SecurityBoat

Compliance · Indian Regulatory

CERT-In audit evidence, from an empanelled team.

SecurityBoat is CERT-In empanelled. TriNetra is the platform our auditors and yours work from — every finding validated, every retest recorded, every report generated from live engagement data.

SQL injection in legacy reporting export

payments-service · reported by PTaaS engagement PT-2026-182

CRITICAL9.8
DraftTriagingVerifiedAccepted RiskFix in progressRetestResolved

Retest queued the moment the fix landed — the loop that proves the fix held.Retest SLA · 3d

The regulation

What CERT-In expects of you.

The Indian Computer Emergency Response Team's April 2022 Directions are the umbrella every sectoral regulator on this site builds on: 6-hour incident reporting for specified categories of cyber incidents — data breaches, unauthorized access, DDoS, ransomware, and more — measured from detection, not confirmation; 180-day log retention for ICT systems, stored within Indian jurisdiction; synchronized time sources tied to Indian time references (NIC/NPL) rather than arbitrary NTP servers; and CERT-In empanelment as a hard gate for any firm conducting a "CERT-In audit" — a report from a non-empanelled firm doesn't satisfy the requirement, regardless of quality. That's a genuine scarcity constraint: only a small fraction of India's security vendors hold current empanelment, and between audit cycles attack surfaces don't stand still — subdomains get spun up, credentials leak onto paste sites, a vendor gets breached and inherits access to your environment.

How TriNetra maps to it

One platform. The whole audit trail.

TriNetra moduleEvidence produced
PTaaSCERT-In-scoped engagements delivered by an empanelled team — the Coverage tab tracks methodology directly against CERT-In's baseline control categories (Cyber Security Management, Protection, Detection, Response, Recovery, Improvement), the same mechanism used for OWASP WSTG coverage on other engagements.
PTaaSProof that findings were fixed, not just found — the enforced remediation-retest loop: you mark a fix ready, the tester confirms or sends it back, all on an append-only history a reviewer can walk end to end.
Attack Surface ManagementContinuous surveillance between audits — monitored targets, discovered subdomains, and exposed assets tracked on a recurring schedule rather than a point-in-time scan, closing exactly the drift gap a once-a-year audit leaves open.
Continuous Controls ValidationControl test history logged against CERT-In's 180-day retention windows, with a single passing control mapped simultaneously across CERT-In's baseline and whichever sectoral framework — RBI, SEBI, IRDAI — also applies. Findings, severity breakdown, and a methodology checklist auto-aggregate into a CERT-In-aligned report through the same pipeline used for RBI, ISO 27001, and SOC 2.
Trust CenterSharing audit artifacts with stakeholders — reports filed under Pentest Reports in a governed document library; access granted through an approval workflow, every view logged.

Keep evidence current between audits with Continuous Controls Validation.

On the platform

Scoped audits, moving on visible rails.

Every CERT-In-scoped engagement runs as a live object — state, assigned team, and findings count visible — not a PDF that arrives six weeks later.

Pentest Engagements

Total 20Active 14Completed 6
Movies Network Penetration TestLive6 findings
Mobile Banking API — Grey BoxReport review11 findings
Partner Gateway — Black BoxClosed4 findings

Why SecurityBoat

The empanelment is ours. The evidence is yours.

CERT-In empanelment means our audit work meets the bar India's national CERT sets for its own ecosystem. Add CREST membership, ISO 27001, ISO 9001, and SOC 2 Type 2, and you get an audit partner whose own house passes the checks it runs on yours — delivering through a platform instead of an inbox full of PDFs.

Ready when you are

Book your CERT-In audit on a platform.

Scope it once, watch findings land in real time, retest to closure, submit an approved report. That's the whole engagement.