FlowstateLLP
04Market served

Software development for US businesses

Delivered from India. State privacy law, SOC 2 readiness and HIPAA handled as build constraints — with a frank account of the overlap.

The time difference with the US is the real constraint and we will not soften it. India is 9.5 to 12.5 hours ahead depending on coast and season, which means the overlap is early US morning against late India evening. We hold a fixed daily window there, keep decisions asynchronous and well documented, and are candid that this suits teams comfortable working from written updates rather than constant live conversation.

In exchange, the US compliance surface is one we work in constantly: a growing patchwork of state privacy laws, SOC 2 as a de facto requirement for selling to enterprises, and HIPAA where healthcare data is involved.

What is different here

The constraints that
change the build.

  • 01

    State privacy laws

    CCPA and CPRA in California plus a widening set of state regimes, with differing definitions and consumer rights. We design one consent, retention and deletion model that satisfies the strictest applicable rather than a patchwork per state.

  • 02

    SOC 2 readiness

    If you sell to US enterprises, SOC 2 will be asked for. We build the underlying controls — access management, audit logging, change control, encryption — so your audit becomes a documentation exercise rather than an engineering project.

  • 03

    HIPAA where relevant

    Where protected health information is involved we architect to minimise how much of it exists, sign a Business Associate Agreement, and design access control and audit logging to the standard.

  • 04

    Asynchronous delivery discipline

    Written decision records, recorded demos, and a documented daily handoff. This is a working practice we have had to be good at, and it is the difference between the offset being manageable and being painful.

  • 05

    Contracting and IP

    US-style master services agreements with statements of work, IP assigned on payment, and mutual NDAs. We work with your counsel's paper rather than insisting on ours.

Sectors

Who buys
software here.

  • B2B SaaS and technology
  • Logistics and freight brokerage
  • Healthcare technology
  • Financial services and insurance
  • Manufacturing and distribution
  • Construction technology
Questions

Practicalities.

How do you handle the time difference honestly?

A fixed daily overlap in the early US morning, and strong asynchronous discipline for everything else: written decision records, recorded demos, a daily handoff note. It works well for teams comfortable with written communication and less well for teams that prefer to resolve things in ad-hoc calls.

Can you help us get SOC 2 ready?

Yes, as a consulting engagement alongside or independent of a build. We are not certified ourselves and say so plainly on our security page — what we do is build and document the control set your auditor will assess.

Will you sign a BAA for healthcare work?

Yes, where an engagement involves protected health information. We also architect to minimise how much PHI our systems and our team ever touch, which is the more useful risk reduction.

Next step

Tell us what you are building.

A short conversation is usually enough to tell whether we are the right firm for the problem. If we are not, we will say so and point you somewhere better.