Compliance ยท SEBI Cloud Framework
AravaliStack and SEBI's cloud adoption framework.
SEBI's 2023 circular on cloud adoption by regulated entities creates specific requirements for stock brokers, depositories, exchanges, and asset managers. AravaliStack maps directly to each.
SEBI Circular: Cloud Adoption by SEBI Regulated Entities
SEBI's circular requires that regulated entities (stock exchanges, depositories, brokers, investment managers) ensure data sovereignty, maintain supervisory access for SEBI, implement robust cybersecurity for market data, and avoid single-point-of-failure in cloud infrastructure. Circular requires documented cloud strategy and annual board-level review.
We offer a dedicated 45-minute briefing for SEBI-regulated entities โ covering our architecture, SEBI compliance mapping, and how to present this to your compliance officer and board.
- SEBI Requirement Status AravaliStack Approach
- Trading and investor data must remain within India
- All market data, order books, and investor records are stored on the entity's own hardware within India. No cloud provider has access to trading data. SEBI supervisory access provided via dedicated audit interface.
- High Availability for Critical Systems
- Market infrastructure must maintain near-zero downtime
- AravaliStack supports 99.99% SLA with multi-site active-active deployment. Auto-failover within 15 seconds. Chaos engineering built into platform for continuous resilience testing. RTO of <1 minute achievable.
- Mandatory security controls for market infrastructure
- Zero-trust perimeter, mTLS service mesh, intrusion detection, SIEM integration, and real-time threat detection aligned to SEBI's cybersecurity framework. CERT-In empanelled VAPT biannual.
- Board Reporting
- AravaliStack generates automated board-ready cloud governance reports โ infrastructure map, compliance posture, incident summary, SLA performance โ exportable as PDF for board review.
