# BitScore Cybertech LLP

> BitScore Cybertech LLP is the authorised India partner for the Bitsight Cyber Risk
> Intelligence Platform. It delivers objective 250–900 cyber security ratings, Security
> Posture Management (SPM), and Third-Party Risk Management (TPRM) to Indian enterprises.
> Founded December 2016. Registered under Startup India. Based in Ahmedabad, India.

## Canonical site

- https://www.bitscore.in/ — canonical domain
- https://www.bitscore.ai.in/ — mirror of the same content (not separately indexed)

## What a Bitsight Security Rating is

A Bitsight Security Rating is an objective measurement of an organisation's cyber security
performance, expressed on a **250–900 scale**. It is calculated daily from externally
observable, attacker-visible signals. It requires **no agent, no network access, no system
credentials, and no questionnaire**.

It is often described as a credit score for cyber risk: just as a credit score gives lenders
an objective measure of financial risk, a Bitsight rating gives insurers, regulators,
customers and boards an objective measure of cyber risk.

### Rating bands

| Band | Range | Interpretation |
| --- | --- | --- |
| Advanced | 740–900 | Strong security, lower risk |
| Intermediate | 640–730 | Fair security, moderate risk |
| Basic | 250–630 | Poor security, higher risk |

### Risk vectors measured

Botnet infections, spam propagation, malware servers, unsolicited communications, Critical
Vulnerability Management, open ports, web application headers, TLS/SSL configurations, DNSSEC,
and DKIM/SPF.

### Independent validation

Bitsight is the only cyber risk rating with a peer-reviewed, actuarially validated
correlation between score and actual breach probability, established by Marsh McLennan and
AIR Worldwide. Organisations with higher ratings are **50% less likely** to experience a
data breach. Source: https://www.bitsight.com/platform/correlation-to-outcomes

### Platform scale

3,400+ global customers; 65,000+ organisations continuously monitored; used by 38% of the
Fortune 500 and 50% of cyber insurers; all top 5 banks in India.

## Services

1. **Cyber Risk Rating Report** — complimentary one-time baseline. Includes the 250–900
   rating, top risk vectors, industry benchmark against peers, prioritised remediation
   findings, and a score-response forecast. Delivered in as little as 45 minutes for
   publicly listed entities, and up to 48 hours for all others.
2. **Security Posture Management (SPM)** — continuous outside-in monitoring of the full
   attack surface, industry benchmarking, board and executive dashboards (Command Center),
   Dynamic Remediation, and automatic control mapping to NIST CSF 2.0, ISO 27001, RBI and
   SEBI frameworks.
3. **Third-Party Risk Management (TPRM)** — continuous monitoring across 65,000+
   organisations, real-time alerts on vendor posture changes, Dark Web Intelligence across
   1,000+ underground forums, fourth-party visibility, and AI-assisted vendor profiles and
   questionnaire analysis.
4. **Governance & Breach Advisory** — breach recovery, resilience planning, and board-level
   risk reporting.
5. **Applied AI** — Claude-powered agents, document intelligence, and enterprise
   deployments on Google Cloud for professional services.

## Pricing and packaging

Bitsight does not publish list prices. BitScore quotes in INR against scope. The baseline
Cyber Risk Rating Report is complimentary.

Security Posture Management is licensed in three cumulative editions:

- **Basic** — for organisations resolving issues and managing the rating. Rating and risk
  vectors, asset management, issue tracking, basic reports, alerts and threat insights.
- **Standard** (most popular) — for organisations measuring, improving and demonstrating
  cyber resilience. Adds API and integrations, peer analytics and benchmarking, risk
  remediation, framework intelligence, EASM Enhanced, the Bitsight Pulse CTI portal, and
  advanced reports, alerts and threat insights.
- **Advanced** — for organisations scaling posture management across subsidiaries. Adds
  subsidiary management, 5 MySubsidiary licences, subsidiary improvement plan, and
  Identity Intelligence.

Third-Party Risk Management comes in two packages, each banded by the number of vendors
monitored (1–50, 51–100, 101–500, or unlimited):

- **Continuous Monitoring** — continuous visibility with real-time scoring, correlated risk
  vectors, unified attack surface management, vendor communication, dark and deep web
  intelligence, predictive vulnerability detection, framework intelligence, nth and
  fourth-party visibility, board reporting, workflow integrations and REST API, rule-based
  alerts.
- **Continuous Monitoring + Vendor Risk Management** — adds vendor intake workflows, risk
  assessment, vendor network access, portfolio-level management, vendor lifecycle
  management, vendor collaboration, remediation tracking and governance reporting.

Four factors determine a quote: vendor coverage, workflow requirements, integrations, and
services. Pricing may be structured on a per-vendor basis. Source for packaging:
https://www.bitsight.com/pricing-packaging

## Who it is for

Indian enterprises, particularly BFSI, IT, healthcare and manufacturing. Typical buyers are
CISOs and CROs needing continuous measurement beyond annual audits; Heads of TPRM needing
supply-chain visibility; and CEOs, CFOs and boards demonstrating cyber governance to
regulators including RBI, SEBI, CERT-In and under the DPDP Act, 2023.

