SaaS door. DPDP + ISO 27001 + SOC 2 + GDPR.

DPDP. ISO 27001. SOC 2. GDPR. One workspace.

Every framework your enterprise buyer asks about, in one platform. Sales-ready by Series B. Audit-ready by Series C. dcomply builds the evidence base once and reuses it across DPDP, ISO 27001, SOC 2, GDPR, and every buyer security questionnaire (VSAQ, CAIQ, SIG). You stop running parallel audits and start closing enterprise deals faster.

ISO 27001 + SOC 2 in one tool GDPR + CCPA for global buyers No credit card to start
Live SaaS Compliance Snapshot
Cloudbridge Tech Pvt Ltd · B2B SaaS
Trust Score: 89/100 GREEN
───────────────────────────────
DPDP Act 2023 ............... 94%
ISO 27001 controls .......... 88%
SOC 2 Trust Services ........ 79%
GDPR (EU customers) ......... 92%
Vendor DPA chain ............ 86%
───────────────────────────────
Open buyer DDs: 3 · Evidence ready: all
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

Your enterprise sales cycle keeps stalling on the security questionnaire.

Your DPO is your CTO's Notion page.

You told the customer "we're SOC 2 ready" and you're now regretting it.

You handle EU users but you have no DSAR process worth the name.

If you sell to Indian regulated buyers, the DPDP door covers the Data Fiduciary side; the Fintech door is your target buyer's door.

Your regulator stack

Here's what sits above the foundation.

A B2B SaaS startup selling to Indian enterprises AND global customers ends up with the widest compliance stack of any industry vertical. dcomply ships modules for each layer.

DPIIT Startup recognition
Recognition tracker, benefit filings, annual returns to unlock startup benefits.
CCPA (California users)
Consumer opt-out, data deletion, do-not-sell workflow.
GDPR (EU users)
DSAR portal, EU representative, cross-border transfer records, cookie consent.
SOC 2 Type II
Trust Service Criteria mapping, evidence library, auditor-ready evidence base.
ISO 27001:2022
All 93 Annex A controls, evidence collection, gap tracker, Statement of Applicability.
DPDP Act 2023
The Indian foundation. Customer data workflows in 22 Indian languages, DPA chain, sub-processor register.
120+
ISO 27001 controls
5
SOC 2 Trust Service criteria
€20M
GDPR max fine
14 days
Buyer DD average
Why SaaS Compliance Eats Founder Hours

Four Audit Stacks, Same Engineering Team

DPDP for India users

Indian user data needs consent, DSR, breach plumbing.

GDPR for EU customers

Article 28 DPA, breach 72h, data transfer impact assessments.

ISO 27001 + SOC 2

Enterprise buyers won't sign without one of them, often both.

Vendor DPA chain

You sign DPAs to your customers; you need them from every vendor too.

In Your Tenant On Day One

Every SaaS Module. Pre-Wired

DPDP
Consent Management

Cookie banner, in-app consent for product analytics, withdrawal flows.

DPDP
DSR Portal

Customer right-to-access, correct, delete. SLA tracking, branded portal.

DPDP
Cross-Border Tracker

AWS / GCP regions, vendor countries, DPDPB approval log.

ISO
ISO 27001 Assessment

Live score across 120+ controls. Evidence linker. Auditor handover binder.

SOC
SOC 2 Readiness

Security / Availability / Confidentiality / Processing Integrity / Privacy.

GDPR
GDPR Compliance

Article 28 DPA generator, EU representative tracker, DPIA module.

CCPA
CCPA Compliance

Do-Not-Sell, SPI register, annual cyber audit (where applicable).

Vendor
Vendor DPA + TPRM

Auto-track every vendor DPA, expiry alerts, sub-processor register.

Vendor
Sub-Processor Disclosure

Customer-facing page with current sub-processor list.

Security
Phishing + Awareness

Track staff training for ISO 27001 A.7.2.2 and SOC 2 CC1.4.

DPIIT
DPIIT Recognition

Track recognition, tax holiday, startup incentives.

Audit
Evidence Locker

One vault: policies, audit logs, vendor reports, training records, breach drill notes.

