The Parent's Rules, Enforced Where the Code Is Written
A capability centre inherits a regulator it never registered with and a security standard set on another continent. Whitespots deploys locally, enforces the parent's standard on the code written here, and keeps the data inside the boundary the contract specifies.
Data stays inside the boundary
Cross-border clauses usually say where source code and derived data may sit. A locally deployed platform respects that by construction.
The parent's standard, applied here
The same rules, severities and quality gates as the head-office deployment — not a local approximation reported upward once a quarter.
Reports for head office and the local regulator
A local instance keeps code and findings in the country, while its reports give the parent's auditor and the local regulator what each of them asks for.
Cost that fits the headcount model
A capability centre exists to add engineers. Per-developer security pricing works directly against that; flat pricing does not.
What Capability Centres Run Into
A GCC carries obligations from a jurisdiction it does not operate in, applied to engineers it hired locally, on systems the parent owns.
Compliance inherited, not chosen
The parent's regulator sets the requirement. The centre has to satisfy it without the context, the relationships or the mandate that produced it.
Contractual data boundaries
Master services agreements and intra-group contracts often constrain where code and derived data may be processed — including by security tooling.
Standards that drift by location
Two engineering organisations, two toolchains, two definitions of a critical finding, and a group report that has to pretend otherwise.
Rapid hiring, static security headcount
Engineering scales because that is the point of the centre. The security function rarely scales with it, so the process has to.
What Applies, and Where It Comes From
Most obligations here arrive through the parent or the contract rather than from the local regulator — but not all of them.
Obligations of data fiduciaries
Reasonable security safeguards to prevent personal data breaches, breach notification to the Data Protection Board and affected persons, and obligations that flow to processors handling data on another entity's behalf.
How Whitespots helps
The platform covers the prevention side: continuous scanning and automatic notifications find vulnerabilities before they lead to a breach, and process reports show the safeguards work. Detecting a breach is a job for your monitoring tools — but if one happens, the findings history shows what was known about the affected system and how it was handled.
Cyber incident reporting directions
Reporting of specified cyber incidents within a short window of noticing them, together with log retention obligations for service providers and intermediaries.
How Whitespots helps
With scanning, notifications and SLAs already running, every vulnerability in an affected system has been found, assigned and tracked from the start. When an incident is noticed, the report starts from that record instead of from a search under deadline.
Chapter V · international transfers
Transfers outside the EEA require an appropriate safeguard, and the technical measures protecting the data must be regularly tested and evaluated.
How Whitespots helps
A locally deployed platform does not create a further transfer of its own, and it produces the testing evidence Article 32 asks for.
Intra-group ICT arrangements
Where the parent is a financial entity, ICT services provided by a group entity are still ICT third-party arrangements subject to the register and the risk framework.
How Whitespots helps
Per-entity scoping so the centre's systems can be reported as their own line rather than folded invisibly into the parent's.
Annex A, as listed in BSI's mapping table
Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing — commonly the standard a parent certifies against group-wide.
How Whitespots helps
The same controls evidenced identically in both locations, which is what makes a group certification survive a site audit.
Data residency and sub-processor clauses
Intra-group and customer contracts frequently name where code and derived data may be processed and require approval of any further processor.
How Whitespots helps
Self-hosting means the security platform is not a further processor and adds no location to declare.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. Applicability depends on the parent's sector, the centre's legal form and the contracts between them, and Indian requirements are given as the most common case rather than the only one. Confirm with group compliance and local counsel.
What Whitespots Gives a Capability Centre
One standard across two locations, without a shared cloud in the middle.
Code stays local, and the group's rules still apply
-
Same standard as headquarters Rules, severities and gates match the parent deployment.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Leave whenever you want Exit is a database export, not a vendor negotiation.
Report to group and to the local authority from one record
-
Evidence per entity and site Per-entity and per-site scoping.
-
Every decision traceable Per-finding trail of scanner, severity and decision.
-
Both audiences served Exportable reports for group audit and local regulators.
Grow the team without buying more licences
-
Headcount doesn't change the price Flat, per-organisation pricing.
-
New teams onboard without pipeline work Connected through a VCS webhook.
-
Findings reach the right owner Routed to repository and service owners.
Both sites agree on what blocks a merge
-
Identical pull-request checks The same gates as the parent organisation.
-
A critical means the same everywhere Shared severity model.
-
Developers see the issue on the exact line Findings in the IDE, with remediation guidance.
Where It Lands
What a capability centre's security function is usually asked to produce.
- Scenario
Group audit checks the centre against the parent standard
With Whitespots platformThe same rules in both locations, with reports to prove it.
- Scenario
A contract restricts where code may be processed
With Whitespots platformThe platform runs inside the boundary and adds no further processor.
- Scenario
A local incident-reporting duty applies
With Whitespots platformThe affected system's findings history, ready before the reporting window opens.
- Scenario
Engineering headcount doubles
With Whitespots platformCoverage and cost unchanged; findings route to the new teams automatically.
What Global Capability Centers Teams Ask First
Should we run our own deployment or use the parent's?
It depends on the contract. Where an agreement constrains where source code or derived data may be processed, a local deployment is the clean answer. Where it does not, a single deployment with per-site scoping is simpler. Both are supported; the decision is legal rather than technical.
How do we keep our standard identical to head office?
By sharing the configuration rather than the instance: the same rules, severity model and quality gates applied to both deployments. That is what makes a group certification survive a site audit, and it removes the argument about whether a critical here means a critical there.
The parent is regulated and we are not. Does that change our obligations?
Usually it transfers them by contract rather than removing them. Intra-group ICT arrangements are still arrangements — under DORA, for instance, a group entity providing ICT services is inside the register. Treat the parent's framework as your requirement and confirm the detail with group compliance.
We hire aggressively. Does the licence cost track headcount?
No. Pricing is flat and per-organisation, not per developer or per asset, so every new team and system is covered at no extra cost.
Can one instance serve several sites in different countries?
Yes, with per-site scoping and roles — provided no contract or local rule requires the data to stay in a specific country. Where one does, a separate deployment per boundary is the straightforward answer.
One Standard, Enforced Where the Code Is Written
Talk to us about a local deployment configured to your parent entity's standard, or start with a free external scan of the surface you own.