Where we work: remote security services from India
One office in India — and clients on three continents.
Our only office is in India. From there we work remotely for companies in India, Southeast Asia, Europe, the Middle East and the USA, on security and software projects. This page explains how that works, and names a rule each region brings to the job.
One office, in India. Its street address is on our contact page. We list no office in any other country.
Who we work with
Companies in India, Southeast Asia, Europe, the Middle East and the USA, for security work and for software work.
How it works
Remotely, from India, during business hours there. You tell us which rules you answer to. We won't guess them from your address.
Rules by region
What a buyer in each region brings to the work.
Each rule below was read on the government's or regulator's own site, or on our own page that covers it.
India
The CERT-In (Indian Computer Emergency Response Team) Directions of 28 April 2022 took effect sixty days after issue, and bind now. The duties the Digital Personal Data Protection (DPDP) Act, 2023 places on a business toward individuals commence in May 2027, as our DPDP Act page explains.
Southeast Asia
Rules differ from country to country. Malaysia, for example, amended its Personal Data Protection Act 2010 in 2024. The Personal Data Protection Commissioner's guideline of 25 February 2025 says a data controller (the organization that decides how personal data is used) must report a personal data breach to the Commissioner and, where its criteria are met, to the people affected.
Europe
A buyer in the EU brings the GDPR (General Data Protection Regulation). The European Commission's list of adequacy decisions names the countries whose data protection it accepts as adequate, so EU personal data can go there without extra safeguards. India is not on it. Our GDPR page sets out what that means for personal data sent to a firm in India.
Middle East & Gulf
Rules differ from country to country. In Kuwait, the Communication and Information Technology Regulatory Authority (CITRA) publishes a Data Privacy Protection Regulation on its own site. Check there which version reaches your organization: this page quotes nothing from it beyond the name.
United States
The Federal Trade Commission's data breach response guide for business says every state, along with the District of Columbia, Puerto Rico and the Virgin Islands, has a law requiring notice of breaches involving personal information.
Somewhere else
Nothing changes for you except the rules. Name the regulator you answer to when you write. This page covers only the regions where we already have clients.
One office
A country on this site means a client is there, nothing more.
If you are checking a vendor abroad, you should be able to confirm each point from this page alone.
Our one office, and the company's registered address, are in India. The street address is on the contact page. This site lists no office or registered address in any other country.
Clients are another matter. Companies in India, Southeast Asia, Europe, the Middle East and the USA have hired us for remote security services from India, and for software work, without us opening an office near any of them.
On a vendor's site, a country name can suggest a local team, a local company and someone accountable nearby. A page for every country would suggest exactly that. So we keep one page for all five regions, and you are reading it.
Not on offer outside India
A local office, branch or partner in Southeast Asia, Europe, the Middle East or the USA.
A contract with a local company. Your contract is with SecWiz Technologies Pvt. Ltd., the company in India.
A local representative named under any country's privacy law.
Legal advice on any country's law.
A separate landing page for each client country.
We are not a law firm. We are a security and software engineering firm. Our pages name rules and who published them. How a rule applies to your company is a question for your own counsel.
Working from another country
How an inquiry from outside India runs.
Four steps, wherever you are. Before step one, gather the answers only your side can give.
01
Write from the contact page
Use the contact page wherever you are. It carries our address in India, and your message goes straight to the team there.
02
Get a reply
We reply within one working day. That holds for every inquiry, wherever it is sent from.
03
Name the rules you answer to
Tell us which country's rules govern your data and systems, starting from the region cards above. We won't assume a rule for you or pick one on your behalf.
04
Plan around the Indian working day
We deliver project work remotely from India, during business hours there. If you're in a distant time zone, you set your schedule around the Indian working day. Retainers for ongoing work, including incident response, are a separate purchase, described on managed security services.
Before you write
Start with the question you have.
Questions that often come before a first message, each answered on its own page.
Offices, time zones, hiring from abroad and the law. For anything else, ask us directly.
SecWiz has one office, and it is in India. The full street address is published on the contact page of secwiztech.com, and this site lists no office in any other country. Clients outside India work with SecWiz remotely. The address on the contact page is the only one a buyer needs to check.
No. SecWiz has clients in Southeast Asia, Europe, the Middle East and the USA as well as in India, but the only office it lists is in India. Project work for clients abroad is delivered remotely from India during business hours there.
Yes. SecWiz has 150+ projects delivered so far, for clients in India, Southeast Asia, Europe, the Middle East and the USA. A buyer in any other country can write through the contact page. We reply within one working day. Be ready to name the rules your own regulator applies, because SecWiz will not guess them from your address.
A page per country would imply an office per country, and the only office SecWiz lists is in India. Instead of separate pages for each region, the site keeps a single page that lists each client region and names a rule a buyer there brings. The detail on India's DPDP Act and the EU's GDPR sits on pages of their own.
No. SecWiz is a security and software engineering firm, not a law firm. Its pages name rules published by governments and regulators, such as Malaysia's Personal Data Protection Commissioner or Kuwait's CITRA, and say who published them. How a rule applies to a particular company is a question for that company's own counsel, and a buyer should settle it with counsel rather than expect it from a vendor.
Project work runs on Indian time, from the office in India, during business hours there. Retainers for ongoing work, including incident response, are a separate purchase, described on managed security services. Clients in Southeast Asia, Europe, the Middle East and the USA are served remotely rather than by a local team. We reply within one working day. That holds whichever country an inquiry is sent from.
Let's talk
Write to the office in India.
Tell us where your company and your users are, and which regulator you answer to. The contact page has our address and every way to reach the team. We reply within one working day.