Scope of work
- AI governance frameworks, model cards, and use-case risk classification
- SaaS terms of service, acceptable use, and DPA suite
- IT Act compliance — intermediary obligations, grievance officer, takedowns
- CERT-In directions — logging, retention, and 6-hour incident reporting
- Cyber incident response — breach notifications and regulator liaison
- eCommerce Rules, consumer protection, and dark-pattern advisory
Deliverables
- AI governance policy and product-launch review
- SaaS ToS, DPA, and acceptable-use policy
- IT Act compliance pack including grievance mechanism
- Incident response playbook with contact tree
Timeline
01. Diagnostic
Week 1Map products, data flows, and regulatory touchpoints.
02. Documentation
Week 2–4Deploy policies, contracts, and playbooks.
03. Retainer
OngoingAd-hoc queries, launch reviews, and incident support.
Timelines are indicative. Regulatory processing times and third-party responses may vary.
Frequently asked questions
Do you review AI features before launch?
Yes — we run pre-launch risk reviews covering IP, privacy, IT Act, and consumer-protection exposure for AI features.
What are CERT-In reporting timelines?
Cyber incidents must be reported to CERT-In within 6 hours of noticing. We build the playbook, template, and escalation tree.
Do you help with US and EU tech regulations?
Yes — including CCPA, GDPR, EU AI Act, and DSA — through our cross-border network.
Related services
Explore adjacent workstreams we handle under the same single-window engagement.
Company Incorporation & Startup Setup
From idea to legally incorporated entity — done right, once.
Trademark Registration & Brand Protection
Own your name, logo, and tagline — before someone else does.
Vendor & Supplier Contract Advisory
Bulletproof contracts with the third parties your business depends on.
Ready to get started?
Book a consultation with Vrushali Borade to discuss your requirements and get a fixed-scope proposal.
