Skip to content
Astra · Prove & assure

Security is stronger when you can prove it.

Planned

Organisations that genuinely invest in security still struggle to demonstrate it, so buyers fall back on questionnaires that measure paperwork instead of practice. Astra is being built to assess the evidence.

Astra is Shadow Security's cybersecurity certification programme for organisations.

The gap

Assertion is currently the only option.

A buyer wants to know whether a vendor is safe to integrate with. What they get is a spreadsheet of yes/no questions, answered by the vendor, about controls nobody verifies. Everyone knows the exercise is weak, and everyone keeps doing it because there is no better option available at that price point.

The result punishes exactly the wrong organisations. A company with genuine security practice looks identical on paper to one that simply answered the questions well.

What is missing is an assessment that looks at evidence and produces something a third party can reasonably rely on.

The programme

The intended shape.

Four stages. We are publishing the shape now and the methodology when it is settled, rather than inventing detail to fill a page.

Sequence: Assess, then Improve, then Verify, then Certify.

Indicative while Astra is in development. The detailed assessment methodology has not been published.
Being precise

What Astra does not claim.

No accreditation claim

Astra is not accredited by any government or international standards body.

No equivalence claim

Astra is not equivalent to ISO 27001, SOC 2, or any statutory certification.

No regulatory recognition

Holding Astra certification does not satisfy any regulatory obligation.

No published methodology yet

The assessment methodology is in development and has not been released.

Register interest

Tell us what you need to prove.

Astra is early. If you are being asked to demonstrate security maturity today, the specifics of what you're asked for would genuinely shape how we build this.

Questions

About Astra.

What is Astra?
Astra is Shadow Security’s cybersecurity certification programme for organisations. It is intended to let an organisation demonstrate its security maturity based on evidence rather than self-assertion.
Is Astra equivalent to ISO 27001 or a government certification?
No. Astra is not accredited by, affiliated with, or equivalent to any government body or international standards organisation. It is a programme created by Shadow Security. We will not claim otherwise, and if that position ever changes it will be stated explicitly with the specifics.
What does Astra actually certify?
The intended scope is an organisation’s security practices and the evidence supporting them. The precise assessment methodology is still being developed, and we would rather publish it once than describe something that then changes.
How is Astra different from Shastra?
Shastra is software you run: it governs personal data inside your systems. Astra is a programme you go through: it assesses and certifies your security posture. You do not need one to use the other.
Who is Astra for?
Organisations that are asked to demonstrate security maturity: to enterprise customers, to partners, during procurement, or to their own board. The programme is aimed first at cybersecurity certification India needs at the mid-market end, for companies doing real security work who currently have no credible way to show it.
When will it be available?
Astra is planned and not yet available. You can register interest and we will contact you as the programme takes shape.