1. Primary sources or say so
Regulatory facts are verified against the primary text — Gazette PDFs, regulator portals, official standards bodies — before publication. Where an official portal cannot be read directly, the entry states how the fact was corroborated instead of hiding it.
2. Dated, versioned, auditable
Reference material carries a last-verified date and a version. Corrections and additions append to a changelog; entries are never silently edited, so anything cited from us last month can be audited this month.
3. Disputed precision is stated as disputed
Where authoritative sources disagree (for example on an exact commencement day), we publish the range and the disagreement — and tell readers to confirm with counsel — rather than picking a side quietly.
4. Written and reviewed by practitioners
Content is authored and reviewed by the CERT-In empanelled, PCI QSA-authorised team that uses it in real assessments. Author and reviewer names appear on articles; the practice, not a content agency, stands behind the claims.
5. Precise service language
We distinguish assessment, readiness, certification, attestation and audit precisely, and never imply a certification or designation that has not been made. Tools that read signals say so — they do not claim decisions that belong to regulators.
6. No unsupported claims about others
Comparison content asserts verifiable facts about ourselves and stays at category level about third parties. A dash in our comparison tables means we make no representation — evaluate the vendor directly.
7. Errors are reportable — and reported
Every open resource invites corrections. Confirmed errors are fixed with a changelog entry stating what changed and when. Tell us at contact@ / the contact page.
This policy governs the India Compliance Registry, the open resource library, CyberSigma Research, the knowledge centre and the blog. Last updated 1 August 2026.