Compliance
The frameworks WebHost24 aligns with or is in-scope for. Each entry links to the relevant law, the audit scope, and the per-framework status. Custom compliance requests: compliance@webhost24.in.
DPDPA 2023
CompliantThe Digital Personal Data Protection Act 2023. Customer data stays in India; data-subject requests honoured within 30 days.
GDPR
CompliantEU General Data Protection Regulation for international customers. Standard Contractual Clauses addendum available.
SOC 2 Type II
Annual auditAnnual third-party audit covers availability, confidentiality, and processing integrity. Report on request under NDA.
ISO 27001
Roadmap 2027Aligned controls; full certification on the 2027 roadmap. Customers receive an annual letter of conformance in the interim.
PCI-DSS
Out of scopeWebHost24 does not store, process, or transmit cardholder data directly. Payments are handled by Razorpay; see [Integrations](/integrations) for the architecture.
HIPAA / Healthcare
Out of scopeWebHost24 is a general-purpose hosting provider. Customers handling PHI must sign a BAA + scope a dedicated plan; we don't market HIPAA as in-scope.
MeitY / India CERT-In
CompliantIndian cybersecurity norms. We cooperate with CERT-In incident reporting as required for hosting providers operating in India.
For framework-specific certifications, request the audit pack from compliance@webhost24.in.