Regulatory tools for the questions the web answers badly.
How long you have to report an incident? Which CSCRF category you are in? Which of the seven RBI Directions binds you? Whether your employees' credentials are already for sale? Every answer here was built from a primary source — the issuing regulator's own notification, or Bitsight's own measurement — and every figure links back to it. Nothing needs a sign-in, and nothing you type leaves your browser.
Know your obligations
3 tools- Which Indian cyber security regulation applies to youPick your entity class. Get the instruments that bind it, with reference numbers and links to the regulator’s own notification.Open the tool →
- Which Indian AI rules actually bind youFive kinds of document get called “India’s AI rules”. One of them is enforceable against you, and which one depends on your regulator.3 worked casesOpen the tool →
- Which DPDP obligations bind you today, and which do not yetPick an obligation and see whether it binds. Most do not until 13 May 2027, including the seventy-two-hour breach report.4 worked casesOpen the tool →
Incident response
2 tools- Cyber incident reporting deadlines in India: who you tell, and by whenEnter your entity type and the moment you noticed. Get every filing you owe, as a deadline rather than a duration.5 worked casesOpen the tool →
- Rehearse an incident against the clocks that actually runPick your entity and what happened. Get a facilitator script where the statutory deadlines fall due during the exercise, not after it.4 worked casesOpen the tool →
SEBI CSCRF
2 tools- Which SEBI CSCRF category are you in, and what it costs youPick your entity type, enter one number, and see your category — against the thresholds as they stand today, not as CSCRF v1.0 set them.4 worked casesOpen the tool →
- Work out your SEBI CSCRF Cyber Capability IndexAll 23 parameters, weighted as SEBI weights them, scored the way the CSCRF FAQ says to score them — including the three that are not ordinary ratios.Open the tool →
Board governance
2 tools- Would your board’s cyber governance survive an inspection?Eleven questions your company secretary can answer from documents that already exist. Every gap comes back against its clause.4 worked casesOpen the tool →
- What your board actually has to approveGovernance tests ask whether the arrangements would survive an inspection. This asks what is written down, who signs it, and when it comes back.4 worked casesOpen the tool →
Exposure checks
5 tools- What can an attacker see about your domain right now?Enter your domain and your work email on it. Two vectors read live, then what the other eight would add.Open the tool →
- Are your employee and customer credentials already for sale?Describe how your identity estate is built. Get the exposure that follows from it, the blast radius of one stolen login, and the clock it starts.Open the tool →
- Can anyone send email as your domain?Enter a domain. See what its DNS says about who may send mail as it — and what a receiving server does about mail that fails.Open the tool →
- Which of your subdomains are failing their SSL checks?Enter a domain. See which of its subdomains serve a certificate or a TLS configuration that a rating would mark down — and which ones nobody has looked at in years.Open the tool →
- What a Bitsight score means, and what most of the web gets wrongEnter a rating and see what it says: the band, the share of entities above it, and why no published rating ends in 1 to 9.3 worked casesOpen the tool →
Answered end to end, for one entity at a time
Each of these runs a single situation all the way through the tool above it — the instrument that actually binds that entity, the clause the answer comes from, and the deadline or category that falls out of it.
Why these are open source?
Each of these is the browser-sized version of a skill in BitScoreCoWork, our MIT-licensed Claude plugin. The full versions run against your own Bitsight tenancy and work from your measured attack surface rather than from a form. The source is public, which is the point: it is easier to show you what the practice does than to describe it. Read the source, or see the Applied AI practice.