BFSI

Industries · BFSI & Fintech

Cloud for banks, NBFCs and fintechs. Compliant by design, resilient by default.

Regulated financial institutions need cloud that meets RBI, SEBI, IRDAI and CERT-In expectations without slowing product delivery. DevOps TechLab designs, secures and operates India-region cloud environments with the controls, logs and evidence your auditors and regulators look for.

  • ISO 27001and a SOC 2 report held by us
  • Indiaregions for data, backups and logs
  • 180 dayslog retention, as CERT-In requires
  • 6 hoursCERT-In reporting window supported
In short

DevOps TechLab designs and runs India-region cloud for banks, NBFCs and fintechs, with the controls, logs and evidence that RBI, SEBI, IRDAI and CERT-In audits expect.

ISO 27001 · SOC 2 · Working with companies across India and abroad from Ahmedabad, in IST

Who we serve

From fintech startups to banks and insurers.

Regulatory obligations scale with your licence and size. Our approach scales with them.

  1. Payments, lending and wealth platforms

    Fintech startups

    • A compliant landing zone before your first audit
    • Payment data kept in India from day one
    • Controls aligned to PCI DSS and ISO 27001
    • Evidence ready for bank and partner due diligence

    Typical engagementBuild, then co-managed

  2. Growing regulated entities

    NBFCs, brokers and co-operative banks

    • Gap assessment against RBI or SEBI directions
    • Managed security monitoring and log retention
    • Tested backup and disaster recovery
    • Audit evidence prepared every quarter

    Typical engagementManaged

  3. Large regulated institutions

    Banks, insurers and AMCs

    • Multi-account governance across business units
    • Integration with your SOC, SIEM and change processes
    • Hybrid connectivity to core and data centre systems
    • Support for regulatory inspections and audits

    Typical engagementManaged, alongside your teams

Regulations

The directions we build around.

The regulatory expectations that shape cloud in Indian financial services, and how our work supports each one.

  1. RBI Master Direction on Outsourcing of IT Services (2023)

    Board-approved outsourcing policy, due diligence, audit and access rights, and exit plans for IT and cloud providers.

    Vendor documentation, access and audit clauses support, exit runbooks.

  2. RBI Master Direction on IT Governance, Risk, Controls and Assurance (2023)

    IT governance, risk management, access control, change management, BCP and DR, and periodic assurance.

    Controls built into the landing zone, with evidence collected continuously.

  3. RBI storage of payment system data (2018)

    Payment system data stored only in systems located in India.

    India-region architecture for data, backups and logs.

  4. SEBI Cybersecurity and Cyber Resilience Framework (CSCRF, 2024)

    Governance, identification, protection, detection, response and recovery controls, with audits and reporting.

    Monitoring, log retention, tested recovery and audit evidence.

  5. IRDAI Information and Cyber Security Guidelines (2023)

    Information security policies, controls and audits for insurers and intermediaries.

    Security baselines, monitoring and evidence for audits.

  6. CERT-In Directions (2022)

    Report specified incidents within 6 hours and keep logs for 180 days within India.

    Detection, 180-day log retention in India and incident timelines.

  7. Digital Personal Data Protection Act (2023)

    Lawful processing, security safeguards and breach notification for personal data.

    Encryption, access controls and breach-response runbooks.

  8. PCI DSS

    Security requirements for systems that store, process or transmit card data.

    Segmented, PCI-scoped environments and evidence for your assessor.

A summary for orientation, not legal advice. Which directions apply depends on your licence and activities; we work alongside your compliance team.

Challenges

Where regulated cloud gets difficult.

Six challenges we see across fintechs, NBFCs, brokers, banks and insurers, and how we address each one.

  • StartupSMBEnterpriseData residency and localisation

    Payment data, backups and logs must stay in India, often across several providers and tools.

    India-region architecture end to end
  • SMBEnterpriseThe audit evidence burden

    Every audit and inspection asks for the same evidence, collected by hand from many systems.

    Evidence collected continuously
  • StartupSMBEnterpriseSix-hour incident reporting

    CERT-In requires specified incidents to be reported within six hours, with logs to support them.

    Detection, runbooks and 180-day logs
  • SMBEnterpriseOutsourcing and vendor risk

    RBI expects due diligence, audit rights and exit plans for every critical IT and cloud provider.

    Documentation and exit runbooks for every service
  • SMBEnterpriseLegacy systems and uptime

    Core and loan management systems run on ageing infrastructure with untested recovery.

    Hybrid connectivity and tested DR
  • StartupSMBEnterpriseFraud, ransomware and DDoS

    Financial services are a constant target, and an outage is also a regulatory event.

    Layered protection and continuous monitoring

Secure landing zone

A foundation built for regulated workloads.

Six control layers we design, build and document for every financial services environment, defined as code and owned by you.

  1. India-region boundary

    Guardrails that keep workloads, backups and logs in Indian regions.

    Layer 01
  2. Identity and privileged access

    Single sign-on, MFA, least privilege and recorded privileged sessions.

    Layer 02
  3. Network segmentation

    Separated environments, private connectivity, firewall and DDoS protection.

