# SemperWise — a Radiatus Group company > An AI-first cybersecurity and enterprise intelligence practice in the Radiatus Group. We deliver end-to-end security services — VAPT and penetration testing, web, API and mobile application security testing, network and cloud assessment, secure code review, and ISO 27001 / SOC 2 / DPDP compliance — and build SemperWise One™, a cloud-native SaaS platform on AWS that unifies security, compliance, risk and AI governance in one dashboard. **Tagline:** Always Wise. Always Ahead. · AI Powered. Human Trusted. **Founded by:** practitioners with 20+ years of combined experience across cybersecurity, cloud, compliance, healthcare and enterprise technology. **Status:** early-stage practice in the Radiatus Group, registered in India, Micro enterprise (MSME). **Contact:** info@semperwise.com · +91-95851-60363 · The Green, 8, STE 15273, Dover, DE 19901, USA (primary) · Coimbatore – 641035, Tamil Nadu, India (operations). **Serves:** clients across India and internationally. Response within 24 business hours. ## What makes SemperWise different - Every finding in every report is verified by a human before delivery. Automation produces candidates; a person confirms exploitability and business impact. Reports are short because of it. - A retest cycle is included in every testing engagement at no extra cost, with per-finding state change recorded. - Findings are pre-mapped to ISO 27001 Annex A, PCI DSS, HIPAA, NIST CSF and OWASP ASVS, so remediation doubles as audit evidence. - Fixed written scope and fixed price after one 30-minute call. No day rates that expand. - The people who scope an engagement are the people who deliver it. - Client names are never published: security testing engagements are covered by NDA. ## Detection coverage (as of 22 September 2026, engine v4.21) Published deliberately as scale, not methodology. Payloads, sequencing and tooling chains are not disclosed. - **68,282 detection rules** across **299 technology definition packs** covering **69 languages and runtimes**, with **3,084 stack fingerprints**. Severity split: 13,831 Critical · 28,318 High · 17,505 Medium · 7,546 Low · 1,082 Informational. Rule classes: 40,656 misconfiguration · 7,249 default-credential/default-config · 5,856 hardening-baseline · 4,040 business-logic · 6,709 AI-generated-code mistakes · 2,859 deprecated-API · 788 version-specific · 125 end-of-life. - **13,742 active test templates**, refreshed continuously. - **377,333 CVEs** carrying EPSS exploit-probability scores, refreshed daily. - **230,993-row version-to-CVE index**, so findings name the exact affected build. - **1,717 known-exploited vulnerabilities** (CISA KEV catalogue) tracked and escalated regardless of CVSS. - **95+ security tools** orchestrated under one pipeline, **41 assessment modules**, **8 assessment types**, **24 report artefacts**. - **40 finding categories** mapped inline to 9 compliance frameworks. Output includes SARIF and JSON as well as PDF and HTML. Full breakdown: https://semperwise.com/detection-coverage ## Services ### Security testing - [VAPT Services](https://semperwise.com/vapt): vulnerability assessment and penetration testing, end to end. Web, API, mobile, network, cloud, code, Active Directory and wireless. - [Web Application Security Testing](https://semperwise.com/web-application-security-testing): authenticated multi-role testing against OWASP Top 10, ASVS and WSTG, including business-logic flaws. - [API Security Testing](https://semperwise.com/api-security-testing): REST, GraphQL and microservices against the OWASP API Security Top 10. Broken object-level authorisation is the most common critical finding. - [Mobile Application Security Testing](https://semperwise.com/mobile-application-security-testing): Android and iOS against OWASP MASVS, plus backend API testing. - [Network Penetration Testing](https://semperwise.com/network-penetration-testing): external perimeter, internal, Active Directory, segmentation, CIS benchmark scoring. - [Cloud Security Assessment](https://semperwise.com/cloud-security-assessment): AWS, Azure, GCP and Kubernetes configuration, IAM permission paths, CIS benchmarks, infrastructure as code. - [Secure Code Review](https://semperwise.com/secure-code-review): manual expert review plus static analysis across 27 languages, with SARIF export. - [Red Team Assessment](https://semperwise.com/red-team-assessment): objective-based adversary simulation mapped to MITRE ATT&CK, with purple team option. - [Attack Surface Management](https://semperwise.com/attack-surface-management): continuous external discovery, shadow IT, change alerting. ### Compliance and advisory Each framework has its own page. The hub is a map, not a substitute for them. - [Compliance & Audit](https://semperwise.com/compliance): the hub. One control set implemented once and mapped outward to the eight frameworks below, because access control, change management, risk assessment, logging, incident response and vendor due diligence are the same controls in every one of them. - [ISO 27001](https://semperwise.com/iso-27001): ISO/IEC 27001:2022 ISMS implementation — scope, gap assessment, risk treatment, Statement of Applicability, internal audit and management review, with support through Stage 1 and Stage 2. 