The certifications we hold, and the gaps we do not hide
ISO 9001 and ISO 27001, held by DigiWagon Technologies. What they cover, the application controls protecting the ledger, and the gaps we name rather than hide.
DigiWagon Technologies, which builds and supports GoDravix, holds ISO 9001 for quality management and ISO 27001 for information security. GoDravix is developed and operated under those certified management systems, and we share both certificates with their scope statements on request so your reviewer can check the scope rather than take our word for it.
SOC 2 is not held and DPDP alignment has not been formally assessed. Alongside the certifications sit the application-level controls built for a government deployment: enforced approval separation, query-level data scoping, an append-only audit trail and an independent auditor role.
Ask for the scope statement, not just the certificate number. An ISO 27001 certificate is only as meaningful as the scope it covers. We send ours unprompted, and we would treat any vendor that does not the same way you should.
What protects the ledger today
Enforced approval separation
Creation, approval and disbursement are three distinct permissions. The workflow refuses an approval from the user who created the loan. Disbursement is unavailable until an approval event exists.
Query-level data scoping
A regional permission sees one zone; a borrower sees only itself. Scoping constrains the data fetched rather than hiding interface elements, so it cannot be bypassed by constructing a URL.
Append-only audit trail
Once the book is live, no edit and no delete for any role including Admin. Corrections are new events referencing the original. Filterable by actor, action, borrower and date range. The migration reset tool is withdrawn at cut-over.
Independent auditor role
Read-only access across the entire portfolio and the complete event log, held outside the operations chain so that review does not depend on the goodwill of the team being reviewed.
What we do not have
Read this section as though you were the person who has to sign the risk assessment.
| Control | Status | What this means for you |
|---|---|---|
| ISO 9001 | Held | Certified quality management system covering how DigiWagon builds and supports software. |
| ISO 27001 | Held | Certified information security management system. Certificate and scope statement shared on request. |
| SOC 2 Type II | Not held | No third-party attestation of controls over a period. Common blocker for enterprise and US buyers. |
| DPDP alignment | Not assessed | ISO 27001 covers a great deal of the groundwork, but DPDP obligations have not been formally mapped against the product. |
| Multi-factor authentication | Available | MFA on GoDravix logins, and on DigiWagon's own systems under the ISO 27001 management system. |
| Single sign-on | Available | Built. The identity provider is configured against yours as part of the deployment, so bring your IdP details to the technical call. |
| Penetration test report | Not available | No current third-party penetration test to share with your security team. |
| On-premise and government cloud | Per deployment | Deployment shape is chosen per engagement: our managed cloud, your private cloud, your own infrastructure, or a government cloud. |
| Multi-tenancy isolation | Per deployment | Single-tenant deployment. There is no tenant isolation layer to review, because there are no shared tenants. |
| Data residency guarantees | Per deployment | Hosting region is agreed per engagement rather than offered as a certified guarantee. |
Test the controls, not just the certificate
ISO 27001 tells you a management system exists and is audited. It does not tell you how this particular application behaves when somebody tries to move money without approval.
So examine both. Ask for our certificates and scope statements, then run these six checks in a demo. Ask us to demonstrate the approval gate by trying to disburse an unapproved loan. Ask us to show what a zone-scoped user sees when they request data outside their zone. Ask the Auditor role to produce the full event history for a loan, then ask an Admin to delete one of those entries.
Those six tests tell you more about how a lending system behaves under pressure than a certificate does.
- Try to disburse without approval
The action should not be available. Verify it.
- Request data outside your scope
A zone-scoped user should get nothing, not a filtered view.
- Ask an Admin to delete an audit entry
There should be no mechanism. Check that there is not.
- Correct a wrong repayment
Both the error and the correction should remain visible.
- Reissue a certificate
Both issuances should appear in the trail.
- Run interest twice
Both runs should be logged with the user who triggered them.
About security
DigiWagon Technologies, which builds and supports GoDravix, holds ISO 27001 for information security and ISO 9001 for quality management. GoDravix is developed and operated under those certified systems. We send both certificates together with their scope statements, because a certificate without its scope tells a reviewer very little.
SOC 2 is a separate matter and is not held, neither Type I nor Type II. If your procurement treats SOC 2 as an eligibility condition rather than a scored criterion, that gate is still closed today.
Not formally assessed, so we will not claim compliance. ISO 27001 covers much of the underlying information-security groundwork that a DPDP programme depends on, but the two are not the same thing and mapping the product against DPDP obligations is work still to be done. We would rather scope it honestly than assert an alignment nobody has verified.
Both. Multi-factor authentication is available on GoDravix logins, and DigiWagon runs MFA across its own systems under the ISO 27001 management system. Single sign-on is built, and the identity provider is configured against yours as part of the deployment rather than being a development project. Bring your IdP details to the technical call and we will confirm the specifics against your setup.
Wherever your policy requires. The deployment shape is chosen per engagement: our managed cloud, your private cloud, your own infrastructure, or a government cloud. Region is agreed the same way. If data residency is a statutory requirement, raise it in the first conversation so it is scoped into the deployment rather than a configuration.
Not from a shelf. Where a customer requires one, a third-party test is commissioned as part of the engagement and the report goes to you.
Bring your security questionnaire
Send it before the first call. We will complete it honestly, including the rows where the answer is no.
45 minutes | On the live deployment | A straight answer on fit