Skip to content
Now taking design partners.Roadmap →

CERT-In, DPDP, SEBI CSCRF, RBI, IRDAI, NCIIPC

Compliance evidence · India

Sekeye produces the AI-agent, MCP, and software inventory, exposure, and IR evidence Indian regulators demand, with data residency and self-hosted deployment.

Request evidence packMapping updated

What we mean by "produces evidence"

Sekeye does not grant compliance. It produces the artefacts these clauses require you to demonstrate, inventory, exposure, and incident-response timeline, for the AI agents and MCP servers running across your hosts as well as the software layer beneath them, inside your data-residency perimeter.

Treat this page as supporting material. The reason to run Sekeye is that AI agents hold credentials, shell, and egress on your laptops and servers, and nothing in the existing stack governs them. The regulatory mapping below is what falls out of governing that surface properly.

CERT-In (April 2022 Directions)

  • Six-hour reporting. A launched campaign identifies affected hosts and the exposure window per machine, including which agents and MCP servers were configured at the time, feeding the incident report.
  • 180-day log retention, within India. Inventory deltas, findings, and campaign results are retained in-region for self-hosted deployments.
  • In-scope events. Malicious code, data breaches, and supply-chain incidents are named explicitly. A malicious MCP server or a compromised agent client falls inside the reporting obligation the same way a Shai-Hulud-class npm worm does.

DPDP Act 2023 (with Rules 2025)

  • Section 8(5) reasonable safeguards. Documented control over the AI agents and self-installed software running on your hosts supports the safeguards defence, particularly where an agent can reach personal data.
  • Monitoring for unauthorised access. Inventory deltas and findings logs are audit-ready evidence.
  • Breach scope determination. Campaign results identify which hosts ran an exfiltrating artefact, or configured a malicious MCP server, in the exposure window, required for a defensible DPIA.
  • Penalty exposure. Failures to implement safeguards can attract penalties up to ₹250 crore. Documented posture reduces that exposure.

SEBI CSCRF (August 2024)

  • Asset inventory including software, with critical / non-critical classification. Fleet inventory plus tagging.
  • SBOM mandate for critical systems, including transitive dependencies. Exportable CycloneDX per endpoint.
  • Vulnerability management with timely closure. Continuous CVE match, closure-state tracking, evidence trail.
  • May 2026 AI advisory. Adopt AI-based vulnerability detection and maintain SBOM upkeep, the AI-agent and MCP coverage lands squarely here, and this is the clause most likely to be asked about at your next audit.

RBI Cyber Security Framework (2016 and 2023 Master Direction)

  • Up-to-date inventory of authorised and unauthorised software. Fleet inventory of the AI-agent and MCP layer plus the self-installed software layer, the surface your EDR tier watches least closely.
  • Mechanism to control software installation. Unauthorised-artefact alerts today; gating and Ask-to-Install for agent surfaces are on the roadmap, not shipped.
  • Vulnerability and patch management, rapid incident reporting. Findings queue and RBI-facing evidence exports.

IRDAI (2023) and NCIIPC (CII)

Mirrors RBI and SEBI on asset management, vulnerability management, and incident reporting. Self-hosted and air-gapped deployment qualify for CII data-locality requirements.