93 Annex A controls across four themes. The certificate is issued by an accredited certification body, never by SemperWise; a firm that offers to both implement and certify is offering a certificate informed buyers will not accept. The 2013 edition was withdrawn and its certificates ceased to be valid after 31 October 2025. - [SOC 2](https://semperwise.com/soc-2): Type I and Type II readiness against the AICPA Trust Services Criteria. SOC 2 produces an attestation report, not a certificate, and only a licensed CPA firm can issue it — "SOC 2 certified" is not a thing that exists. Security is the only mandatory criterion; Availability, Processing Integrity, Confidentiality and Privacy are scoped to actual contractual commitments rather than bundled. Type II observation windows run 3–12 months, most commonly 6 for a first report. - [DPDP Act Compliance](https://semperwise.com/dpdp-act-compliance): India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Phased commencement, data mapping, notice and consent, data-principal rights, breach reporting, children's data, Significant Data Fiduciary duties and the penalty schedule. There is no DPDP certification and no accredited certifier — the Data Protection Board of India adjudicates, so what is sold is readiness and defensibility, never a badge. - [GDPR](https://semperwise.com/gdpr): scope determination under Article 3 first, because the extraterritorial reach catches Indian companies that serve or monitor people in the EU regardless of where they are incorporated. Records of processing, lawful basis, DPIAs, data-subject rights, 72-hour breach notification, and Standard Contractual Clauses for EU–India transfers — India has no adequacy decision, and the transfer mechanism is the control most commonly missing at Indian vendors. No general-purpose GDPR certificate exists in practice. - [HIPAA](https://semperwise.com/hipaa): Business Associate readiness for Indian IT, BPO and health-tech vendors handling US patient data. Status attaches to what you do with ePHI, not to whether a Business Associate Agreement was signed. Security Rule risk analysis, administrative/physical/technical safeguards, BAA review and Breach Notification Rule duties. HHS and OCR do not certify or accredit anyone under HIPAA — "HIPAA certified" is a training record, not a legal status. - [PCI DSS](https://semperwise.com/pci-dss): v4.0.1, the current standard since June 2024; v3.2.1 retired 31 March 2024 and the 51 future-dated v4.0 requirements became mandatory 31 March 2025. Scope reduction first, because every system that can reach the cardholder data environment inherits the full requirement set, then segmentation testing to prove the boundary holds. SemperWise is not a QSA and not an ASV; where a QSA signature or an ASV-branded scan is formally required we work alongside a certified partner and say so up front. - [NIST CSF](https://semperwise.com/nist-csf): Cybersecurity Framework 2.0, released February 2024, assessed across all six functions including the new GOVERN, scored against the four Implementation Tiers with current and target profiles. There is no such thing as NIST CSF certification — it is a voluntary maturity framework with no accreditation body — so the deliverable is a defensible score and a roadmap. Detect and Respond are validated against real telemetry rather than self-attestation. - [ISO 42001](https://semperwise.com/iso-42001): ISO/IEC 42001:2023, the first certifiable AI management system standard, published December 2023. AI inventory and provider/deployer role mapping, AI risk and impact assessment, data governance for training and inference, Annex A controls and Statement of Applicability. The EU AI Act is the law and ISO 42001 is the management system that helps evidence it — related, not equivalent, and certification does not by itself make you compliant with the Act. The standard is young and its certification ecosystem is still maturing. - [DPDP Readiness Assessment](https://semperwise.com/dpdp-readiness-assessment): fixed-scope diagnostic. Data-processing inventory, Data Fiduciary/Processor role determination, RAG-rated clause-by-clause gap register against the Act and the 2025 Rules, and a remediation roadmap dated to 13 May 2027. Two to four weeks, fixed price, not a legal opinion. - [AI Security & Governance](https://semperwise.com/ai-security): LLM and RAG assessment against the OWASP Top 10 for LLM Applications, prompt injection, agent permissions, private AI deployment. - [Managed Security & vCISO](https://semperwise.com/managed-security): named senior