Core GRC Company

Defend what matters. Detect what others miss. Comply with confidence.

Celetrix helps organisations build resilient governance, master enterprise risk, and stay audit-ready across every major framework — so compliance stops being a scramble and becomes a strength.

12+
Frameworks covered
360°
Risk visibility
100%
Audit-ready posture
01

Defend

Governance, policies and controls that harden your organisation and give leadership clear oversight.

02

Detect

Surface risk and control gaps continuously — through assessment, audit and monitoring, not once-a-year spreadsheets.

03

Comply

Map once, satisfy many. Evidence that stands up to any auditor, across any framework.

Frameworks we operate across
ISO 27001SOC 2PCI DSSDPDPAGDPRISO 42001NIST CSF
What we do

End-to-end Governance, Risk & Compliance

One partner across the full GRC lifecycle — from framing your governance model to proving continuous compliance to your board, customers and regulators.

Compliance & Certification

Get certified and stay certified. We run readiness, implementation support and audit liaison across the frameworks your customers demand.

  • ISO 27001
  • SOC 2
  • PCI DSS
  • ISO 42001

PCI DSS Compliance

Protect cardholder data and meet PCI DSS end to end — scoping, gap assessment, remediation support and QSA assessment liaison for merchants and service providers.

  • Scoping & SAQ
  • Gap assessment
  • Remediation
  • QSA liaison

SOC 2 Type 2

Prove your controls operate over time. We take you from readiness through the observation window to a clean SOC 2 Type 2 report your customers can trust.

  • Readiness
  • Control design
  • Observation period
  • Audit support

Enterprise Risk Management

Build a living risk register with clear ownership, scoring and treatment plans — so risk decisions are made on evidence, not instinct.

  • Risk assessment
  • Register & scoring
  • Treatment plans
  • Reporting

Audit & Assurance

Internal audits, gap assessments and control testing that surface issues before an external auditor ever does.

  • Internal audit
  • Gap analysis
  • Control testing

IT General Controls (ITGC)

Review and strengthen the controls behind your systems — access management, change management, backups and operations — the foundation every financial and SOC audit depends on.

  • Access controls
  • Change management
  • SDLC
  • Backup & ops

Governance & Policy

Design the policies, standards and accountability framework that turn security intentions into repeatable, auditable practice.

  • Policy suite
  • Control frameworks
  • Board reporting

Data Privacy & DPDPA

Operationalise India's DPDPA and global privacy laws — data mapping, consent, DPIAs and breach-response ready processes.

  • DPDPA
  • GDPR
  • Data mapping
  • DPIA

Continuous Monitoring

Keep controls alive between audits with ongoing monitoring, evidence collection and a real-time view of your compliance posture.

  • Control monitoring
  • Evidence automation
  • Dashboards

Incident Response

Be ready before it happens. We build incident response plans, run tabletop exercises and support you through containment, recovery and post-incident review.

  • IR planning
  • Tabletop drills
  • Breach response
  • Root-cause review

Security Training & Awareness

Turn your people into your strongest control. Role-based training, phishing simulations and awareness programmes that build a lasting security culture.

  • Awareness training
  • Phishing simulations
  • Role-based modules

Third-Party & Vendor Risk

Know the risk your suppliers carry. We assess, tier and monitor your vendors so a weak link in your supply chain never becomes your breach.

  • Vendor assessment
  • Risk tiering
  • Ongoing monitoring
How we work

A clear path from exposed to assured

A proven four-stage method that meets you wherever you are and takes you to a defensible, audit-ready state.

01

Assess

We map your current controls, obligations and gaps against the frameworks that matter to your business.

02

Design

We build the governance model, policies and risk register tailored to how your organisation actually runs.

03

Implement

Hands-on support to embed controls, train teams and collect the evidence auditors will ask for.

04

Sustain

Continuous monitoring and audit support so your posture strengthens over time instead of decaying.

Who we are

GRC is all we do — and we do it with rigour

Celetrix is a specialist governance, risk and compliance firm. We exist because too many organisations treat GRC as a box-ticking exercise until an audit, a breach or a customer questionnaire forces a scramble.

We bring the structure, tooling and hands-on expertise to make compliance continuous and risk visible — translating dense frameworks into practical controls your teams can actually run.

Practitioner-led

Advice from people who have run real audits and remediations.

Framework-fluent

Map once, satisfy many — no duplicated effort.

Evidence-first

Everything we build is designed to stand up to scrutiny.

Business-aligned

Controls that fit your operations, not the other way around.

Why organisations choose Celetrix

1Single partner across the entire GRC lifecycle
7+Major frameworks delivered under one methodology
24/7Posture visibility through continuous monitoring
0Surprises when the external auditor arrives
Get in touch

Let's build your compliance advantage

Tell us where you are on your GRC journey and we'll map the fastest path to an assured, audit-ready state.

Location88, Borewell Road, Whitefield, Bengaluru, India

We'll respond within one business day. Your details stay confidential.