Team — Certifyi | The People Behind the Platform
Lalitpur, Kathmandu — serving clients globally

The people who actually
do the compliance work

Certifyi is built and run by certified practitioners — not salespeople handing work off to junior staff. When you engage with us, you work directly with the same people who designed the platform.

Bhaskar

Founder and Technical Lead, Certifyi / Dignep Group

Bhaskar started Dignep Group in 2018 with a focus on enterprise software, GRC, and cybersecurity. Over time the work kept running into the same problem — startups losing deals or missing funding rounds because compliance moved too slowly and cost too much. Certifyi is the direct result of that frustration.

He works across product, engineering, and client delivery. On any given week that means designing platform architecture, running a client's weekly compliance check-in, and working through Sentinel AI's governance module — sometimes all three.

Before Certifyi, he led GRC and SOP portal implementations, AI governance workshops for local government, and enterprise software engagements across Nepal, Australia, and the US.

ISO/IEC Lead Implementer AI Governance GRC Architecture SOC 2 Full-Stack Engineering
Core team

Small team. Deep specialization.

Every person on the Certifyi team has a specific domain they own. No generalists filling in gaps.

Suman Adhikari

GRC Lead and ISO Implementer

Handles control design, framework mapping, and weekly client check-ins. Has led ISO 27001 and SOC 2 implementations across fintech and healthtech companies. The person in the room when auditors ask hard questions.

ISO 27001 SOC 2 Control Design

Priya Rana

AI Governance and Policy Specialist

Leads Certifyi's NIST AI RMF and EU AI Act coverage. Writes the governance templates and policy libraries that clients use to build their compliance posture from the ground up. Previously worked on AI ethics and regulatory frameworks across South Asia.

NIST AI RMF EU AI Act Policy Writing

Dev Tamrakar

Platform Engineer

Builds and maintains the Certifyi GRC platform. Owns the evidence collection pipeline, audit log architecture, and integrations. Background in enterprise SaaS and security engineering before joining Dignep Group.

React / TypeScript FastAPI Supabase

Asmita Shrestha

Vendor Risk and TPRM Lead

Runs third-party risk assessments and vendor security reviews for clients going through SOC 2 and ISO 27001. Designed the vendor questionnaire library inside the platform and manages security advisory engagements.

TPRM Vendor Assessments GDPR

Rohan KC

Security and Audit Specialist

Leads mock audits and pre-audit readiness reviews. Has worked as an internal auditor and security consultant before moving to the client side. Knows what auditors look for because he used to be one.

Internal Audit Mock Audits Gap Assessment

Nisha Karmacharya

Client Success and Engagement

Manages the client journey from the first scoping call through to post-certification check-ins. Keeps projects on schedule, translates between compliance teams and engineering, and makes sure nothing falls through during an active audit window.

Project Management Client Success Audit Liaison
What the team covers

Credentials that matter in the audit room

The team's certifications and specializations span the full scope of what Certifyi offers. Nothing is outsourced to a subcontractor for the core compliance work.

ISO/IEC Lead Implementation

Certified lead implementers who have run end-to-end ISO 27001, ISO/IEC, and ISO 20000 engagements across multiple industries and geographies.

SOC 2 Audit Readiness

Hands-on experience preparing companies for SOC 2 Type I and Type II audits — building control environments from scratch and navigating the observation period.

AI Governance Frameworks

Specialist coverage of NIST AI RMF and EU AI Act requirements. Built into the platform natively — not mapped from a generic SOC 2 template.

GRC Platform Engineering

The platform is built in-house. The engineers who maintain it also understand the compliance logic behind it — which is rarer than it sounds.

How we work

Nepal-based.
No handoffs.

The team is based in Lalitpur, Kathmandu. When you book a call, you talk to the person who will actually be doing the work — not a sales rep who then hands you to a delivery team you've never met.

We don't staff junior consultants on client work. The same people who built the platform run the engagements. That's a deliberate choice, not a function of company size.

We operate across time zones and have worked with clients in the US, Australia, and across South Asia. Nepal business hours overlap reasonably well with US morning and European afternoon, and we plan check-ins around what works for the client's team.

2018
Company founded in Lalitpur, Nepal
10+
Years in GRC and cybersecurity
3
Countries with active client engagements
0
Handoffs from sales to a delivery team
Work with us

Talk to the team before you commit to anything

The first call is a 30-minute scoping session. No pitch deck, no demo you didn't ask for. We'll map your frameworks and tell you what the engagement actually looks like.

Fixed-price quote provided within the week. No commitment required.

Scroll to Top