Frequently asked questions
What Offload Security is, how it's deployed, how pricing works, and how we handle your data — the questions buyers ask most. Still have one? Talk to us.
What is Offload Security?
A unified cybersecurity platform (CNAPP + compliance/GRC) covering cloud, code, containers, Kubernetes, vulnerability management, and compliance — backed by a practitioner-led professional-services team. You get one governed view of security and compliance instead of a dozen disconnected scanners and spreadsheets.
Is Offload a product, a professional service, or both?
Both. Use the platform on its own, deploy it with our experts, or engage us to run specific security and compliance programmes with your team (pentesting, assessments, ISO 27001 / SOC 2 / DPDP readiness, DevSecOps). See the Platform and Services pages.
Is it SaaS or can we run it on-premises?
Both. Offload runs as SaaS or deploys fully on-premises (including air-gapped, where supported) — so personal data, security findings, and evidence never leave your environment. On-prem is a common requirement for BFSI, healthcare, and other regulated organisations in India.
How does pricing work?
Offload uses a predictable platform-licence model — not per-developer, per-scanner, or cloud-spend pricing. Your price depends on deployment model (SaaS vs on-premises), environment scale, the modules you need, and support level. We're happy to share indicative packaging and scope a bounded pilot — talk to us for a quote.
Which clouds and scanners does it support?
AWS, GCP, and Azure for cloud posture, plus code, container, Kubernetes, and network scanning. Offload runs its own engines and ingests third-party tools you already use — e.g. Wazuh, OpenVAS, SonarQube, Snyk, Trivy, Grype, and more — deduplicating their findings into one data layer. See the docs for the full engine list.
How do you handle our source code and credentials?
Source-code scanning runs in ephemeral workspaces that are destroyed after the scan; only minimal excerpts needed for a finding are retained. Credentials are encrypted at rest, tenant isolation is enforced on every read and write, and we never train AI on your data. See the Trust Center for the full architecture.
How long does implementation take, and what does a pilot look like?
Most teams connect their first cloud accounts and repositories and see consolidated findings quickly. We also offer a bounded pilot with measurable success criteria — a scoped set of environments over a defined window — so you can validate value before a broader rollout.
Do you help with India's DPDP Act?
Yes. There's a dedicated DPDP module (breach-deadline tracking, DPIAs, Significant Data Fiduciary classification, vendor due diligence, readiness scoring, audit packs), and a free, no-signup DPDP Readiness Checker you can run in your browser today.
What support do you offer?
From self-serve platform use through guided implementation to managed programmes where our practitioners operate specific security and compliance workstreams with your team. Support level is part of your package.
Ready to see it on your environment?
Book a walkthrough, or start with the free DPDP Readiness Checker — no signup, runs in your browser.