Emerging Tech Start-up of the Year
Recognised for building AI enabled security and compliance services that help growing companies meet the enterprise trust bar.
On 25 August 2026, SecComply was honoured at the ETNOW.in Business Conclave & Awards 2026, West Edition, in Mumbai.

SecComply was named Emerging Tech Start-up of the Year at the West Edition.
Recognised for building AI enabled security and compliance services that help growing companies meet the enterprise trust bar.
The award was received on behalf of the company by Shivani Tikadia, Chief Executive Officer, and presented by Rohit Gopakumar. The West Edition of the conclave brings together founders, operators and investors from across the region, with awards recognising companies building in emerging sectors of the Indian economy.
The enterprise trust bar is a specific thing: the point at which a large customer, a regulator or an investor asks a smaller company to prove that its security and data practices hold up.
That is the work. It rarely makes headlines. It decides whether a deal closes.
This recognition reflects the work that happens every day behind the scenes at SecComply.
Building cybersecurity and compliance solutions for growing businesses means understanding real challenges, listening closely to customers, solving complex problems, and continually finding better ways to help organisations stay secure and compliant without slowing their growth. That has been our focus from the beginning.
We are grateful to our customers, partners, mentors, and the entire SecComply team for being part of this journey.
A sincere thank you to The Economic Times and ET NOW for the recognition, and to Rohit Gopakumar for presenting the award and making the evening memorable.
We are proud of this milestone, and there is much more to build. We remain committed to making cybersecurity and compliance simpler, stronger, and more accessible for businesses.
We built SecComply for the companies that get handed enterprise requirements without enterprise budgets. This award tells us that problem is finally being recognised as a serious one.
Two things sit inside this recognition. One is about the category. The other is about us.
An emerging tech category is not an award for having new technology. It is an award for pointing new technology at a problem that people are actually paying to solve, and showing that it works at scale beyond a single customer.
For SecComply, that problem is a specific one. Security and compliance programmes were designed for large enterprises with large teams. Growing companies inherit the same requirements without the same resources. They are asked for ISO 27001, SOC 2, DPDP readiness and AI governance by customers who will not wait six months for an answer.
We built our services and our platform around closing that gap: assessment, control design, evidence and audit support, delivered with automation where automation genuinely helps and with people where it does not.
Honestly, less than you might expect, and more than we let on.
It does not change how a project runs on a Tuesday morning. The standard we are measured against is still the same one: did the client clear the audit, did the questionnaire get answered, did the deal move.
What it does change is the opening conversation. Growing companies are careful about who they trust with security work, and rightly so. Independent recognition shortens the part where we have to explain that we are a serious firm, and gets us to the part where we can be useful.
SecComply started in 2021 with a question we kept hearing from founders: our biggest customer just sent us a security questionnaire, what do we do?
Five years later the question has not changed much. The stakes have.
A small consulting practice, working directly with founders and heads of engineering. No brand, no platform. One certification at a time, learning the difference between what a standard says and what an auditor accepts.
After enough engagements, patterns emerge. The same gaps, the same evidence problems, the same three weeks lost to chasing screenshots. We started building the methodology that our delivery still runs on.
India's data protection regime arrived, GDPR expectations spread through customer contracts, and compliance stopped being something companies did once before a big deal. Our scope widened from certification support to running the security and compliance function itself, through CISO advisory and vCISO services.
Consulting scales with people. Evidence collection, control mapping and audit readiness do not have to. YourComply came out of watching our own consultants do the same manual work across every client.
The work stopped being tied to one regulator and one buyer. Frameworks that used to arrive one at a time now arrive together, and a single client will ask about an Indian rule, an American customer questionnaire and a European contract clause in the same conversation.
A five year old company exists because someone took a chance on a two year old one.
We want to be specific about what our early customers actually gave us, because it was not just revenue. They gave us a real problem with a real deadline attached, which is the only way to learn this work properly. They told us when a deliverable was too long, too theoretical, or written for an auditor rather than for their engineering team. They let us sit in on the uncomfortable calls where a deal was at risk. And when it went well, they told other founders, which is how most of our work still arrives.
Several of them have now been through three or four cycles with us: a first certification, then a surveillance audit, then a new framework as they entered a new market, then an AI governance question nobody was asking when we started.
To every customer who chose a smaller firm when a larger name was available, thank you. This award belongs to you as much as to us.
Almost nobody calls us because they woke up worried about control A.8.24. They call because a customer, an investor or a regulator is waiting, and a certificate is the thing standing between the company and the next stage of its growth.
That changes how a programme should be designed. The right question is not what the standard requires, it is what the deadline is, what the deal is, and what the shortest defensible path looks like. Programmes that ignore the commercial clock get abandoned halfway through, no matter how well written they are.
A policy library is not a security programme. Controls only work when a named person owns them on an ordinary Monday, with a calendar reminder and somewhere to put the evidence.
The engagements that go badly are the ones where documentation was produced and ownership was not assigned. The engagements that go well are boring: fewer controls, clearly owned, evidenced as a habit rather than reconstructed in a panic three weeks before the audit.
The market's answer to compliance has been software. Software genuinely helps with the repetitive parts: evidence collection, control mapping, drift detection, reminders.
But a platform cannot tell a founder which of eleven frameworks actually matters for the deal in front of them, or how to scope an environment so the audit stays affordable, or what to say when an auditor pushes back. That judgement is the expensive part, and removing it from the equation is why so many teams end up with a fully configured tool and a failed audit.
Automation for the volume. People for the judgement. Five years in, we are more convinced of this than we were at the start.
The presentation, the trophy, and the conclave where it was awarded.











A security company winning a general business award, in a room mostly full of people who do not work in security, is worth noticing on its own.
For a long time cybersecurity sat outside the growth conversation. It was a cost, a compliance chore, a slide near the end of the board pack. That has shifted. Enterprise buyers now run security due diligence before they sign. India's data protection rules are moving through phased implementation and boards are being asked direct questions about accountability. Every company shipping an AI feature is discovering that its customers want to know how the model is governed.
Security has become a condition of doing business, which means the companies solving it are now part of the growth story rather than a deduction from it.
For founders building in this space, three things follow from that. The buyer is increasingly the CEO or the head of revenue, not only the security team, so the pitch has to be commercial. The underserved market is not the Fortune 500, it is the several thousand growing companies being held to enterprise standards without enterprise budgets. And credibility compounds slowly: in security, being unglamorous and correct for five years is a strategy.
Recognition like this is a signal that the category is being taken seriously. That is good for everyone building in it, not only for us.
The award marks a point on the road, not the destination. Here is what the next stretch looks like.
From sign-off to audit-ready, automated across 50+ frameworks. The direction is fewer manual evidence requests, continuous control monitoring instead of annual scrambles, and a single set of evidence that serves multiple frameworks at once.
Our clients are shipping AI faster than the governance around it is maturing. We are building out ISO 42001 readiness, AI risk assessment and security review of AI systems, so that using AI responsibly is something a company can evidence rather than assert.
Consent architecture, data principal rights handling, breach response and processor obligations, delivered as advisory and design work that a client's own teams can operate.
Growing the vCISO bench and the partner programme so that more companies can access senior security leadership at a price that makes sense at their stage.
Deeper coverage across the four regions we already serve: India, the Middle East, Europe and the United States.
The mission has not moved since year one. Make security and compliance simpler, stronger and more accessible for the companies that cannot afford to get it wrong.
An award does not sign an audit report. Our customers do that, and they are the reason we were on that stage.