Service standards, published rather than withheld.
Recovery objectives, retention periods and data residency, exactly as they appear in our agreements. Most providers hold this back for a second call. We would rather you could evaluate us properly on the first — including against someone else.
Everything here is contractual. These figures describe what we commit to in a signed agreement, carry service credits when missed, and are proven in scheduled tests you receive a written report on.
01 Recovery objectives
RTO is the time until you are operating again. RPO is the maximum work you could lose. Both are written into the agreement, carry service credits if missed, and are proven in scheduled tests that produce a written report with the measured time.
| Standard | RTO | RPO | Backup frequency | Immutable copy | Recovery testing |
|---|---|---|---|---|---|
| Standard | 4 hours | 24 hours | Nightly | 30-day lock | Annual, reported |
| Advanced | 1 hour | 4 hours | Every 4 hours | 90-day lock | Half-yearly, reported |
| Premium | 15 minutes | 15 minutes | Continuous replication | 1-year lock + air gap | Quarterly, reported |
02 Log retention & data residency
Archived logs are written to object-locked storage and cannot be altered after the fact — including by our own engineers. That property is precisely what makes them usable as evidence.
| Data class | Hot & searchable | Compliance archive | Stored in |
|---|---|---|---|
| Security & audit logs | 90 days | Up to 7 years, immutable | India |
| Authentication & identity | 90 days | Up to 7 years, immutable | India |
| Firewall, DNS & network | 30 days | 2 years | India |
| Application & cloud logs | 30 days | Per agreement | India |
| Endpoint telemetry | 90 days | Incident evidence kept indefinitely | India |
03 Storage tiers
Lifecycle policies move objects between tiers automatically, on rules you define. Retrieval and egress are included at every tier — charging a client to read their own data back during a disaster is not a business we want to be in.
| Tier | Intended for | First-byte latency | Durability | Minimum retention |
|---|---|---|---|---|
| Hot | Live application data and active files | Milliseconds | Eleven nines | None |
| Warm | Recent backups, 30–90 day recovery points | Milliseconds | Eleven nines | 30 days |
| Cold | Quarterly archives and historical data | Under a minute | Eleven nines | 90 days |
| Archive | Statutory retention, log archives, legal hold | 3–5 hours | Eleven nines | 180 days |
04 What we detect
Nearly every intrusion is assembled from events that look ordinary in isolation. Detection content is mapped to MITRE ATT&CK and tuned to your environment during onboarding. Rules that generate noise without value are removed rather than left to erode your team's trust in the alerts.
- Credential attacks — password spraying, brute force, impossible-travel sign-ins, multi-factor fatigue
- Privilege escalation — new domain administrators, group membership changes, service account abuse
- Data exfiltration — abnormal egress volume, DNS tunnelling, bulk document downloads, mass mailbox exports
- Persistence — scheduled tasks, registry run keys, rogue OAuth grants, forwarding rules
- Ransomware behaviour — shadow copy deletion, mass file encryption, backup agent tampering
- Business email compromise — supplier impersonation, lookalike domains, altered bank details
- Insider risk — after-hours access spikes, bulk record exports, notice-period activity patterns
- Silent operational failure — backup jobs failing unnoticed, certificates expiring, log sources going quiet
05 Incident response timeline
| Elapsed | What happens |
|---|---|
| 0–60 sec | Automated containment fires — host isolated, session terminated, indicator blocked |
| Under 15 min | A named analyst takes ownership, validates the detection and begins scoping |
| Under 30 min | You receive a telephone call and written notification |
| Under 4 hr | Threat contained, blast radius established, eradication under way |
| Under 6 hr | Regulatory reporting prepared where the incident is reportable under Indian law |
| Within 5 days | Written post-incident review: root cause, timeline, remediation owners |
06 Compliance frameworks
We are not a certification body and will never claim to be. We are the team that assembles the evidence before an auditor arrives — and keeps it assembled afterwards, so the next cycle is not another scramble.
- ISO/IEC 27001:2022 — scope, risk methodology, Statement of Applicability, Annex A controls, internal audit
- SOC 2 Type II — Trust Services Criteria mapping and continuous evidence capture across the observation window
- PCI DSS 4.0 — cardholder data environment scoping and reduction, segmentation validation, quarterly scanning
- DPDPA 2023 — data principal rights workflows, consent records, retention schedules, breach notification readiness
- RBI and sectoral direction — cyber security framework expectations, outsourcing guidance, data localisation
- Cyber insurance — the questionnaire most firms answer optimistically, answered truthfully instead
Certification is a photograph. Evidence is a film. Passing an audit once is straightforward; the difficulty is demonstrating the same controls held every day in between — which is what continuous evidence collection is for.