01
Will this work with the security tools we already have?
Yes. That's how we prefer to start. In Step 02 (Plan) we map every tool you already own, score what's working, and keep what earns its keep. We replace only what doesn't. Most clients retain 40–70% of their existing stack; we integrate around it. No rip-and-replace.
02
What's included in the monthly fee, and what costs extra?
Included: 24×7 SOC, SIEM/EDR/NDR licences, full compliance programme management, continuous VAPT, dedicated compliance manager, named SOC analyst, board & client reports, and a 15-minute response SLA. Extra: audit firm fees (charged by the auditor, not us), any bespoke integration engineering beyond the scoped stack.
03
Who owns our data, policies, and evidence?
You do. All of it. Security telemetry, compliance evidence, policies, audit artifacts: every byte is owned by your company and exportable by you at any time. Our contract language explicitly states NxgSecure has no rights to your data beyond providing the service. If you leave, everything leaves with you.
04
What's the exit process if we decide to move on?
30-day notice, no exit fees. We deliver a complete handover package (policies, evidence, playbooks, current posture snapshot, open tickets, vendor accounts) in a format you or your next partner can pick up. We'll even run joint sessions with a successor vendor for up to 4 weeks. We believe good exits make good partnerships.
05
How is this different from Sprinto, Scrut, or Vanta?
Those are compliance automation platforms — excellent at collecting evidence and tracking controls. But they sit on top of your security. You still need someone to build, configure, and run the security underneath — the actual monitoring, detection, response, and testing.
NxgSecure is the complete stack: security operations and compliance, delivered as one managed programme, one contract, one accountable team. We implement the security, run it 24×7, and the compliance evidence flows from it continuously. No assembly required.
06
What actually happens in the first 48 hours?
Hour 0–4: read-only access to your key systems (Azure/AWS, Microsoft 365 / Google Workspace, existing EDR). Hour 4–24: automated discovery runs across identities, devices, systems. Hour 24–48: written assessment delivered: your current posture score, top 10 risks, compliance gap map, and a specific plan. Zero commitment to continue. You own the report either way.
07
Do you work with Indian and global regulators in parallel?
Yes. One control mapped once can satisfy multiple regimes. DPDPA + ISO 27001 share ~60% of controls; SOC 2 + GDPR overlap another 50%+. Our compliance engine tracks the intersection so you don't re-run the same evidence collection for every audit. A fintech client runs RBI + SOC 2 + DPDPA from a single programme. A healthtech client runs HIPAA + ISO 27001 + DPDPA.
08
Do we need an internal security team to work with you?
No. We work alongside whoever you already have — usually IT or DevOps. They keep their role; we take the security and compliance load off their plate. If you don't have anyone today, we work directly with leadership.
09
Where does our data reside? Can you guarantee it stays in India?
NXG360, our visibility and compliance platform, runs on AWS India — your data stays in-country. For the broader security stack, the majority of tools we deploy have India data centres. In some cases, depending on the tool selected, certain telemetry may be processed outside India — but we ensure this never violates DPDPA or any applicable regulatory requirement. During Step 02 (Plan), we map every data flow against your regulatory obligations and flag anything that needs attention before deployment.
10
Is there still time to become DPDPA compliant before the deadline?
Yes. The DPDPA compliance deadline is May 13, 2027, and the security safeguards component — which carries the highest exposure at up to ₹250 crore — is the most implementation-heavy part. The good news: if you already have a baseline security stack and some form of ISO 27001 or SOC 2, you're closer than you think. Roughly 60% of those controls map directly to DPDPA requirements. Even if you're starting from scratch, we can get you to a DPDPA-compliant posture within one month. The free assessment in Step 01 (Discover) will tell you exactly where you stand and how long your specific path will take.
11
What happens if something goes wrong?
We don't disappear — that's the whole point of the accountability model. A named human leads the response from minute one, no emergency or call-out fees, ever. You get a full post-incident report with root cause and remediation, and we handle any regulatory documentation your compliance regime requires. It's written into your SLA.