The empanelments behind every engagement
Empanelled by India’s national CERT to perform recognised security audits.
Authorised to perform Qualified Security Assessor work for PCI DSS across CEMEA, Asia Pacific and the USA.
Senior-led delivery supported by qualified specialists and independent quality review.
Compliance and security programmes delivered worldwide.
We hold ourselves to the standard we audit you against
Every engagement runs under NDA. Client data is handled on a strict need-to-know basis by the assigned senior team only.
Access to your systems and evidence is scoped to what the engagement requires, and revoked when it ends.
Findings and evidence are stored and transmitted securely, and retained only as long as your engagement and obligations require.
Every assessment produces clean, traceable evidence — the same standard we hold your programme to.
How SigmaTrust protects your data
The security posture of the SigmaTrust and SigmaTrust DPDP platforms — the controls behind enterprise procurement.
Customer data is hosted and processed on India-based infrastructure, with residency confirmed in our architecture documentation and subprocessor register (available under NDA).
AES-256 encryption for data at rest and SHA-3 for integrity/hashing, with TLS in transit.
Role-based access control across every workspace, with multi-factor authentication and SSO (SAML/OIDC) available per tenant.
A contractual 99.9% uptime target backed by a resilient multi-node disaster-recovery architecture; DR-test summaries and the SLA are available in the NDA review pack.
The AI features (Virtual DPO and assistants) run on a locally-hosted LLM by design; documented AI data flows (available under NDA) show customer data is not used to train external models.
Every consent and compliance action is written to a hash-chained, sealable audit ledger with on-demand integrity verification.
Deletion and consent evidence is retained for up to 7 years (2,555 days) to support audit and regulatory defensibility.
The platform is security-tested and maintained in a compliant state, with a secure development lifecycle across the release process.
Found a security issue in our platform or services? Report it responsibly and we’ll acknowledge and triage it. We do not pursue researchers who act in good faith.
security@cybersigmacs.comIn the event of a reportable security incident affecting customer data, we notify affected customers within a 6-hour SLA, in line with CERT-In directions and our contractual commitments.
Customer data is deleted in accordance with our data-retention policy and your contract. On request or at contract end, personal data is removed within the agreed window and confirmation is provided.
Enterprise review pack — available under NDA
Security and legal documentation for procurement and vendor-risk teams. Request access and we’ll share the relevant documents under NDA.
Platform architecture and data-residency documentation supporting the commitments above.
Request this document →The contractual uptime target and support/response commitments.
Request this document →Our DPDP/GDPR-aligned processing terms for customer engagements.
Request this document →The current list of infrastructure and service providers, kept up to date.
Request this document →An executive summary of the platform’s most recent security testing and closure status.
Request this document →Evidence of the most recent disaster-recovery test against the availability commitments.
Request this document →Documented data flows for the locally-hosted AI features — what is processed, where, and what never leaves.
Request this document →The data-retention and deletion schedule behind the evidence-retention commitment.
Request this document →A pre-completed vendor-security questionnaire to accelerate your review.
Request this document →Our mutual non-disclosure agreement to open a confidential review.
Request this document →CERT-In and PCI QSA listing evidence and certificate copies.
Request this document →Verify a CyberSigma certificate
Received a certificate or attestation from us? Confirm it’s genuine in seconds.
Validate a certificate →