Vendor risk management,
built for Indian compliance.
Inventory your vendors. Send DPDP / RBI / SEBI / IRDAI / ISO 27001 / SOC 2 security questionnaires. Get alerted when vendors are breached. Export audit-ready evidence packs in one click. From ₹5,000/month — DPDP-defensible from day one.
Built for Indian businesses regulated by
Everything you need to defend your vendor risk programme.
No more spreadsheets. No more email chains. No more "remind me, what SOC 2 do we have on file for them?"
Vendor inventory
Add vendors manually or import via CSV. Tag criticality, data sensitivity, contract dates, evidence on file.
Smart questionnaires
Pre-built templates for DPDP, RBI, SEBI, IRDAI, ISO 27001, SOC 2. Send via email — vendor fills in browser, no account needed.
Document repository
SOC 2, ISO 27001, DPA, pen-test letters, cyber insurance. Auto-track expiry. Audit-ready.
Risk scoring
Inherent + residual scores per vendor. Automated heat-map across your supply chain.
Breach alerts
Daily monitoring against HaveIBeenPwned, CERT-In bulletins, news. Alert when a vendor is breached.
Cert expiry alerts
60 / 30 / 7-day reminders before SOC 2 / ISO certificates expire. Never get caught at audit.
One-click audit pack
Export a PDF mapped to RBI / SEBI / IRDAI / DPDP / ISO 27001 / SOC 2 control IDs. Ready for the auditor.
Team workspaces
Owner / admin / member / viewer roles. Audit-trailed. SCIM provisioning on Pro.
India-first
Singapore-region storage with India residency option. Razorpay billing in INR. DPDP-defensible architecture.
From spreadsheet chaos to audit-ready in 30 days.
Add your vendors
Import or type — typical onboarding takes 30 minutes for 50 vendors. We auto-classify by data sensitivity.
Send questionnaires
Pick a framework template, send to the vendor contact. Vendor fills in browser; responses populate automatically.
Collect evidence
Vendors upload SOC 2, ISO, DPA. We track expiry and alert before renewal.
Monitor + report
Daily breach scanning. Quarterly continuous attestation. One-click audit-pack PDF for the regulator.
Eight pre-built questionnaire libraries.
No more building DPDP DPAs from scratch in Word. We've done it.
Indian-SMB pricing. No annual lock-in.
All plans are monthly. Cancel anytime. Pay in INR via Razorpay.
For trying the product with a few vendors.
- 5 vendors
- 1 questionnaires/month
- 1 team members
- 0.1 GB storage
- Breach monitoring
- Cert expiry alerts
- Audit-pack PDF export
- Custom questionnaires
- API access
- Priority support
For small teams getting their vendor risk programme off the ground.
- 25 vendors
- 25 questionnaires/month
- 3 team members
- 0.5 GB storage
- Breach monitoring
- Cert expiry alerts
- Audit-pack PDF export
- Custom questionnaires
- API access
- Priority support
For mid-market businesses with multi-framework compliance pressure.
- 100 vendors
- 200 questionnaires/month
- 10 team members
- 5.0 GB storage
- Breach monitoring
- Cert expiry alerts
- Audit-pack PDF export
- Custom questionnaires
- API access
- Priority support
For Q-RE / MII / SDF organisations needing premium audit support.
- Unlimited vendors
- Unlimited questionnaires
- Unlimited team
- 50.0 GB storage
- Breach monitoring
- Cert expiry alerts
- Audit-pack PDF export
- Custom questionnaires
- API access
- Priority support
Need bigger? Talk to sales for custom volume + private deployment.
Common questions
Do you store our vendor data in India?+
Primary storage is in Singapore (AWS ap-southeast-1) for low Indian latency. Pro plan customers can request India-region storage (AWS ap-south-1) for sectoral compliance. We do not store vendor data outside these regions.
How is this different from Drata / Vanta TPRM?+
Drata and Vanta are excellent for SOC 2 / ISO 27001 / HIPAA but weak on Indian sectoral regulations. We are India-first: RBI Cyber Framework, SEBI CSCRF, IRDAI 2023, DPDP Act, ABDM. And our pricing fits Indian SMB budgets — Drata starts at $999/month; we start at ₹5,000/month.
Does the vendor need an account to respond to questionnaires?+
No. We email a unique link; they fill it in browser; submission lands in your dashboard. Zero friction.
Can I import my existing vendor list?+
Yes. CSV import on every paid plan. Free plan supports manual add only.
What happens if I cancel?+
You keep read-access for 30 days. Audit pack export remains available. Your data is hard-deleted after 30 days unless you reactivate.
Do you sign a DPA?+
Yes. Standard DPA available on Starter and above. Custom DPA negotiation included on Pro plan.
Is there an annual contract?+
No. All plans are month-to-month. Annual discount (15%) available on request.
How do you stay current with changing regulations?+
RingSafe is a practising consultancy — we maintain the questionnaire library as part of our daily client work. Frameworks update within 30 days of regulatory changes.
Your next vendor breach hasn't happened yet.
Get RingSafe Trust on it before it does. Free for 5 vendors — no card, no commitment.