Coverage By Regulator

What dcomply Replaces

FrameworkWhy It Appliesdcomply Module
DPDP Act 2023You process Indian user data Data Privacy pack
ISO 27001:2022Enterprise buyer DD ISO 27001 Assessment
SOC 2 Type IIUS enterprise SaaS buyers SOC 2 Readiness
GDPREU users or EU customer base GDPR Compliance module
CCPACalifornia consumers (50K+) CCPA module
CERT-InCyber incident reporting CERT-In 6-hour intake
DPIITTax holiday + funding DPIIT tracker
vDPO Addon

DPDP Says You Need a DPO. We Become One.

B2B SaaS founders rarely have time to be the DPO themselves. And DPDP Section 10 makes it mandatory at scale.

dcomply vDPO bolts on from ₹2,499/mo. Standard tier adds a monthly human checkpoint. Premium gives you a dedicated advocate-DPO for buyer-facing legal questions.

See vDPO tiers
vDPO Standard₹7,999/mo

AI for the daily work + monthly human checkpoint. Popular for B2B SaaS.

  • Plain-English Q&A with citations
  • Monthly DPO PDF report
  • Document gap analysis
  • Vendor DPA assistant
  • 30-min monthly consultation
Built for SaaS & tech startups

PostgreSQL + S3 + Stripe is your stack. dcomply maps it.

Production DB, object storage, payment provider, lead CRM. Connect them; we find PII and surface DPDP + GDPR exposure in minutes.

PostgreSQL
Production DB
MongoDB
Document DB
AWS S3
Object storage
Google Sheets
Ops & analytics
Zoho CRM
Sales pipeline
Razorpay
Payment PII
SaaS compliance FAQs

Questions SaaS founders and heads of security actually ask.

Common on every early-stage SaaS implementation call.

B2B SaaS platforms process personal data on behalf of customers, making them Data Processors under DPDP Section 8. Obligations: written Data Processing Agreement with every customer, processing only per customer instructions, sub-processor disclosure, breach notification to customer within contractual SLA, and support for customer DSR requests. Plus ISO 27001 or SOC 2 for enterprise deals, CERT-In 6-hour breach rules, and GDPR if selling into the EU.

You are a Data Fiduciary for data you decide the purpose of: your own employees, sign-up leads, marketing contacts. You are a Data Processor for data your customers put into your product. Most SaaS is both simultaneously. dcomply supports separate processing records for each role with distinct DPAs and DSR workflows.

Not legally required, but almost every enterprise procurement now insists on one. ISO 27001:2022 is the more affordable and India-recognised option; SOC 2 Type II is preferred by US customers. dcomply's ISO 27001 and SOC 2 modules run the gap assessment, evidence collection and audit prep. Most SaaS achieves either in 4 to 6 months on the platform.

Section 8 read with DPDP Rules requires notifying customers of any new sub-processor with reasonable notice (typically 30 days). dcomply maintains a sub-processor register per tenant, auto-sends the change notification via email plus in-app plus DPA distribution list, and captures acknowledgements.

A DPDP DPA specifies purposes (limited to customer instructions), categories of data, categories of principals, retention (per customer instruction), sub-processors (with link to the maintained register), security measures, breach notification SLA, audit rights, and terms of data return and deletion on termination. dcomply's AI drafts one automatically from vendor metadata.

DPDP Section 16 allows cross-border transfer except to countries explicitly blocked by government notification. As of 2026 no country is blocked. Sector-specific rules (RBI localisation, DPDP Rules for children data, sectoral notices) may force India-only storage. dcomply flags each processing activity with a data-residency requirement.

No. dcomply is not an auditor. dcomply is the workspace that produces the evidence your SOC 2 auditor asks for. You still hire a qualified auditor for the report itself.

Same model. dcomply builds and maintains the control evidence. A certified body issues the certificate.

DPDP is Indian. GDPR is EU. Most SaaS companies with international users need both. The DSR module handles both request types in a single workflow.

Yes. Standard questionnaires (VSAQ, CAIQ, SIG) are pre-populated from your control evidence. Customers get answers in a day, not a week.

DPDP plus a basic vendor register are worth setting up from day one. SOC 2 usually starts around Series A when the first enterprise deals arrive.
Real teams, real programmes

"We closed three enterprise contracts we would have lost."

"We were losing enterprise deals on the security questionnaire. dcomply gave us the SOC 2 evidence base in eight weeks. We closed three enterprise contracts we would have lost."
Head of Security, a Series-B SaaS company from Bengaluru.

Start Free. Scale When You're Ready.

Pay-per-module from ₹1,499. Sector pack from ₹4,999. vDPO from ₹2,499.