Early-stage SaaS (seed to Series A)
DPDP consent + buyer-questionnaire readiness + early SOC 2 Type I prep + ESOP + Delaware flip (if planned) + USD invoicing. From ₹25k–75k/mo. Focus on sales-unblocking.
SOC 2 Type II, ISO 27001, DPDP + GDPR, USD invoicing, FIRC collection, SEIS and SOFTEX filings, buyer-questionnaire turnaround and trademark + patent for Indian SaaS and IT services firms selling to global buyers.
For Indian SaaS and IT services firms selling to global buyers, compliance is a sales enabler, not a cost centre. Enterprise buyers in the US, EU and APAC refuse to sign without SOC 2 Type II or ISO 27001. Procurement teams send 200-item buyer questionnaires (VSAQ, CAIQ, SIG, SIG-Lite) that take weeks to answer. European customers demand GDPR Data Processing Agreements and Standard Contractual Clauses. UK customers want a UK representative. A single blocked deal because of a compliance gap can cost multiples of a year of compliance spend.
At the same time, Indian SaaS and IT services firms are Indian legal entities. DPDP Act applies to Indian data processing. FEMA governs USD invoicing and FIRC collection. SEIS and SOFTEX need monthly STPI filings. LRS and ODI tracking matters for founders with international earnings. Ind-AS 115 revenue recognition is non-trivial for SaaS subscription models.
Running this split — compliance in one hemisphere, finance in another — is where most firms break. Compliance team does not know what FIRC is. Finance team does not know what a VSAQ is. Legal team is somewhere else again. The founder ends up personally stitching the whole thing together, which is the most expensive version of all three functions.
Cosmoura runs the full SaaS and IT services back-office as one retainer. Named DPO plus named CA plus named CS plus named IP attorney on your account. SOC 2 + ISO 27001 + DPDP + GDPR with common controls mapped once. USD invoicing + FIRC + SEIS + SOFTEX in one book. Trademark India + Madrid Protocol in one portfolio. Decipher Consultancy Services (our sister concern) builds the buyer-questionnaire answer library and the evidence collection automation. One operating group, one invoice, one point of contact when a deal is on the line.
Trigger moment: A $5M enterprise deal just stalled on a SOC 2 Type II requirement. A European customer asked for your GDPR Data Processing Agreement and you don't have one. Your SEIS claim for last financial year is still unfiled. The procurement team at your biggest buyer just sent a 180-item security questionnaire. If one or more of these is open — call us this week.
Who this is for
The retainer is tuned to your stage. If you do not fit cleanly, we scope a custom pack.
DPDP consent + buyer-questionnaire readiness + early SOC 2 Type I prep + ESOP + Delaware flip (if planned) + USD invoicing. From ₹25k–75k/mo. Focus on sales-unblocking.
SOC 2 Type II + ISO 27001 + DPDP + GDPR parallel tracks. Virtual DPO. USD invoicing + FIRC + SEIS + SOFTEX. ESOP for 100+ grantees. Multi-geography customer DPA negotiation. Buyer questionnaire answer library.
ISO 27001 renewed, SOC 2 Type II on continuous observation, Ind-AS 115 revenue recognition clean, cap table hygiene, ESOP tax clarity for grantees, SEBI ICDR preparation 18–24 months out.
What this industry faces
Enterprise buyers (US, EU, APAC) require SOC 2 Type II or ISO 27001 before signing. We take you from zero to audit-ready in 90–120 days with common controls mapped across both frameworks.
DPDP for India processing, GDPR for EU data subjects, UK GDPR for UK users. We draft DPAs, Standard Contractual Clauses, Transfer Impact Assessments, and set up EU representative plus UK representative where required.
Export invoicing templates, FIRC and BRC collection, SEIS registration, SOFTEX monthly filings via STPI, LRS tracking, ODI compliance for founders with international earnings. Avoid blocked remittances and FEMA notices.
VSAQ, CAIQ, SIG, SIG-Lite, custom buyer questionnaires. We maintain your answer library, update after every audit cycle, and respond to incoming questionnaires within 24 hours with named engineering + security signoffs.
Pre-built packs
Each pack pulls from the right pillars. Pick one or bundle all four.
Hero · Audit-ready
ISMS build-out, 64-control TSC-mapped policy library, Type I in 60–75 days + Type II in +90 days, ISO 27001 Statement of Applicability, auditor coordination (Big-4 and boutique), buyer questionnaire answer library populated.
Data Protection
DPDP consent architecture for Indian processing, GDPR DPA plus Standard Contractual Clauses for EU buyers, EU representative and UK representative appointment, cross-border Transfer Impact Assessments, customer DPA negotiation playbook.
Finance
ARR / MRR tracking with cohort breakdown, USD invoicing templates, FIRC and BRC collection and reconciliation, SEIS and SOFTEX monthly STPI filings, Ind-AS 115 revenue recognition for subscription models, deferred revenue schedule.
