India-first · DPDP-native · 35+ frameworks

Compliance,
on autopilot.

SOC 2, ISO 27001 and India's DPDP Act — monitored 24/7, evidenced automatically, audit-ready in weeks. One platform, one transparent price.

No credit card · Live demo: krishal@acme.com / trst1234

35+
frameworks
480+
requirements
100%
coverage
Hourly
monitoring

36 frameworks · one library

Every framework that matters — including the India ones.

Global standards and Indian regulation — DPDP, CERT-In, RBI, SEBI, IRDAI — in the same platform. Map your controls once, satisfy many. Add a framework, inherit most of it.

SOC 2

US · Global

SOC 2 Type II

The de-facto B2B SaaS trust report — Security, Availability, Confidentiality, Processing Integrity, Privacy.

Deliverable · Independent auditor's SOC 2 Type II report

ISO 27001

Global

ISO/IEC 27001:2022

International standard for an Information Security Management System — 93 Annex A controls.

Deliverable · Accredited ISO 27001 certificate + Statement of Applicability

DPDP

India

DPDP Act 2023

India's data-protection law — consent, notice, breach notification, data-principal rights. Enforcement 13 May 2027.

Deliverable · Audit-ready DPDP record + (SDF) DPIA & audit

GDPR

EU

EU General Data Protection Regulation

The gold-standard EU privacy regulation — lawful basis, data-subject rights, cross-border transfers.

Deliverable · GDPR compliance record + DPO advisory

HIPAA

US · Healthcare

HIPAA Security Rule

US health-data safeguards — administrative, physical and technical controls for PHI.

Deliverable · HIPAA compliance record + Security Rule assessment

PCI DSS

Global · Cards

PCI DSS v4.0

Payment card industry standard — 12 requirements for organisations that store, process or transmit cardholder data.

Deliverable · SAQ or QSA-issued Report on Compliance

NIST CSF

US · Global

NIST Cybersecurity Framework 2.0

Risk-based framework across Govern, Identify, Protect, Detect, Respond, Recover.

Deliverable · CSF profile + maturity assessment

ISO 42001

Global

ISO/IEC 42001:2023 (AI)

The first international standard for responsible AI — governance, lifecycle and data controls.

Deliverable · ISO 42001 certificate

RBI CSF

India · Banking

RBI Cyber Security Framework

Baseline cyber-security controls for banks & NBFCs, including 6-hour incident reporting.

Deliverable · RBI cyber-security compliance + audit

SEBI CSCRF

India · Capital Markets

SEBI Cyber Security & Resilience

Govern-Identify-Protect-Detect-Respond-Recover framework for SEBI-regulated entities.

Deliverable · SEBI CSCRF compliance + VAPT

CERT-In

India

CERT-In Directions (2022)

Mandatory 6-hour incident reporting, 180-day India-resident logs, KYC & clock-sync duties.

Deliverable · CERT-In compliance record

IRDAI

India · Insurance

IRDAI Information & Cyber Security Guidelines

Cyber-security guidelines for insurers — CISO, encryption, VAPT and incident reporting.

Deliverable · IRDAI cyber-security audit

+ 24 more:ISO 27701SOC 1NIST 800-53NIST 800-171CMMC 2.0FedRAMPHITRUSTCIS v8SOX ITGCCyber EssentialsEssential EightNIS2DORATISAXISO 22301ISO 9001CCPA/CPRALGPDPIPEDAPOPIAPDPA SGAU PrivacyCSA CCMNIST AI RMF
Start free — see coverage on your systems →

No credit card. Every framework at 100% coverage on day one via attested controls; monitoring flips them to evidence as you connect systems.

Everything an audit needs. Automated.

Built to clear the bar incumbents set — then beat it on price, residency and design.

24/7 autonomous monitoring

Agents continuously test your controls against live systems, catch drift within the hour, and remediate where it's safe — no spreadsheets, no screenshots.

One control library, every framework

Collect a piece of evidence once and it satisfies SOC 2, ISO 27001, DPDP and more at the same time. Add a framework, inherit most of it.

Immutable, hashed evidence

Every result is timestamped and SHA-256 hashed into an append-only timeline — the period-of-time, chain-of-custody proof auditors actually accept.

Auditor portal + sampling

Invite your CPA firm with read-only access. Statistical sampling (AICPA AU-C 530) over the audit window — exactly how a Type II is tested.

DPDP-native, India-first

Purpose-built for India's DPDP Act 2023, with data residency on infrastructure you control. Global frameworks included, not bolted on.

Transparent, all-in pricing

One price. Audits, trust center and frameworks included — no surprise add-on fees, no opaque quotes. The opposite of the incumbents.

Audit-ready in three steps

01

Connect your stack

Link AWS, GitHub, Okta, Google Workspace and more in minutes. Credentials are encrypted per-tenant with AES-256-GCM.

02

We monitor 24/7

Trst tests your controls every hour, maps evidence across all 35+ frameworks, and flags anything that drifts.

03

Hand auditors the proof

Export a dated, hashed evidence pack and a polished audit report — or give your auditor a live, read-only portal.

Transparent pricing. No surprises.

All-in — audits, trust center and monitoring included. The opposite of opaque enterprise quotes.

Starter
₹9,999/mo
Seed & early-stage
  • 1 framework (SOC 2 or ISO 27001 or DPDP)
  • Core connectors
  • Continuous monitoring
  • Trust center + evidence export
Start free
Most popular
Growth
₹24,999/mo
Most popular
  • Up to 4 frameworks
  • All connectors + auditor portal
  • Policy & personnel management
  • Risk register + vendor/TPRM
Start free
Scale
Custom
Multi-entity & enterprise
  • All 35+ frameworks
  • SSO/SAML + RBAC
  • Dedicated support
  • Custom data residency
Talk to us

Frequently asked questions

What exactly is Trst?+

An autonomous compliance platform. It continuously collects evidence from your systems, maps it across 35+ frameworks (SOC 2, ISO 27001, DPDP, HIPAA, RBI, SEBI and more), and keeps you audit-ready — so you stop chasing screenshots and spreadsheets.

Which frameworks do you support?+

SOC 2, SOC 1, ISO 27001:2022, ISO 27701, ISO 42001 (AI), India's DPDP Act 2023, GDPR, HIPAA, PCI DSS v4.0 and NIST CSF 2.0 — one control library mapped across all of them.

Does Trst issue my SOC 2 report or certificate?+

No — a licensed CPA firm (SOC 2) or accredited body (ISO) issues that. Trst prepares and continuously monitors the evidence they test, and gives your auditor a read-only portal. We make the audit faster and cheaper; we don't replace the auditor.

How long until I'm audit-ready?+

Most teams reach audit-readiness in weeks, not months, because evidence collection and control mapping are automated from day one.

Where is my data stored?+

On infrastructure located in India — important for DPDP data residency. Your compliance data doesn't leave the country.

Is it secure? You'll hold our credentials.+

Yes. Connector credentials are encrypted at rest with AES-256-GCM, traffic is TLS-only, access is least-privilege, and evidence is hash-verified and append-only. See our Security & Trust page.

How does the monitoring work?+

Once you connect a system (AWS, GitHub, Okta, Google Workspace…), Trst tests your controls every hour, records dated and hashed results, flags drift, and surfaces what needs attention.

What does it cost?+

Transparent, all-in pricing — audits, trust center and monitoring included, no surprise add-on fees. See Pricing above; start free, no credit card.

Get audit-ready. Start today.

Join the compliance platform built for India's next generation of software companies.