practitioner, continuous vulnerability management, compliance operations, incident response retainer. - [Security Training](https://semperwise.com/security-training): awareness, phishing simulation, secure coding labs, incident response drills, executive briefings. ## Platform [SemperWise One™](https://semperwise.com/platform) — cloud-native SaaS on AWS, 30 modules in four groups (Protect, Comply, Govern, Intelligence) on one data model and one dashboard. Deployable to our AWS cloud, a customer private cloud, or on-premises. Modules are marked live or in development on the platform page; we do not claim shipped capability we do not have. ## Blog Source-checked articles on compliance, AI security and cryptography, each citing primary sources (regulator notifications, NIST, OWASP, IBM). Written under research-desk bylines, not individual names — see https://semperwise.com/about for why. - [DPDP Act Compliance 2026: Your Countdown to the May 2027 Deadline](https://semperwise.com/blog/dpdp-act-compliance-2026-checklist): the phased DPDP Rules 2025 timeline, penalty exposure (up to ₹250 crore) and a practical readiness checklist. - [DPDP Rules 2025 Explained: What Changed and the 2027 Deadline](https://semperwise.com/blog/dpdp-act-2025-what-changed): the regulatory explainer — what the DPDP Rules 2025 changed, the three-tranche commencement clock in rule 1, extraterritorial reach, the obligations in the order they arrive as work, the graded penalty schedule, and the gap GDPR and ISO 27001 leave behind. - [OWASP Top 10 for Agentic AI (2026): How to Secure Autonomous Agents](https://semperwise.com/blog/owasp-top-10-agentic-ai-security-2026): the OWASP Gen AI Security Project's agentic-application risk categories and a defence blueprint. - [Post-Quantum Cryptography 2026: Beat "Harvest Now, Decrypt Later"](https://semperwise.com/blog/post-quantum-cryptography-migration-2026): why data with a long confidentiality shelf-life is at risk today, and how to start a NIST-aligned PQC migration. - [Shadow AI in 2026: Why AI-Enabled Breaches Now Cost $6 Million](https://semperwise.com/blog/shadow-ai-ai-enabled-breaches-2026): IBM 2026 breach-cost figures for AI-enabled incidents and a shadow-AI governance playbook. - [SOC 2 vs ISO 27001 in 2026: Which One Wins You Enterprise Deals?](https://semperwise.com/blog/soc-2-vs-iso-27001-2026-startup-guide): how the two frameworks compare, which to pursue first, and how to get certified without derailing a product roadmap. Full index: https://semperwise.com/blog ## Industries Healthcare, banking, financial services, insurance, government, manufacturing, retail, telecommunications, IT services, pharmaceuticals, education, logistics, energy and utilities, cloud providers, SaaS companies, startups and MSMEs. See https://semperwise.com/industries ## Typical questions - **What is VAPT?** The combination of a broad vulnerability assessment that finds weaknesses and focused penetration testing that proves which of them an attacker could exploit. You need both. - **How long does a test take?** A single web application is five to eight working days of testing plus two to three for reporting. A perimeter of under 50 hosts is about a week. Larger programmes run three to six weeks. - **How long does ISO 27001 take?** Four to nine months, driven by starting position and scope rather than company size. - **Is there such a thing as DPDP certification?** No. The DPDP Act created the Data Protection Board of India to adjudicate, not a certification scheme, and there is no accredited DPDP certifier. What is real is demonstrable readiness: a data-processing inventory, working consent and rights processes, a rehearsed breach playbook and evidence that can be produced on request. - **Does the DPDP Act apply to us?** Almost certainly, if you process the digital personal data of people in India — including processing outside India where goods or services are offered to people in India. - **Do you use AI in testing?** Yes, for correlation, analysis and drafting. Never for severity or exploitability judgement. Every delivered finding is human-verified. Client data is never used to train models. - **What does it cost?** Scoped in a 30-minute call, then quoted as a fixed written price. No published price list, because any figure would be wrong for most readers. Full FAQ: https://semperwise.com/faq ## Key pages - Home: https://semperwise.com/ - Services overview: https://semperwise.com/services - Detection coverage: https://semperwise.com/detection-coverage - Platform: https://semperwise.com/platform - Blog: https://semperwise.com/blog - Resources: https://semperwise.com/resources - DPDP readiness checklist: https://semperwise.com/resources/dpdp-checklist - Industries: https://semperwise.com/industries - FAQ: https://semperwise.com/faq - About: https://semperwise.com/about - Contact: https://semperwise.com/contact - Sitemap: https://semperwise.com/sitemap.xml