Sovereignty is a contract, a jurisdiction and a set of audited controls. This page separates the three honestly, because an auditor will.
Held by BlueWhale Stack Consulting and Technologies FZE LLC as at June 2026.
Information Security Management System.
Business Continuity Management System.
Security controls for cloud services.
Protection of personally identifiable information in public clouds.
Privacy Information Management System.
Data protection compliance for EU personal data.
Cloud Security Alliance self-assessment, registry-listed.
Readiness assessed against the Trust Services Criteria. This is a readiness assessment, not a completed audit.
Mapping is not certification. These are the obligations the platform is built to satisfy, and the evidence you would put in front of a regulator.
| Framework | What the platform does | Status |
|---|---|---|
| CERT-In Directions (2022) | 6-hour incident reporting, 180-day log retention in-country, NTP sync to NIC/NPL, appointed Point of Contact. | Controls mapped |
| DPDP Act 2023 | Data Processor obligations, breach notification workflow, India-resident processing by default, erasure on termination. | Controls mapped |
| RBI Data Localisation | Payment system data stored only in India; annual System Audit Report by a CERT-In empanelled auditor. | Controls mapped |
| SEBI CSCRF | Cybersecurity and Cyber Resilience Framework controls mapped for regulated intermediaries. | Controls mapped |
| IRDAI Cyber Guidelines | Controls mapped for insurers and intermediaries, including in-country DR. | Controls mapped |
| GIGW 3.0 | Accessibility and usability guidelines for Indian Government portals. | Controls mapped |
An India public cloud needs these to sell into Government and regulated sectors. None is in place today. Each one says which door it opens and when we expect it, so you can plan around the gap rather than discover it during procurement.
| Certification | Scope | Why it matters | Expected |
|---|---|---|---|
| MeitY Empanelment Planned | Full-stack empanelment (VPC, GCC, Managed Services). | Gate for Government and PSU tenders | Targeted with in-mum-1 and in-del-1 GA |
| STQC Audit Planned | Infrastructure and application security audit per MeitY guidelines. | Prerequisite for MeitY empanelment | Scheduled alongside empanelment |
| PCI DSS 4.0 Planned | Level 1 Service Provider scope for the payments regions. | Gate for card and payment workloads | After in-mum-1 GA |
| Uptime Institute Tier III Planned | Concurrently maintainable facility certification. | Held by the data-centre partner, not by us | Per-site, confirmed at each region launch |
| CERT-In Empanelled Auditor Report Planned | Annual third-party audit of the platform. | Required for RBI-regulated customers | First cycle after GA |
In the Indian region you choose, and nowhere else. Compute, block volumes, object storage, snapshots, backups and database replicas all stay inside that region unless you explicitly create a cross-region replica — and every destination we offer is also in India.
Control-plane logs, audit records, metrics and traces are stored in Mumbai and Delhi NCR. Nothing is shipped to a foreign SaaS observability vendor.
Only your account principals. BlueWhale support engineers need an explicit, time-boxed, ticket-linked grant from you before they can touch a resource, and every access is written to your audit log.
BlueWhale Stack Consulting and Technologies Pvt Ltd, Mumbai. Indian law, Indian courts, Indian jurisdiction. BlueWhale Stack operates US, UAE and India entities; your contract is with the Indian one.
Data for Indian regions is held only in India. Indian lawful-access requests go through our published transparency process, and we notify you unless legally barred.
Certifications extend to a region when it reaches GA and completes its first audit cycle. Preview and under-construction regions run the same controls but sit outside audit scope.
| Region | Status | ISO 27001 / 27017 / 27018 | ISO 27701 | SOC 2 readiness | MeitY (planned) |
|---|---|---|---|---|---|
| Mumbai in-mum-1 | GA | ✓ | ✓ | ✓ | — |
| Delhi NCR in-del-1 | GA | ✓ | ✓ | ✓ | — |
| Bengaluru in-blr-1 | GA | ✓ | ✓ | ✓ | — |
| Hyderabad in-hyd-1 | preview | — | — | — | — |
| Chennai in-maa-1 | building | — | — | — | — |
| Kolkata in-ccu-1 | planned | — | — | — | — |
ISO certificates, the SOC 2 readiness letter and our standard DPA are downloadable from the console once you have an account.