Corporate & Commercial
Incorporation, shareholder and vendor agreements, technology transactions and mergers, structured to be commercially practical and enforceable when it matters.
Explore this practiceAdvocates & counsel · Hyderabad · Delhi NCR · Austin
SIRI Law LLP is a multi-service law firm in Hyderabad advising founders, boards, families and enterprises across corporate, litigation, data privacy, IP, banking, employment, property, tax, family and cyber law.
The firm
We are a law firm for people who build, run and protect things: companies, careers, families and data. Eleven practice areas, one accountable team, and no hand-offs between the advice you get and the work that follows.
What we do
Swipe to browse all eleven →
Incorporation, shareholder and vendor agreements, technology transactions and mergers, structured to be commercially practical and enforceable when it matters.
Explore this practice →Advocacy across commercial, corporate, consumer and technology disputes, from urgent injunctions to long-running tribunal matters.
Explore this practice →DPDPA 2023 programmes, cross-border transfers, breach response and cybercrime advisory, led by advocates who work alongside forensic engineers.
Explore this practice →Protecting and enforcing what your business creates: trademarks, patents, copyright, trade secrets and technology licensing.
Explore this practice →Regulatory and transactional counsel for banks, NBFCs, payment companies and fintechs: licensing, compliance, cross-border investment and financing.
Explore this practice →Employment contracts, workplace policies, POSH compliance, labour-code readiness, restructuring and defending or bringing employment claims.
Explore this practice →Purchase and sale, title diligence, lease structuring and RERA matters for developers, investors, businesses and homeowners.
Explore this practice →Direct and indirect tax advisory, regulatory filings and cross-border structuring that stands up to scrutiny.
Explore this practice →Sensitive personal matters handled with discretion: matrimonial proceedings, succession, guardianship and family dispute resolution.
Explore this practice →SIRI Security: penetration testing, red teaming, cloud security and certification programmes, run under a single legal engagement so findings stay privileged.
Explore this practice →Governance, contracts and liability for AI, blockchain and digital assets, and legal counsel for health-technology products.
Explore this practice →Not sure which team you need?
Cyber incident response · 24/7
CERT-In's 2022 Directions require notification within six hours of noticing an incident. Our advocates and forensic engineers join the same call, preserve evidence, and prepare the regulatory filing while the technical team contains the breach.
When must we notify CERT-In?
Sectors
Every sector has its own regulator, its own contracts and its own failure modes. We bring sector-specific counsel to each, from RBI and SEBI to ABDM and IRDAI.
How we work
Tell us what is happening, at whatever level of detail you have. We check conflicts and jurisdiction first, and if we are not the right firm we say so immediately.
You receive our view of the situation, the risks, the options and the cost, in writing, before anything is billed. Fixed fee, retainer or staged estimate, whichever suits the matter.
A named advocate owns your matter. Where the problem has a technical side, our security engineers and forensic examiners work inside the same engagement, not in a separate one.
When the matter closes we do not disappear. Retainer clients keep a lawyer who already knows their business, plus regulatory updates as the rules change.
Selected outcomes
A selection of matters, anonymised at the client's request. The deadline in each one was the real deadline.
Attorneys and forensic engineers moved together. CERT-In notification and containment closed within 72 hours and no regulatory penalty followed.
Legal and security diligence ran as one workstream instead of two, so material risks surfaced early and were priced into the final deal terms.
A single breach triggered notification duties in India, the EU and the US at once. All three were managed in parallel and no enforcement action followed.
An enterprise deal was on hold for one line item. Legal drafting and the technical audit ran in parallel and certification was delivered in 14 weeks.
Client names withheld and details anonymised by sector and role. Outcomes are specific to those matters and are not a guarantee of results in any other situation.
Your next step
Pick whichever suits you. Every route starts with a free conversation and a conflicts check, with no obligation.
Call between 9:30 AM and 7:00 PM IST, Monday to Saturday. The incident line is open 24/7.
+91 79819 12046 → 02Share the situation at a high level. We reply within one working day and confirm a secure channel before documents.