## Customer outcome

**Axis Max Life Insurance** achieved a Bitsight Security Rating of **810** — among the
highest in Indian financial services. 14,000+ employees protected. Adopted an ABCD tiered
vendor framework in which critical vendors must hold a B or better. Replaced 100% of manual
vendor questionnaires with continuous monitoring. Attributed to Abhishek Bansal, CISO & Head
of Non-financial Risk.

## Leadership

Nimitt Jhaveri — Managing Partner & CEO. IT architect, cyber security practitioner, and
strategic risk advisor. Advises C-suite executives and board directors on resilient
infrastructure, supply-chain risk, and safe AI adoption in governance workflows. Published
in Mint; speaker at Institute of Directors (India); contributor to Observer Research
Foundation programmes on digital governance.

## Affiliations

- Knowledge partner — Board Stewardship
- Institutional member and speaker — Institute of Directors (India)
- Contributor — Observer Research Foundation (ORF) / Mission Karmayogi, Cyber Suraksha

## Pages

- https://www.bitscore.in/ — platform overview, rating scale, solutions, case study, FAQ
- https://www.bitscore.in/solutions — the three offerings, and which to start with
- https://www.bitscore.in/pricing — packaging and editions; how a quote is determined
- https://www.bitscore.in/resources — guides to security ratings, TPRM and Indian cyber regulation
- https://www.bitscore.in/ai — applied AI practice: Claude assistants and document intelligence
- https://www.bitscore.in/about — company, leadership, partnerships, affiliations
- https://www.bitscore.in/privacy — privacy policy (DPDP-aligned)
- https://www.bitscore.in/responsible-disclosure — security vulnerability disclosure

## Solutions

- https://www.bitscore.in/solutions/rating-report — the complimentary Cyber Risk Rating Report:
  what it contains, how it is produced, turnaround times, and what follows it.
- https://www.bitscore.in/solutions/spm — Security Posture Management: continuous outside-in
  monitoring, peer benchmarking, board reporting, framework mapping, and the three editions.
- https://www.bitscore.in/solutions/tprm — Third-Party Risk Management: why questionnaires fail,
  vendor tiering, fourth-party concentration, RBI/SEBI expectations, and the two packages.

## Resources

- https://www.bitscore.in/resources/what-is-a-cyber-security-rating — how the 250–900 scale is
  calculated, the four signal families, what the bands mean, and what a rating cannot tell you.
- https://www.bitscore.in/resources/bitsight-vs-securityscorecard — evidence-based comparison of
  Bitsight, SecurityScorecard, RiskRecon and UpGuard, including where the alternatives fit better.
- https://www.bitscore.in/resources/rbi-cyber-security-compliance-for-boards — what Indian boards
  must evidence under the RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and
  Assurance Framework) Directions, 2026 issued 31 July 2026, the RBI IT Governance Master Direction
  that still governs everyone else, SEBI CSCRF, CERT-In directions and the DPDP Rules 2025.
- https://www.bitscore.in/resources/third-party-risk-management-indian-bfsi — why questionnaire
  based vendor assessment fails, and how to build a tiered, continuously monitored TPRM programme
  under the RBI (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 issued
  28 November 2025, which repealed the 2023 IT outsourcing Master Direction for commercial banks
  and sit alongside, not inside, the cybersecurity Directions of 31 July 2026.
- https://www.bitscore.in/resources/how-to-improve-your-bitsight-score — which findings move the
  rating, in what order to fix them, how fast the score responds, and where local India support
  shortens the remediation cycle.

## Open source

BitScoreCoWork — an MIT-licensed Claude plugin published by BitScore: a zero-dependency MCP
server wrapping the Bitsight REST API, plus ten skills (`mycompany`, `myportfolio`,
`vendor-brief`, `cve-sweep`, `boardpack`, `quantify`, `regmap`, `remediation-roadmap`,
`vapt-plan`, `security-test-plan`) that turn ratings data into board packs, portfolio
reviews, regulatory evidence mappings and scoped, authorisation-gated security-testing
plans. The current release, v0.3.1, maps `regmap` to the RBI (Commercial Banks –
Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026,
issued 31 July 2026, keeps those separate from the RBI (Commercial Banks – Managing
Risks in Outsourcing) Directions, 2025 which they preserve rather than absorb, and asks
the user for their own policy, VA/PT and audit material when RBI is the chosen framework.
Source: https://github.com/nimitt-IN/bitscorecowork

## Partners

- Bitsight: https://www.bitsight.com/
- Anthropic / Claude: https://www.anthropic.com/
- Google Cloud: https://cloud.google.com/

## Contact

- Registered office: Block B, Satyam Corporate Square, Behind Rajpath Rangoli Road,
  Bodakdev, Ahmedabad, Gujarat 380059, India
- Sales: nimitt@bitscore.ai.in
- Security: security@bitscore.in