IP
Trademark India plus Madrid Protocol (110+ countries), copyright for product UI and code, patent drafting for novel architecture, non-compete and IP assignment agreements for engineering team.
How we onboard
Most new saas & it services clients come to us mid-mess. Clean-up is a one-time cost; everything else is monthly cadence.
Week 1–2
We walk your SOC 2 / ISO / DPDP / GDPR posture, review your last 3 months of buyer questionnaires (and what blocked deals), audit your USD invoicing and FIRC collection history, and check your SEIS / SOFTEX status. Written report with ranked sales-unblocking priorities.
Week 2–10
64 TSC-mapped policies drafted for SOC 2 + 45 ISO 27001 policies + 15 DPDP policies + GDPR DPA templates + SCCs — common controls shared across frameworks. Risk register built. Evidence collection started on dcomply platform. Buyer questionnaire answer library populated.
Week 10–20
SOC 2 Type I audit completed, Type II observation window opened. ISO 27001 Stage 1 and Stage 2 audits. GDPR DPA and SCCs released to EU buyers. EU + UK representatives appointed. Buyer questionnaire turnaround SLA dropped to 24 hours.
Ongoing
Continuous Type II observation evidence collection. Annual ISO 27001 surveillance audit. Annual SOC 2 Type II report. Continuous Virtual DPO coverage. Monthly SEIS + SOFTEX filing + FIRC collection + USD books close. Buyer questionnaire SLA on 24 hours.
How we compare
Honest comparison on cost, coverage and the parts most firms quietly skip.
| Generic CA firm | Self-run team | Cosmoura retainer | |
|---|---|---|---|
| Named DPO + CA + CS + IP attorney | Partner on paper only | ₹60L+/yr fully loaded | 4 named leads, direct contact |
| SOC 2 + ISO + DPDP + GDPR parallel | Sequential projects | 18+ months | Parallel — 6–9 months |
| Buyer questionnaire turnaround | Case-by-case | 2–3 days typical | 24-hour answer library |
| GDPR DPA + EU + UK rep | Separate counsel | Rare in-house | In-house + ongoing |
| SEIS + SOFTEX + USD + FEMA | Separate CA for FEMA | In-house CA | In-house, included |
| Trademark India + Madrid | Separate IP firm | External counsel | In-house, included |
| Total cost (full stack) | ₹25–40L/yr across vendors | ₹60L+/yr fully loaded | ₹8–20L/yr fixed retainer |
What's included
FAQ
Type I in 60–75 days, Type II in another 90 days (minimum observation window). Total 5–6 months for first-time clients. Faster if you already have ISO 27001 — 60% of controls overlap.
Both. Pre-seed startups usually start with DPDP + buyer questionnaire readiness (₹25–50k/mo). Series A+ adds SOC 2 + ISO 27001 (₹2–3L/mo). Scale-ups add Virtual DPO + GDPR + customer DPA negotiation (₹5L+/mo).
Yes. GDPR Data Processing Agreement, Standard Contractual Clauses, EU representative appointment, data transfer impact assessments, breach notification setup. We also handle UK GDPR + UK representative post-Brexit. For most Indian SaaS firms selling to EU/UK, this unblocks a tier of enterprise customers.
Export invoicing templates, FIRC / BRC collection, STPI registration, SOFTEX monthly filings, SEIS claim preparation, ODI / LRS tracking for founders. All included in the SaaS finance pack. For most IT services firms, SEIS claim alone recovers more than our annual fee.
We maintain a library of pre-approved DPA clauses, standard SCC riders, and your preferred liability caps and audit terms. When a customer sends their own DPA, we redline against your position within 48 hours, flag open issues, and route to your legal counsel only for exceptions. Dramatically speeds enterprise contracting.
Yes. End-to-end — Delaware incorporation, share swap, FEMA FC-TRS filing, ODI compliance for Indian shareholders, tax implications per DTAA, ESOP migration to US entity. Executed with your legal counsel and tax advisor; we are the project manager plus the Indian compliance signoff.
Ind-AS 115 governs how revenue is recognised across time for subscription contracts. For annual contracts invoiced upfront, revenue is recognised monthly, with deferred revenue booked on the balance sheet. Getting this right matters for your audit, your Series A diligence, and your eventual IPO filing. We book it correctly from month one.
Yes. IT services (staffing, project-based consulting, offshore development) has lighter compliance surface than SaaS but heavier FEMA + USD invoicing + MSA negotiation surface. We offer a tuned IT-services pack that drops the SaaS-specific revenue-recognition pieces and adds MSA + SOW library.
Ready to run cleaner?
Free 30-minute discovery call. We map your current compliance + finance posture, then come back with a sequenced plan.