For SEBI-regulated entities
SEBI’s Cybersecurity & Cyber Resilience Framework asks regulated entities to demonstrate their controls — in recurring audits, not once. Sanad is the evidence layer: it collects, signs and preserves the proof your auditor asks for, continuously.
The framework
CSCRF (SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113) consolidates SEBI’s cybersecurity expectations for stockbrokers, investment advisers and other intermediaries, graded by entity category.
What it demands
Not just controls, but demonstrable ones: asset inventories, incident-response records, policies, log trails and audit reports — maintained and producible on request.
What stacks on top
The same entities also carry CERT-In’s 6-hour incident reporting and 180-day log mandates, and DPDP Act duties for client personal data. Sanad covers all three from one deployment.
Six categories of proof, produced and signed as a by-product of normal operation.
The Sentinel agent reports installed software, patch status, disk encryption and endpoint posture from every Windows machine — an inventory your auditor can trace to hardware-attested telemetry, not a spreadsheet.
From detection to CERT-In dispatch, every step is timestamped and signed. The 6-hour clock is tracked for you, and the record of when you knew and when you reported is tamper-evident.
Pre-configured templates for the cybersecurity policy, incident-response SOP, data-encryption and vendor-security policies CSCRF expects — each version signed on creation and verifiable by number.
Windows event logs are collected, minimised for privacy, HMAC-signed in batches and retained on Indian storage — with a coverage ledger showing exactly which windows were captured.
Security-awareness sessions — including CSCRF-specific modules for trading-desk and vendor-governance staff — recorded as signed artifacts with attendance and content.
Your vendor lifecycle — registration, risk classification, DPA status, review dates — kept as chained records, ready for the supply-chain questions every CSCRF review asks.
Every artifact carries an Ed25519 signature and a position in a hash-chained ledger. Your auditor — or SEBI — can verify a record without trusting our word for it.

Sanad does not replace your CSCRF auditor, your VAPT provider or your SOC. It makes their job — and yours — dramatically easier by ensuring that when evidence is requested, it exists, it is signed, and it has not been altered. That is the part audits actually fail on.