GoDravixA product byDigiWagon
Migration
Pricing
Book a demoSee the platform

The certifications we hold, and the gaps we do not hide

ISO 9001 and ISO 27001, held by DigiWagon Technologies. What they cover, the application controls protecting the ledger, and the gaps we name rather than hide.

What we hold, and what we do notaudited
Control surfaceSecurity controls held, and the one gap named.Control surfaceApproval separationenforced per loanQuery-level data scopingnot UI hidingAppend-only audit trailno edit, no deleteMulti-factor authenticationon every loginISO 9001 and ISO 27001scope on requestSOC 2 attestationnot heldAsk for the scope statement, not the number
Audited every year
Certifications, and the controls underneath them.Ask for the scope statement, not just the number

DigiWagon Technologies, which builds and supports GoDravix, holds ISO 9001 for quality management and ISO 27001 for information security. GoDravix is developed and operated under those certified management systems, and we share both certificates with their scope statements on request so your reviewer can check the scope rather than take our word for it.

SOC 2 is not held and DPDP alignment has not been formally assessed. Alongside the certifications sit the application-level controls built for a government deployment: enforced approval separation, query-level data scoping, an append-only audit trail and an independent auditor role.

Ask for the scope statement, not just the certificate number. An ISO 27001 certificate is only as meaningful as the scope it covers. We send ours unprompted, and we would treat any vendor that does not the same way you should.

Controls in place

What protects the ledger today

Enforced approval separation

Creation, approval and disbursement are three distinct permissions. The workflow refuses an approval from the user who created the loan. Disbursement is unavailable until an approval event exists.

Query-level data scoping

A regional permission sees one zone; a borrower sees only itself. Scoping constrains the data fetched rather than hiding interface elements, so it cannot be bypassed by constructing a URL.

Append-only audit trail

Once the book is live, no edit and no delete for any role including Admin. Corrections are new events referencing the original. Filterable by actor, action, borrower and date range. The migration reset tool is withdrawn at cut-over.

Independent auditor role

Read-only access across the entire portfolio and the complete event log, held outside the operations chain so that review does not depend on the goodwill of the team being reviewed.

Gaps

What we do not have

Read this section as though you were the person who has to sign the risk assessment.

ControlStatusWhat this means for you
ISO 9001HeldCertified quality management system covering how DigiWagon builds and supports software.
ISO 27001HeldCertified information security management system. Certificate and scope statement shared on request.
SOC 2 Type IINot heldNo third-party attestation of controls over a period. Common blocker for enterprise and US buyers.
DPDP alignmentNot assessedISO 27001 covers a great deal of the groundwork, but DPDP obligations have not been formally mapped against the product.
Multi-factor authenticationAvailableMFA on GoDravix logins, and on DigiWagon's own systems under the ISO 27001 management system.
Single sign-onAvailableBuilt. The identity provider is configured against yours as part of the deployment, so bring your IdP details to the technical call.
Penetration test reportNot availableNo current third-party penetration test to share with your security team.
On-premise and government cloudPer deploymentDeployment shape is chosen per engagement: our managed cloud, your private cloud, your own infrastructure, or a government cloud.
Multi-tenancy isolationPer deploymentSingle-tenant deployment. There is no tenant isolation layer to review, because there are no shared tenants.
Data residency guaranteesPer deploymentHosting region is agreed per engagement rather than offered as a certified guarantee.
How to evaluate us

Test the controls, not just the certificate

ISO 27001 tells you a management system exists and is audited. It does not tell you how this particular application behaves when somebody tries to move money without approval.

So examine both. Ask for our certificates and scope statements, then run these six checks in a demo. Ask us to demonstrate the approval gate by trying to disburse an unapproved loan. Ask us to show what a zone-scoped user sees when they request data outside their zone. Ask the Auditor role to produce the full event history for a loan, then ask an Admin to delete one of those entries.

Those six tests tell you more about how a lending system behaves under pressure than a certificate does.

  • Try to disburse without approval

    The action should not be available. Verify it.

  • Request data outside your scope

    A zone-scoped user should get nothing, not a filtered view.

  • Ask an Admin to delete an audit entry

    There should be no mechanism. Check that there is not.

  • Correct a wrong repayment

    Both the error and the correction should remain visible.

  • Reissue a certificate

    Both issuances should appear in the trail.

  • Run interest twice

    Both runs should be logged with the user who triggered them.

Questions

About security

DigiWagon Technologies, which builds and supports GoDravix, holds ISO 27001 for information security and ISO 9001 for quality management. GoDravix is developed and operated under those certified systems. We send both certificates together with their scope statements, because a certificate without its scope tells a reviewer very little.

SOC 2 is a separate matter and is not held, neither Type I nor Type II. If your procurement treats SOC 2 as an eligibility condition rather than a scored criterion, that gate is still closed today.

Not formally assessed, so we will not claim compliance. ISO 27001 covers much of the underlying information-security groundwork that a DPDP programme depends on, but the two are not the same thing and mapping the product against DPDP obligations is work still to be done. We would rather scope it honestly than assert an alignment nobody has verified.

Both. Multi-factor authentication is available on GoDravix logins, and DigiWagon runs MFA across its own systems under the ISO 27001 management system. Single sign-on is built, and the identity provider is configured against yours as part of the deployment rather than being a development project. Bring your IdP details to the technical call and we will confirm the specifics against your setup.

Wherever your policy requires. The deployment shape is chosen per engagement: our managed cloud, your private cloud, your own infrastructure, or a government cloud. Region is agreed the same way. If data residency is a statutory requirement, raise it in the first conversation so it is scoped into the deployment rather than a configuration.

Not from a shelf. Where a customer requires one, a third-party test is commissioned as part of the engagement and the report goes to you.

Next step

Bring your security questionnaire

Send it before the first call. We will complete it honestly, including the rows where the answer is no.

45 minutes | On the live deployment | A straight answer on fit