Reference

The regulatory map.

Which statute drives which system requirement — and the platform or practice we answer it with. This is the map our compliance products are built against.

SEBI (Prohibition of Insider Trading) Regulations, 2015

A structured digital UPSI database, pre-clearance for designated persons, trading window controls and continual disclosure tracking — all reconstructible on demand.

What the system must do

Append-only UPSI register, multi-level trade approval workflow, window state enforced at approval time, regulator-ready MIS reporting.

Insider Trading Compliance Platform

Companies Act, 2013

Board and general meetings properly convened and minuted, statutory registers maintained and current, filings made on statutory timelines.

What the system must do

Meeting lifecycle automation, version-controlled digital registers, compliance calendar with ownership and escalation.

Corporate Secretarial Suite

Vigil mechanism — Companies Act §177 & SEBI LODR

A confidential channel for directors and employees to report concerns, with safeguards against victimisation and board-level oversight.

What the system must do

Anonymous intake with no identifying metadata, encrypted investigator dialogue, case management with audit-committee reporting.

Whistleblower Management System

DPDP Act, 2023

Personal data processed for stated purposes with consent, security safeguards, breach notification and erasure on request.

What the system must do

Purpose-scoped data models, consent records, encryption at rest and in transit, retention and erasure enforced in code.

Custom compliance engineering

HIPAA (US health data)

Administrative, physical and technical safeguards for protected health information — access control, audit logging, transmission security.

What the system must do

Role-based access with least privilege, immutable audit logs, encrypted PHI, documented breach procedures.

Healthcare engineering

IRDAI norms (insurance)

Policyholder data protection, outsourcing controls and auditable operational processes for insurers and intermediaries.

What the system must do

Segregated data environments, vendor-access controls, process workflows with complete audit trails.

Financial services practice

Ready to transform your business with custom software?

Share your project requirements and we'll come back with a tailored solution — scope, architecture and a realistic timeline.

What happens next

  1. Tell us the business problem, the constraints and the deadline you're working to.
  2. We come back with a proposed approach, technology stack and delivery roadmap.
  3. Agree scope and start with discovery — requirements, feasibility and a project roadmap.
Mon–Fri, 9:00 AM – 7:00 PM IST · insights@craft360.in