All solutionsRegion For teams in India

Six hours to report it. Most teams find out in six days.

CERT-In gives you six hours from the moment you notice. DeDups gets you to that moment sooner: a re-check every hour, the finding routed to a named owner the same hour, and a timestamped record you can export. Connect one account, read-only - the first scan finishes in about 15 minutes.

15 minutes to connect. No credit card. No sales call.
6 hoursto report it to CERT-In

From the moment you notice the incident - not from the moment you finish investigating it. Set by the CERT-In directions of 28 April 2022.

The problem

The clock starts when you notice. Not when you are ready.

One incident starts two clocks in India. CERT-In wants a report within six hours of you noticing it, and expects your logs kept for 180 days inside the country. The DPDP Act starts a second one: you have to tell the Data Protection Board and every person whose data was touched. Miss the safeguards behind either and penalties reach ₹250 crore. Six hours is not long enough to work out what broke, whose data it held, and who owns the system.

  • Nobody can say which server or bucket the alert is actually about.
  • Logs sit in three places, and nobody has checked they cover 180 days inside India.
  • You have to tell every affected person, and nobody can list who was affected.
How DeDups solves it

See it within the hour. Report it within six.

Continuous checks put the finding in front of a named person the same hour it appears, with the system, the region, the time it started and the evidence already attached. The six hours then go on writing the report rather than assembling it. It takes one read-only role and about 15 minutes to set up.

  1. 01Re-check every hour

    AWS, Azure and Google Cloud accounts are read continuously, so a bucket that went public this morning is a finding this morning - not a discovery at the next audit.

  2. 02Name an owner

    Maya routes each finding to the person who runs that system on Slack, Jira, WhatsApp or email, and escalates to their lead if nobody answers inside the window you set.

  3. 03Pin the window and the blast radius

    Every finding carries when it first appeared, when it was closed, and which systems and accounts it touched. That is your CERT-In timeline and your DPDP list of who to tell, in one export.

  4. 04Prove the safeguards

    Evidence is tagged to DPDP Act and ISO 27001 controls as it is collected, so the "reasonable security safeguards" question is a download rather than a project.

What you get

The numbers, and what sits behind them.

6 hoursreporting window covered
Every houryour cloud is re-checked
180 dayslog retention checked

1,000+ posture checks across AWS, Azure, Google Cloud and Kubernetes

Log retention and clock-sync settings checked against the CERT-In directions

One export with the timeline, the owners and the affected systems

DPDP Act and ISO 27001 evidence collected while you work

Findings routed to a named person on Slack, Jira, WhatsApp or email

Every laptop and server inventoried by the Inspector agent

Not sure you are in scope? The CERT-In directions reach body corporates, intermediaries, data centres and service providers - which is most companies running anything online in India. The free scan shows you what you would have to report today: one account, about 15 minutes, no credit card.

Machine speed, human judgement

A person still says yes.

DeDups writes the fix, runs it as a dry run and shows you exactly what will change. Nothing touches your infrastructure until someone on your team approves it, and every approval is recorded with a name and a time - which is what a regulator asks about afterwards. If a fix fails its own check, it rolls back and tells you.

DPDP Act 2023CERT-In DirectionsISO 27001SOC 2RBI IT Framework
Before you commit

The questions we get asked most.

No. Filing is your team’s call and your team’s signature. DeDups hands you the timeline, the affected systems and the log evidence in one export, so writing the report takes minutes instead of days.

The DPDP Act requires you to notify the Data Protection Board and each affected person; the timing detail sits in the Rules made under it, so confirm the current text with your counsel rather than with us. What DeDups gives you either way is the list of affected systems and the exposure window, the same day.

Yes. Azure and Google Cloud run through the same checks. Laptops and servers are covered by the Inspector agent, which needs no cloud account at all.

Ask us on the demo call. We will confirm the hosting region in writing before you sign anything, rather than making a promise on a page you cannot hold us to.

Get started

Start with your own numbers.

Connect one account. The first scan finishes in about 15 minutes and the report is yours either way - free, no credit card, no sales call. Read it, then decide.

sales@dedups.ai - we reply within 2 hours