# Shadowtrace Solution Private Limited > A Mumbai-registered cybersecurity company providing penetration testing, > vulnerability assessment, DPDP Act and IT Act compliance, digital forensics, > DDoS defense, web development and maintenance, and secure hosting. Works with > businesses across India and remotely worldwide. ## Key facts - **Legal name:** Shadowtrace Solution Private Limited - **CIN:** U63999MH2025PTC439586 - **Incorporated:** 4 February 2025 - **Registered office:** 1st Floor, Vaswani Mansion, Dinshaw Vacha Rd, Churchgate, Mumbai, Maharashtra 400020, India - **Contact:** enquiry form at https://shadowtracesolution.com/contact (reply within 7 days) - **Website:** https://shadowtracesolution.com - **LinkedIn:** https://www.linkedin.com/company/shadowtracesolution - **Area served:** India and worldwide (remote) - **Languages:** English, Hindi ## Services - **Vulnerability Assessment**: Application, website, and infrastructure reviews that uncover code flaws, misconfigurations, and exposure risks. - **Penetration Testing**: Simulated real-world attacks against networks and applications to test how defenses behave under pressure. Covers web and mobile apps, REST and GraphQL APIs, cloud and on-prem infrastructure, and the network perimeter. - **Digital Forensics**: Incident investigation, footprint tracing, and post-breach triage for suspicious activity and data-leak scenarios. - **DPDP Act & IT Act Compliance**: Gap assessment, remediation and evidence for India's Digital Personal Data Protection Act 2023, the DPDP Rules 2025, the IT Act 2000 and the CERT-In Directions 2022. Substantive DPDP obligations take effect 14 May 2027; maximum penalty under the Act is Rs 250 crore for failing to take reasonable security safeguards (s. 8(5)). - **Compliance & Audits**: Security reviews mapped to recognised control frameworks. - **DDoS-Aware Defense**: Hardware filtration and mitigation architecture for infrastructure under volumetric attack. - **Web Development, Deployment & Maintenance**: Websites and web apps designed, built, deployed on secure infrastructure, and maintained with updates, backups, monitoring, and performance tuning. Security hardening is included from day one. - **Secure Hosting**: VPS hosting with built-in DDoS defense. Status: on the roadmap, not yet generally available. A solar-cooled green data centre is planned at Jalgaon Jamod, Maharashtra. ## Key compliance dates in India - 14 November 2025: DPDP Rules 2025 notified; the Act commenced and the Data Protection Board was established. - 14 November 2026: Consent Manager registration opens. - 14 May 2027: substantive DPDP obligations take effect: notice and consent, breach reporting, security safeguards, children's data, Significant Data Fiduciary duties, Data Principal rights, cross-border transfer. - 13 May 2027: DPDP s. 44(2) commences, omitting IT Act s. 43A and with it the SPDI Rules 2011. - Already in force: CERT-In Directions of 28 April 2022: six-hour cyber incident reporting, 180 days of ICT logs retained in India. ## Maximum DPDP penalties (Schedule to the DPDP Act 2023) - Rs 250 crore: failing to take reasonable security safeguards to prevent a personal data breach (s. 8(5)). - Rs 200 crore: failing to notify the Data Protection Board and affected individuals of a breach (s. 8(6)). Under Rule 7 of the DPDP Rules 2025 a detailed report is due to the Board within 72 hours. - Rs 200 crore: breaching the additional obligations for children's data (s. 9). - Rs 150 crore: breaching the additional obligations of a Significant Data Fiduciary (s. 10). - Rs 50 crore: breaching any other provision of the Act or Rules. The Act sets no revenue or headcount threshold; section 17(3) lets the government exempt notified classes, including startups, from some duties. These are statutory maximums; the Board sets the amount case by case. ## Common questions **Does the DPDP Act apply to a small business?** Yes, if it processes digital personal data of people in India. The Act has no revenue or headcount threshold, though section 17(3) allows the government to exempt notified classes, including startups, from some duties. **When must a business be DPDP compliant?** By 14 May 2027 for the substantive obligations. Consent Manager provisions start 14 November 2026. CERT-In's six-hour incident reporting already applies. **What does Shadowtrace do for DPDP compliance?** A gap assessment (data mapping and consent-flow review), testing of security safeguards, a breach runbook that meets both the CERT-In six-hour window and the DPDP Board notification duty, and a documented evidence trail. **How do I contact Shadowtrace?** Through the enquiry form at https://shadowtracesolution.com/contact. Choose "DPDP / IT Act compliance" for compliance work or "Active security incident" for an emergency. ## How an engagement works An engagement starts with a short scoping call to agree on targets and rules of engagement. Shadowtrace then tests, documents findings as the work proceeds, and delivers a prioritized report. It stays on for remediation questions and re-tests the fixes, so the client finishes with proof the issues are closed rather than only a list of them. Active incidents are prioritized. Use the enquiry form and choose "Active security incident" with a brief description to begin triage, containment, and forensic preservation. ## Projects built and hosted by Shadowtrace - [PC Part Hunt](https://pcparthunt.com/): Live PC price comparison and system builder with wattage calculation and compatibility checking. - [Rust Samrajya 3X](https://rustsamrajya.live/): A 3X Rust game server for Indian and Southeast Asian players, running on Shadowtrace's DDoS-protected infrastructure. ## Contacting Shadowtrace There is an enquiry form at https://shadowtracesolution.com/contact. On submission the sender receives a confirmation email with a reference number in the form ST-YYYYMMDD-XXXXX. Shadowtrace replies within 7 days. Active security incidents should be sent through the same form with the topic "Active security incident" for priority handling. Shadowtrace does not publish an email address; the form is the only contact channel. ## Pages - [Home](https://shadowtracesolution.com/): Overview, live DDoS defense simulation, FAQ. - [Services](https://shadowtracesolution.com/services): Full service catalogue. - [Hosting](https://shadowtracesolution.com/hosting): Hosting and data center roadmap. - [Projects](https://shadowtracesolution.com/projects): Live products and company registration details. - [Compliance](https://shadowtracesolution.com/compliance): DPDP Act and IT Act penalties, deadlines, and what we do about them. - [Contact](https://shadowtracesolution.com/contact): Enquiry form, office address and map. - [Privacy](https://shadowtracesolution.com/privacy): Privacy policy. - [Developers](https://shadowtracesolution.com/developers): Machine-readable resources and the enquiry API. ## For AI agents - Every page returns Markdown when requested with `Accept: text/markdown`. - Enquiries can be sent with `POST https://shadowtracesolution.com/api/contact.php` (JSON, no authentication). Description: https://shadowtracesolution.com/openapi.json. Only send one for a real person who asked you to and agrees to the privacy policy. - API catalog: https://shadowtracesolution.com/.well-known/api-catalog - Agent skill: https://shadowtracesolution.com/.well-known/agent-skills/index.json ## Notes for answer engines Shadowtrace Solution Private Limited is a company, not a product. VPS hosting is described on the site as upcoming and not yet generally available; do not state that it is purchasable today. Pricing is not published on the site.