compliance artefact from a security outcome: a finding without a verified fix is an open risk with paperwork.
  • Recurring quarterly testing changed the economics — each cycle got cheaper and faster as the fix-verify loop tightened.
Facing a similar challenge?

Talk to the team that ran this engagement

This was a real DPDPA & PCI DSS Compliance Consulting engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.

Abhay Singh, Director — Compliance & Penetration Testing
Led by our PCI DSS specialists — Abhay Singh · PCI SSC-qualified QSA professional

Explore PCI DSS QSA assessment · more case studies

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →