Evidence that exists before the auditor asks.
Most organisations pass audits by reconstruction — someone spends three weeks assembling screenshots to prove that monitoring was running last March. Hello SOC produces the evidence continuously, signed and dated, on a chain that cannot be quietly rewritten afterwards.
- →Signed monthly report and weekly digest, every period
- →Tamper-evident audit chain over alerts, actions and approvals
- →Daily integrity receipt so the record is not just self-verified
- →Mapped to RBI, CERT-In, DPDP, ISO 27001 and SOC 2
What lands in the audit file
Four artefacts, produced on a schedule, whether or not an audit is coming.
Signed monthly report
A dated PDF covering incidents raised, actions taken and their outcomes, plus coverage across your monitored estate. This is the artefact that goes into the audit file — the same document every month, so a reviewer can compare periods rather than interpret a fresh format each time.
Weekly admin digest
Open and closed-this-week incidents to your named administrators every Monday. Its compliance value is not the content but the cadence: it demonstrates that monitoring was live and being reviewed continuously, which is the control most audits actually test.
Tamper-evident audit chain
Every auditable event is written to an append-only chain where each entry cryptographically covers the one before it. Any retroactive edit or deletion breaks verification from that point forward, so the record cannot be quietly rewritten — by anyone, including us.
Daily integrity receipt
The head of your chain is emailed to you each day. Once that hash is in your mailbox, we cannot rewrite history without producing a different value than the one you already hold. Self-verification proves nothing; this is what makes the chain evidence rather than assertion.
Frameworks this evidence supports
The same monitoring pipeline answers the logging-and-monitoring control in every one of these. What differs is the format the evidence is presented in.
| Framework | Applies to | What Hello SOC evidences |
|---|---|---|
| RBI Cyber Resilience Framework | India · Banks & co-operative banks | Continuous surveillance, logging and monitoring, incident detection and response — with the monthly report as standing evidence and a risk-prioritised incident summary your risk register can cite. |
| CERT-In directions (2022) | India · All organisations | Detection already running so "when did we notice" is a timestamp rather than a reconstruction, incident rollup with a full timeline, and a pre-formatted notification so the reporting window is spent filling fields, not designing a document. |
| DPDP Act 2023 | India · Data Fiduciaries | Reasonable security safeguards operating 24×7 and evidenced, personal-data-breach detection with an incident timeline, and an audit trail built for the Data Protection Board. |
| ISO 27001:2022 | Global | Evidence for the logging, monitoring and incident-management controls — A.8.15 through A.8.16 and A.5.24 onward — as a continuous record rather than a screenshot taken the week before the audit. |
| SOC 2 Type II | USA · Service organisations | Type II tests operating effectiveness across a period, not a point in time. Continuous monitoring with a dated, signed monthly artefact is exactly the form of evidence that period-of-time testing asks for. |
| DORA / NIS2 | EU & UK | ICT risk monitoring and incident-reporting readiness for in-scope financial entities and essential services, drawn from the same detection and evidence pipeline. |
Hello SOC supplies technical monitoring evidence. It is not a certification body, an auditor, or legal advice on compliance. For the honest line-by-line split on the DPDP Act — including what stays with you — see the DPDP coverage mapping.
What we don’t do
Worth stating plainly, because “compliance services” is a term vendors stretch until it means nothing.
We do not certify you
No vendor can. Certification comes from an accredited auditor assessing your whole programme. We are one input to that assessment.
We do not write your policy
Governance documents, training programmes and access-review processes are organisational work. We evidence the monitoring control, not the management system around it.
We do not file on your behalf
A regulatory notification is a legal filing made by your organisation. We prepare it in the required format and start the clock with facts in hand; you submit it.
Compliance services — questions we get
- What compliance services does Hello SOC actually provide?
- Hello SOC produces the continuous monitoring evidence that security frameworks require: signed, dated monthly reports, a weekly digest to named administrators, incident timelines with the response actions taken, and a tamper-evident audit chain covering every alert, action and approval. That evidence set is mapped to the RBI Cyber Resilience Framework, CERT-In directions, the DPDP Act 2023, ISO 27001 and SOC 2. What we provide is the technical monitoring evidence layer, produced continuously rather than assembled the month before an audit.
- Does Hello SOC make my organisation compliant or certify us?
- No, and any vendor telling you otherwise is selling something. Hello SOC is not a certification body, an auditor or a law firm. Compliance is an organisational programme covering governance, policy, training, application controls and legal interpretation; monitoring is one control within it — an important one that many organisations fail on, but one control. We supply the evidence for that control, honestly scoped, so your auditor, DPO or CISO can see exactly what is covered and what still sits with your team.
- What is a tamper-evident audit chain, and why does it matter?
- Every auditable event is written to an append-only record where each entry contains a cryptographic hash covering the previous entry. Changing or deleting any earlier entry changes its hash, which breaks verification for every entry after it. It matters because the usual audit-log promise is circular: a log we hold, verified by us, proves only that we are internally consistent. The chain closes that gap by making retroactive edits detectable rather than asking you to trust us.
- If you hold the database, why should I trust your audit chain?
- You should not, on its own — which is why we anchor it. Each day the current head of your chain is published to you by email. Once you hold "on this date the head was this value", rewriting history means producing a different hash at that point than the one already sitting in your mailbox, and we cannot reach into your inbox to change what we already sent. Only a 32-byte hash is published, so the receipt itself discloses no personal data. For engagements that need a stronger independence guarantee, the chain head can additionally be timestamped by an external RFC 3161 authority.
- Will Hello SOC file our CERT-In incident report for us?
- We prepare it; you submit it. Hello SOC detects the incident, rolls up the timeline, and produces the notification in CERT-In format so the reporting window is spent reviewing facts rather than reconstructing them. The actual submission to CERT-In or the RBI remains the regulated entity’s action — it is a legal filing made by your organisation, and it is not something a monitoring provider can or should do on your behalf.
- How much of my audit does this cover?
- Honestly, one section of it. For the logging, monitoring and incident-response controls, it covers the substance rather than a checkbox. For governance, policy, training, access reviews, application-layer controls, consent management and data-principal rights, it covers nothing — those live in your organisation and your product. We publish that split explicitly on our DPDP page rather than making you discover it during the engagement.
Have a checklist row you need to answer?
Send us the specific line item — an RBI control, an ISO annex reference, a SOC 2 criterion — and we’ll reply with exactly what we evidence and what we don’t.