    Layer 03
  4. Encryption and key management

    Encryption at rest and in transit, with keys under your control.

    Layer 04
  5. Logging and monitoring

    Immutable logs kept for at least 180 days, with security alerts routed to on-call.

    Layer 05
  6. Backup and disaster recovery

    Backups and a recovery site within India, with drills on a schedule.

    Layer 06

Incident response

Ready for the six-hour window.

When an incident happens, the clock starts. We detect, contain and document so you can meet your reporting obligations.

6 hCERT-In reporting window
  1. 1
    0 hDetect

    Monitoring raises an alert and the on-call engineer starts the runbook.

  2. 2
    1 hTriage and contain

    Affected systems are isolated and evidence and logs are preserved.

  3. 3
    Within 6 hReport

    We prepare the facts and timeline so you can report to CERT-In within six hours.

  4. 4
    As requiredNotify regulators

    Supporting material for any RBI, SEBI or IRDAI reporting that applies to you.

  5. 5
    AfterRecover and review

    Systems restored, root cause documented and fixes tracked to closure.

Audit evidence

Evidence on demand, not on deadline.

We collect and maintain the evidence auditors and inspectors ask for, every quarter, so audits stop being projects.

Evidence pack8 sets kept current
  • Access reviewsQuarterly sign-off of who can reach production and data.
  • Change recordsEvery infrastructure change linked to an approved request.
  • Vulnerability and patch reportsScan results and patching status for every environment.
  • Log retention proofEvidence that logs are kept for 180 days, in India, unaltered.
  • Backup and restore testsScheduled restores with results recorded.
  • DR drill reportsRecovery drills against agreed targets, with findings.
  • Vendor and outsourcing fileDue diligence, contracts and exit plans for each provider.
  • Policies and runbooksSecurity, incident and recovery documents kept current.
ISO 27001certified
SOC 2report held

We hold both ourselves, and we prepare evidence the way auditors expect to see it.

Resilience

Recovery that is tested, not assumed.

Recovery targets agreed per system, built into the architecture and proven in regular drills.

  1. Tier 1 · Critical

    Payments, core banking or loan management, customer channels

    Recovery in minutes to an hour, with a warm standby in a second Indian region

  2. Tier 2 · Important

    Internal applications, reporting and analytics

    Recovery within hours from replicated backups

  3. Tier 3 · Standard

    Development, test and archives

    Recovery within a day from backups

Illustrative tiers. Actual recovery point and time objectives are agreed per system and tested in drills.

Workplace security

Secure workplace, one invoice.

Email, collaboration and devices configured to the same standard as your cloud.

  • Email and collaboration

    Microsoft 365 or Google Workspace with data loss prevention, retention and secure sharing.

  • Managed devices

    Laptops and mobiles enrolled, encrypted and wiped remotely when lost or returned.

  • Email and identity security

    Phishing protection, MFA and conditional access for every employee.

  • One GST invoice

    Cloud, licences and devices billed together, below list price.

Engagement models

Assess, build, operate.

Start with a gap assessment, build a compliant platform, then let us operate it with evidence ready for every audit.

Best for a first step

Assess

A gap assessment of your cloud against the RBI, SEBI, IRDAI and CERT-In expectations that apply to you, with a prioritised plan.

  • Findings mapped to each direction
  • Board-ready summary
Discuss assess →
Best for new platforms and migrations

Build

A compliant India-region landing zone and migration of your workloads. We are approved to run AWS MAP-funded migrations.

  • Controls and evidence built in
  • Runbooks and documentation you keep
Discuss build →
Best for ongoing assurance

Operate

Managed operations with security monitoring, 180-day log retention, DR drills and a quarterly evidence pack.

  • Evidence ready for every audit
  • Support during inspections
Discuss operate →

FAQ

Questions from risk and technology leaders.

Can RBI-regulated entities use public cloud?
Yes. Cloud adoption is permitted, subject to RBI’s directions on IT outsourcing and IT governance. Responsibility stays with the regulated entity, so we help you put the required due diligence, controls and documentation in place.
Will our data stay in India?
Yes. We design workloads, backups, logs and disaster recovery in Indian cloud regions, which also supports payment data localisation and CERT-In log requirements.
Do you support audit and access rights in contracts?
Yes. We work with your legal and compliance teams on agreements that include the audit, access and exit provisions regulators expect.
Do you report incidents to CERT-In for us?
Reporting is done by your organisation. We provide detection, preserved logs and a clear timeline so you can report within six hours.
Does DevOps TechLab hold ISO 27001 and SOC 2?
Yes. DevOps TechLab holds ISO 27001 certification and a SOC 2 report, available on request.
Can you bill in INR?
Yes. For companies in India we bill cloud usage and licences in INR on a GST invoice.

Talk to an engineer

Start with a 20-minute review. Leave with a plan.

An engineer looks at your current setup, points out what’s costing you money or risk, and tells you what we’d fix first. No sales deck, no obligation to go ahead.

Every month you wait, the bill grows, the audit gets harder and the AI project waits another quarter.

What do you need help with?*
We reply from a real inbox, not a bot.