Industry GCCs, offshore engineering & shared services

The Parent's Rules, Enforced Where the Code Is Written

A capability centre inherits a regulator it never registered with and a security standard set on another continent. Whitespots deploys locally, enforces the parent's standard on the code written here, and keeps the data inside the boundary the contract specifies.

Data stays inside the boundary

Cross-border clauses usually say where source code and derived data may sit. A locally deployed platform respects that by construction.

The parent's standard, applied here

The same rules, severities and quality gates as the head-office deployment — not a local approximation reported upward once a quarter.

Reports for head office and the local regulator

A local instance keeps code and findings in the country, while its reports give the parent's auditor and the local regulator what each of them asks for.

Cost that fits the headcount model

A capability centre exists to add engineers. Per-developer security pricing works directly against that; flat pricing does not.

Key challenges

What Capability Centres Run Into

A GCC carries obligations from a jurisdiction it does not operate in, applied to engineers it hired locally, on systems the parent owns.

Contractual data boundaries

Master services agreements and intra-group contracts often constrain where code and derived data may be processed — including by security tooling.

Standards that drift by location

Two engineering organisations, two toolchains, two definitions of a critical finding, and a group report that has to pretend otherwise.

Clause map

What Applies, and Where It Comes From

Most obligations here arrive through the parent or the contract rather than from the local regulator — but not all of them.

DPDP Act 2023 India

Obligations of data fiduciaries

Reasonable security safeguards to prevent personal data breaches, breach notification to the Data Protection Board and affected persons, and obligations that flow to processors handling data on another entity's behalf.

How Whitespots helps

The platform covers the prevention side: continuous scanning and automatic notifications find vulnerabilities before they lead to a breach, and process reports show the safeguards work. Detecting a breach is a job for your monitoring tools — but if one happens, the findings history shows what was known about the affected system and how it was handled.

CERT-In India

Cyber incident reporting directions

Reporting of specified cyber incidents within a short window of noticing them, together with log retention obligations for service providers and intermediaries.

How Whitespots helps

With scanning, notifications and SLAs already running, every vulnerability in an affected system has been found, assigned and tracked from the start. When an incident is noticed, the report starts from that record instead of from a search under deadline.

GDPR European Union

Chapter V · international transfers

Transfers outside the EEA require an appropriate safeguard, and the technical measures protecting the data must be regularly tested and evaluated.

How Whitespots helps

A locally deployed platform does not create a further transfer of its own, and it produces the testing evidence Article 32 asks for.

DORA European Union

Intra-group ICT arrangements

Where the parent is a financial entity, ICT services provided by a group entity are still ICT third-party arrangements subject to the register and the risk framework.

How Whitespots helps

Per-entity scoping so the centre's systems can be reported as their own line rather than folded invisibly into the parent's.

ISO/IEC 27001:2022 International

Annex A, as listed in BSI's mapping table

Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing — commonly the standard a parent certifies against group-wide.

How Whitespots helps

The same controls evidenced identically in both locations, which is what makes a group certification survive a site audit.

Parent entity · MSA Contract

Data residency and sub-processor clauses

Intra-group and customer contracts frequently name where code and derived data may be processed and require approval of any further processor.

How Whitespots helps

Self-hosting means the security platform is not a further processor and adds no location to declare.

References reflect published text as of August 2026 and describe obligations rather than a certification we grant. Applicability depends on the parent's sector, the centre's legal form and the contracts between them, and Indian requirements are given as the most common case rather than the only one. Confirm with group compliance and local counsel.

Platform

What Whitespots Gives a Capability Centre

One standard across two locations, without a shared cloud in the middle.

Local deployment 01

Code stays local, and the group's rules still apply

  • Same standard as headquarters Rules, severities and gates match the parent deployment.

  • Zero outbound data No code, findings, logs or usage data leave your servers.

  • Leave whenever you want Exit is a database export, not a vendor negotiation.

See deployment options →
Two-way reporting 02

Report to group and to the local authority from one record

  • Evidence per entity and site Per-entity and per-site scoping.

  • Every decision traceable Per-finding trail of scanner, severity and decision.

  • Both audiences served Exportable reports for group audit and local regulators.

How it works →
Scales with hiring 03

Grow the team without buying more licences

  • Headcount doesn't change the price Flat, per-organisation pricing.

  • New teams onboard without pipeline work Connected through a VCS webhook.

  • Findings reach the right owner Routed to repository and service owners.

Explore the platform →
Developer experience 04

Both sites agree on what blocks a merge

  • Identical pull-request checks The same gates as the parent organisation.

  • A critical means the same everywhere Shared severity model.

  • Developers see the issue on the exact line Findings in the IDE, with remediation guidance.

See the IDE integration →
Outcomes

Where It Lands

What a capability centre's security function is usually asked to produce.

  • Scenario

    Group audit checks the centre against the parent standard

    With Whitespots platform

    The same rules in both locations, with reports to prove it.

  • Scenario

    A contract restricts where code may be processed

    With Whitespots platform

    The platform runs inside the boundary and adds no further processor.

  • Scenario

    A local incident-reporting duty applies

    With Whitespots platform

    The affected system's findings history, ready before the reporting window opens.

  • Scenario

    Engineering headcount doubles

    With Whitespots platform

    Coverage and cost unchanged; findings route to the new teams automatically.

FAQ

What Global Capability Centers Teams Ask First

Should we run our own deployment or use the parent's?

It depends on the contract. Where an agreement constrains where source code or derived data may be processed, a local deployment is the clean answer. Where it does not, a single deployment with per-site scoping is simpler. Both are supported; the decision is legal rather than technical.

How do we keep our standard identical to head office?

By sharing the configuration rather than the instance: the same rules, severity model and quality gates applied to both deployments. That is what makes a group certification survive a site audit, and it removes the argument about whether a critical here means a critical there.

The parent is regulated and we are not. Does that change our obligations?

Usually it transfers them by contract rather than removing them. Intra-group ICT arrangements are still arrangements — under DORA, for instance, a group entity providing ICT services is inside the register. Treat the parent's framework as your requirement and confirm the detail with group compliance.

We hire aggressively. Does the licence cost track headcount?

No. Pricing is flat and per-organisation, not per developer or per asset, so every new team and system is covered at no extra cost.

Can one instance serve several sites in different countries?

Yes, with per-site scoping and roles — provided no contract or local rule requires the data to stay in a specific country. Where one does, a separate deployment per boundary is the straightforward answer.

One Standard, Enforced Where the Code Is Written

Talk to us about a local deployment configured to your parent entity's standard, or start with a free external scan of the surface you own.