Open WhatsApp → 03Send a short enquiry and choose your practice area. We come back to you with a time, in person in Hyderabad or online.
Fill the form →SIRI Shield · Retainer
Fixed-fee counsel for growing companies: a dedicated advocate, security testing and incident response on a predictable monthly retainer. No surprise invoices.
Pre-seed and seed startups, early fintech and healthtech
Series A to C companies, regulated startups, SaaS serving enterprises
Large and regulated organisations with multi-jurisdiction exposure
Our people
Advocates, security engineers and forensic examiners who have advised through live breaches, regulatory investigations and cross-border transactions. Every engagement carries a named lead who answers for the outcome.
Counsels boards and CISOs through cyber incidents, DPDPA implementation and AI governance. Practises before the Supreme Court of India and is enrolled with the Bar Councils of Uttar Pradesh and Telangana.
Leads data protection across DPDPA, GDPR and HIPAA.
Heads litigation and disputes before the Delhi High Court and NCLT.
Leads AI and emerging-technology law.
Leads corporate and commercial, from venture rounds to M&A.
Heads governance and compliance programmes.
Directs offensive security and incident response.
Prepares court-admissible forensic reports and testifies as an expert witness.
Advises startups from incorporation through Series C.
Advises banks, NBFCs and payment aggregators on RBI and SEBI matters.
Runs adversarial testing of LLM and RAG deployments.
Advises hospitals and healthtech platforms on ABDM and HIPAA.
Insights
Commentary on court rulings, regulation and compliance, written to change what your organisation does next.
Questions
The questions we hear most. If yours is not here, ask us directly.
We are a multi-service firm. Our practice areas are corporate and commercial, litigation and dispute resolution, data privacy and cyber law, IP and technology, banking and finance, employment and labour, real estate, taxation, family law, cybersecurity and compliance, and AI and emerging technology. If your matter sits between two of these, that is usually where we are most useful.
Yes. We check for conflicts first, listen to your situation, and give you an honest view of how we can help and what it would cost. If we are not the right firm, we will say so. Contacting us does not create an advocate–client relationship, which begins only when an engagement is confirmed in writing.
Our advocates are enrolled with the Bar Council and appear before courts, tribunals and regulators in matters we take on, including High Courts, NCLT, the Cyber Appellate Tribunal and consumer forums. At scoping we confirm the forum, the counsel and the plan, so you know who will be in the room.
Fees are agreed in writing before work begins. Defined projects are priced as a fixed fee, ongoing needs are covered by a monthly SIRI Shield retainer starting at ₹30,000 plus applicable taxes, and litigation is estimated stage by stage.
Call our emergency line, on any day at any hour. Avoid wiping or rebuilding affected systems so evidence is preserved. Under CERT-In's 2022 Directions, notification is due within six hours of noticing an incident, so the clock matters. An advocate and a forensic engineer join the same call, and we prepare the notification and preserve evidence in parallel.
For most mid-sized organisations a full DPDPA programme takes roughly six to twelve weeks from gap assessment to implementation. Because our legal and technical teams work in parallel instead of in sequence, timelines are shorter than when the two are handled by separate firms.
When penetration testing or forensics is commissioned through counsel, the resulting reports may be protected by legal privilege, subject to the facts and applicable law. A security firm engaged on its own cannot offer that. It also removes the translation gap between legal advice and technical reality.
Yes. We are based in Hyderabad with offices in Delhi NCR and Austin, Texas, and we work online worldwide. Where local representation is required in the United States or Canada, we coordinate with appropriately qualified local counsel.
Free first consultation
High level is fine. We check conflicts, tell you honestly whether we can help, and what it would cost. You decide, with no pressure.
A member of our team will be in touch within one working day. For anything urgent, call +91 79819 12046.
Visit us
HITEC City, Madhapur, Hyderabad, Telangana 500081
Mon to Sat, 9:30 AM to 7:00 PM IST · Meetings by appointment · Online consultations worldwide