All solutionsIndustry For banks, lenders and fintechs

The regulator asks who can reach the data. You have a screenshot from March.

PCI DSS v4.0’s future-dated requirements have been mandatory since 31 March 2025, and RBI, MAS and SAMA all want the same thing: dated evidence covering the whole period. DeDups checks access, encryption and logging continuously and keeps the proof as it goes.

15 minutes to connect. No credit card. No sales call.
31 March 2025PCI DSS v4.0 fully in force

The future-dated requirements stopped being best practice on that date. They are requirements now.

The problem

Access changes daily. Your proof does not.

A contractor gets a role for one migration and keeps it for a year. A test database is restored from production with the data still in it. A logging bucket is opened for one debugging session. Each is a small, sensible decision on the day. Together they are the finding that lands in the report.

  • Nobody can list who can reach the cardholder data environment today.
  • Encryption is on in production and off in a staging account nobody claims.
  • The quarterly access review is done from memory, not from a record.
How DeDups solves it

Checked continuously. Proven automatically.

Every check that passes is captured as evidence and tagged to the requirement it satisfies, on the day it ran. When the auditor picks a month, the month is already covered.

  1. 01Check every account continuously

    1,000+ checks across AWS, Azure, Google Cloud and Kubernetes covering access, encryption, logging, network exposure and key management.

  2. 02Map each result to the control

    Results are tagged to PCI DSS, SOC 2, ISO 27001 and HIPAA requirements as they are collected, so the evidence pack builds itself.

  3. 03Fix it with a dry run first

    The remediation agent shows the exact change it will make, waits for approval, applies it, then verifies. A failed verification rolls back automatically.

  4. 04Export the audit pack

    One export per framework, carrying dates, sources and control mappings. Hand it to the auditor without preparing anything.

What you get

The numbers, and what sits behind them.

1,000+checks per account
< 5 minaverage fix time
Rollbackon failed verification

Access, encryption, logging and key-management checks on every account

Evidence mapped to PCI DSS 4.0, SOC 2, ISO 27001 and HIPAA automatically

Dry run before any change, human approval, then automatic verification

Full audit trail - who approved what, when, and what it changed

Public IP and API scanning for the internet-facing side of the estate

Multi-account view with findings tagged to the account they came from

Machine speed, human judgement

Nothing changes without an approval.

Every fix is proposed, simulated and shown as a full diff before anyone approves it. You can also leave every fix manual and use DeDups purely to find and to prove - the detection and the evidence work exactly the same either way.

PCI DSS 4.0RBI IT FrameworkSOC 2ISO 27001MAS TRMSAMA CSF
Before you commit

The questions we get asked most.

Only after a person approves that specific change, and only after a dry run has shown what it will do. Auto-approval is off unless you turn it on.

No. It reads configuration - who has access, what is encrypted, what is exposed to the internet. It does not read the rows in your database.

Evidence is collected once and mapped to each framework, so one control can satisfy several reports without being collected three times.

Get started

Start with your own numbers.

Connect one account. The first scan finishes in about 15 minutes and the report is yours either way - free, no credit card, no sales call. Read it, then decide.

sales@dedups.ai - we reply within 2 hours