We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Trust Center

Credentials you can verify

The authorizations behind our work, how we handle your data, and a way to validate any certificate we’ve issued — all in one place.

Validate a certificate →View accreditations
Authorizations

The empanelments behind every engagement

CERT-In Empanelled

Empanelled by India’s national CERT to perform recognised security audits.

PCI QSA Authorised

Authorised to perform Qualified Security Assessor work for PCI DSS across CEMEA, Asia Pacific and the USA.

Senior-led delivery

Senior-led delivery supported by qualified specialists and independent quality review.

1,000+ organisations

Compliance and security programmes delivered worldwide.

How we handle your data

We hold ourselves to the standard we audit you against

Confidentiality by default

Every engagement runs under NDA. Client data is handled on a strict need-to-know basis by the assigned senior team only.

Least-privilege access

Access to your systems and evidence is scoped to what the engagement requires, and revoked when it ends.

Secure evidence handling

Findings and evidence are stored and transmitted securely, and retained only as long as your engagement and obligations require.

Defensible, auditable work

Every assessment produces clean, traceable evidence — the same standard we hold your programme to.

Platform security

How SigmaTrust protects your data

The security posture of the SigmaTrust and SigmaTrust DPDP platforms — the controls behind enterprise procurement.

Data residency — India

Customer data is hosted and processed on India-based infrastructure, with residency confirmed in our architecture documentation and subprocessor register (available under NDA).

Encryption

AES-256 encryption for data at rest and SHA-3 for integrity/hashing, with TLS in transit.

Access control — MFA & SSO

Role-based access control across every workspace, with multi-factor authentication and SSO (SAML/OIDC) available per tenant.

Availability — 99.9% target

A contractual 99.9% uptime target backed by a resilient multi-node disaster-recovery architecture; DR-test summaries and the SLA are available in the NDA review pack.

Private AI — locally hosted LLM

The AI features (Virtual DPO and assistants) run on a locally-hosted LLM by design; documented AI data flows (available under NDA) show customer data is not used to train external models.

Tamper-evident audit ledger

Every consent and compliance action is written to a hash-chained, sealable audit ledger with on-demand integrity verification.

Evidence retention

Deletion and consent evidence is retained for up to 7 years (2,555 days) to support audit and regulatory defensibility.

Tested & compliant

The platform is security-tested and maintained in a compliant state, with a secure development lifecycle across the release process.

Report a vulnerability

Found a security issue in our platform or services? Report it responsibly and we’ll acknowledge and triage it. We do not pursue researchers who act in good faith.

security@cybersigmacs.com
Incident notification — 6-hour SLA

In the event of a reportable security incident affecting customer data, we notify affected customers within a 6-hour SLA, in line with CERT-In directions and our contractual commitments.

Data deletion & retention

Customer data is deleted in accordance with our data-retention policy and your contract. On request or at contract end, personal data is removed within the agreed window and confirmation is provided.

Documentation

Enterprise review pack — available under NDA

Security and legal documentation for procurement and vendor-risk teams. Request access and we’ll share the relevant documents under NDA.

Architecture overview

Platform architecture and data-residency documentation supporting the commitments above.

Request this document →
Service Level Agreement (SLA)

The contractual uptime target and support/response commitments.

Request this document →
Data Processing Addendum (DPA)

Our DPDP/GDPR-aligned processing terms for customer engagements.

Request this document →
Sub-processor register

The current list of infrastructure and service providers, kept up to date.

Request this document →
Penetration-test summary

An executive summary of the platform’s most recent security testing and closure status.

Request this document →
DR-test summary

Evidence of the most recent disaster-recovery test against the availability commitments.

Request this document →
AI data-flow statement

Documented data flows for the locally-hosted AI features — what is processed, where, and what never leaves.

Request this document →
Retention schedule

The data-retention and deletion schedule behind the evidence-retention commitment.

Request this document →
Security questionnaire (CAIQ/SIG)

A pre-completed vendor-security questionnaire to accelerate your review.

Request this document →
Standard NDA

Our mutual non-disclosure agreement to open a confidential review.

Request this document →
Accreditation evidence

CERT-In and PCI QSA listing evidence and certificate copies.

Request this document →
Request access under NDA →

Verify a CyberSigma certificate

Received a certificate or attestation from us? Confirm it’s genuine in seconds.

Validate a certificate →