Trust & compliance
We engineer for audit from day one.
Every certification, every framework, every piece of documentation a procurement team or CISO will ask for.
Recognitions
Officially recognised. Operationally ready.
- 01Startup India recognised: DeepTech
- DPIIT-recognised DeepTech startup (Cert# DIPP258374, valid through 30 Jul 2045). Eligible for tax benefits, IPR fast-tracking, and government procurement preferences.
- 02MSME Udyam registered
- Udyam-registered enterprise (UDYAM-TS-20-0144545, registered 22 Aug 2025). Eligible for procurement preferences with public-sector and government-empanelled buyers.
- 03Trademark protected
- OrbitNexa is a registered trademark with the Indian Trademark Registry.
Certified · recognised
Startup India
DeepTech DPIIT recognised
MSME
Registered
ISO/IEC 27001
Information security
ISO 9001
Quality management
ISO/IEC 20000
IT service management
CERTIFICATIONS
Three ISO certifications. Real audits. Real reports.
All certified at OrbitNexa Technologies Pvt Ltd. Audit reports available on request under NDA.
3 frameworks
- 01ISO/IEC 27001:2022 (Information Security Management)
- Cert# 0314I311726, issued by Toris Management Pvt. Ltd. (EGAC accredited, IAF MLA). Certified 14 Mar 2026, valid through 13 Mar 2029. Scope: Design, development, and provision of SaaS solutions and IT support services. Surveillance audits annually. Full audit reports on request under NDA.
- 02ISO 9001:2015 (Quality Management)
- Cert# 0314Q311626, issued by Toris Management Pvt. Ltd. (EGAC accredited, IAF MLA). Certified 14 Mar 2026, valid through 13 Mar 2029. Scope: Design, development, and provision of SaaS solutions and IT support services. Covers Studio and Lab delivery processes.
- 03ISO/IEC 20000-1:2018 (IT Service Management)
- Cert# 305026031478SM, issued by QRO Certification LLP (EGAC accredited, IAF). Certified 14 Mar 2026, valid through 13 Mar 2029. Scope: Information technology and computer service activities, SaaS, and IT services. Covers incident, change, and service-level management.
Audit calendar
Every surveillance audit, on the calendar.
External surveillance audits land annually. Every certificate below opens as the signed PDF after a short request form, and every one is independently verifiable with the registrar named against it. Full audit reports on request under NDA.
COMPLIANCE FRAMEWORKS WE DELIVER AGAINST
The frameworks your buyers, auditors, and regulators ask about.
Not aspirational checkboxes: the controls we actually engineer into client deliveries.
9 frameworks
- 01DPDP Act 2023 (India)
- India's data protection regime: consent, residency, deletion, and grievance controls engineered in.
- 02HIPAA-aligned (US healthcare)
- BAA available for US healthcare partners. PHI controls and audit logging on every access.
- 03GDPR (UK + EU)
- DPA available. Consent, lawful basis, residency, and subject-rights controls.
- 04PCI-DSS Level 1-ready
- Card-data tokenisation, network segmentation, and key management for banking and payment-system clients.
- 05RBI cybersecurity framework
- For banks and NBFCs. Critical-system controls, AA framework integration, and reporting workflows.
- 06ABDM-FHIR ready
- Health ID, HFR/HPR integration, FHIR R4 resources for hospitals and diagnostic labs.
- 07NABL workflow alignment
- ISO 15189: diagnostic-lab QA processes baked into product flows. Used in inferagen.ai.
- 08FCA AI guidance (UK)
- Audit-traceable AI agents for UK financial services clients. Outcome-monitoring patterns.
- 09CERT-In incident response
- Reporting timelines and runbook readiness.
ARCHITECTURE STANDARDS
Defaults that auditors smile at.
The technical defaults on every Studio engagement. Override only with explicit client request and a documented exception.
6 frameworks
- 01AWS Mumbai by default
- India data residency on every project unless the client explicitly requests another region.
- 02Encryption at rest + in transit
- AES-256 at rest. TLS 1.3 for all traffic.
- 03Quarterly third-party penetration testing
- All client-facing production systems. Reports shared with clients under NDA.
- 04Secrets management via AWS Secrets Manager
- No plain-text credentials in code or config. Rotation policies enforced.
- 05Audit logging on every state-changing action
- Tamper-evident logs for all clients in regulated industries. Retention per regulator.
- 06AI agent governance
- Tracing, content moderation, prompt-injection defenses, human-in-the-loop gating on every agent.
Document library
Documents your security review will ask for.
None of these is published. Each is sent by a founder on request. Tell us which you need and you will have a reply within one business hour. The certifications above open as the signed certificate after a short request form.
Need a security review call?
Book 30 minutes with the team that owns the audit posture. We’ll walk through your specific concerns and answer follow-ups within one business hour.
Book a security review callHave a security or compliance question?
Founders review every inbound message personally. We're easy to find, and we don't hide behind a help-desk.