Trust

What we hold, what we map, what is still to come

Sovereignty is a contract, a jurisdiction and a set of audited controls. This page separates the three honestly, because an auditor will.

01 · Certifications held

Current certifications

Held by BlueWhale Stack Consulting and Technologies FZE LLC as at June 2026.

ISO/IEC 27001:2022Certified

Information Security Management System.

Assessed by LMS Assessments
ISO 22301:2019Certified

Business Continuity Management System.

Assessed by AMERICO QSR
ISO/IEC 27017:2015Certified

Security controls for cloud services.

Assessed by SNS Certification
ISO/IEC 27018:2019Certified

Protection of personally identifiable information in public clouds.

Assessed by SNS Certification
ISO/IEC 27701:2019Certified

Privacy Information Management System.

Assessed by Staunchly MSS
GDPRCertified

Data protection compliance for EU personal data.

Assessed by SNS Certification
CSA STAR Level 1Certified

Cloud Security Alliance self-assessment, registry-listed.

Assessed by SNS Certification
SOC 2 Type IIReadiness assessed

Readiness assessed against the Trust Services Criteria. This is a readiness assessment, not a completed audit.

Assessed by SNS Certification
02 · Regulatory alignment

Frameworks we map controls to

Mapping is not certification. These are the obligations the platform is built to satisfy, and the evidence you would put in front of a regulator.

FrameworkWhat the platform doesStatus
CERT-In Directions (2022)6-hour incident reporting, 180-day log retention in-country, NTP sync to NIC/NPL, appointed Point of Contact.Controls mapped
DPDP Act 2023Data Processor obligations, breach notification workflow, India-resident processing by default, erasure on termination.Controls mapped
RBI Data LocalisationPayment system data stored only in India; annual System Audit Report by a CERT-In empanelled auditor.Controls mapped
SEBI CSCRFCybersecurity and Cyber Resilience Framework controls mapped for regulated intermediaries.Controls mapped
IRDAI Cyber GuidelinesControls mapped for insurers and intermediaries, including in-country DR.Controls mapped
GIGW 3.0Accessibility and usability guidelines for Indian Government portals.Controls mapped
03 · On the roadmap

Not yet held

An India public cloud needs these to sell into Government and regulated sectors. None is in place today. Each one says which door it opens and when we expect it, so you can plan around the gap rather than discover it during procurement.

CertificationScopeWhy it mattersExpected
MeitY Empanelment PlannedFull-stack empanelment (VPC, GCC, Managed Services).Gate for Government and PSU tendersTargeted with in-mum-1 and in-del-1 GA
STQC Audit PlannedInfrastructure and application security audit per MeitY guidelines.Prerequisite for MeitY empanelmentScheduled alongside empanelment
PCI DSS 4.0 PlannedLevel 1 Service Provider scope for the payments regions.Gate for card and payment workloadsAfter in-mum-1 GA
Uptime Institute Tier III PlannedConcurrently maintainable facility certification.Held by the data-centre partner, not by usPer-site, confirmed at each region launch
CERT-In Empanelled Auditor Report PlannedAnnual third-party audit of the platform.Required for RBI-regulated customersFirst cycle after GA
Why say this out loud. Every claim on this site is meant to be demonstrable in the 90-day prototype. A certification we do not hold is not demonstrable, so it sits in this table instead of the one above.
04 · Data residency

The five questions your CISO will ask

Where does my data live?

In the Indian region you choose, and nowhere else. Compute, block volumes, object storage, snapshots, backups and database replicas all stay inside that region unless you explicitly create a cross-region replica — and every destination we offer is also in India.

Where do the logs and telemetry live?

Control-plane logs, audit records, metrics and traces are stored in Mumbai and Delhi NCR. Nothing is shipped to a foreign SaaS observability vendor.

Who can access my data?

Only your account principals. BlueWhale support engineers need an explicit, time-boxed, ticket-linked grant from you before they can touch a resource, and every access is written to your audit log.

Which entity contracts with me?

BlueWhale Stack Consulting and Technologies Pvt Ltd, Mumbai. Indian law, Indian courts, Indian jurisdiction. BlueWhale Stack operates US, UAE and India entities; your contract is with the Indian one.

What about foreign government requests?

Data for Indian regions is held only in India. Indian lawful-access requests go through our published transparency process, and we notify you unless legally barred.

05 · By region

Which certifications reach which region

Certifications extend to a region when it reaches GA and completes its first audit cycle. Preview and under-construction regions run the same controls but sit outside audit scope.

RegionStatusISO 27001 / 27017 / 27018ISO 27701SOC 2 readinessMeitY (planned)
Mumbai in-mum-1GA
Delhi NCR in-del-1GA
Bengaluru in-blr-1GA
Hyderabad in-hyd-1preview
Chennai in-maa-1building
Kolkata in-ccu-1planned
Certified entity: BlueWhale Stack Consulting and Technologies FZE LLC unless otherwise noted. SOC 2 Type II is a readiness assessment against the Trust Services Criteria, not a completed audit. BlueWhale Stack does not hold ISO 9001. Certificates and the full control matrix are available from the Trust Center under NDA.

Need the certificates?

ISO certificates, the SOC 2 readiness letter and our standard DPA are downloadable from the console once you have an account.