Get started before you ship

Know what you need,
and when you need it

This is the founder-side setup guide for Indian SaaS and web apps. Use it to sequence your startup essentials, trust layer, compliance basics, and launch ops before you run the actual ShipSafe scan.

Skip ahead to scanWork through the checklist

Founder flow

1

Set up the company and launch stack

2

Publish trust basics before asking for money

3

Cover India-specific compliance and ops

4

Run ShipSafe as the final launch gate

0/20
Checklist progressAcross all launch-readiness tasks
0/14
Mandatory completeThe minimum trust and compliance layer
All items
Current filter0/20 complete in view

Checklist filter

Build the launch layer in the right order

Phase 1: Entity & Registrations

Decide what you legally are before you build. This choice drives your liability, your ability to raise money, and everything you will have to file later — and it is the hardest thing to change afterwards.

Choose your entity: Private Limited, LLP, or proprietorship

A Private Limited company is what investors expect and what lets you issue shares and ESOPs. An LLP is lighter to run but cannot take equity investment the same way. A sole proprietorship is fastest but gives you no liability separation at all.

Mandatory

When you need it

Before you raise money, sign a customer contract, or take on a co-founder.

Common mistake

Starting as a proprietorship to move fast, then having to restructure mid-fundraise — which costs legal fees, delays the round, and can trigger tax on the transfer of assets.

Incorporate with the MCA and get your CIN

Register through the MCA's SPICe+ process. You will need DIN for directors, a DSC for signing, name approval, and your MOA/AOA. This produces your Certificate of Incorporation and CIN.

Mandatory

When you need it

Before opening a bank account or onboarding to a payment gateway — both require incorporation documents.

Common mistake

Picking a company name that clashes with an existing trademark, getting name approval rejected, and losing days of runway on a re-filing.

Get PAN and TAN, then open a current account

PAN identifies the company for tax, TAN is required to deduct TDS on salaries and vendor payments, and a current account in the company's own name is what separates business money from your personal money.

Mandatory

When you need it

Immediately after incorporation, before your first payment in or out.

Common mistake

Running early revenue through a personal savings account. It breaks your books, complicates due diligence later, and can violate your bank's terms of use.

Check whether you must register for GST

GST registration is compulsory once you cross the turnover threshold for your state and supply type, and is compulsory from day one for some categories regardless of turnover — including inter-state supply and most e-commerce operators. Confirm your specific case on the GST portal.

Mandatory

When you need it

Before you invoice, since you cannot charge GST or claim input credit without a GSTIN.

Common mistake

Assuming the turnover threshold protects you when your category requires registration from the first rupee. Late registration means paying the tax you never collected out of your own margin.

Consider DPIIT Startup India recognition

Recognition through the Startup India portal unlocks self-certification on several labour and environment laws, easier public procurement, and access to tax benefits you must apply for separately.

Recommended

When you need it

Once incorporated, if you are within the eligibility window on age and turnover.

Common mistake

Never applying because it sounds bureaucratic, and paying full compliance overhead a recognised startup is exempt from.

Sign a founders' agreement and fix the cap table

Put equity splits, vesting, roles, IP assignment, and what happens if a founder leaves in writing. Assign all product IP to the company, not to individuals.

Mandatory

When you need it

Before you write significant code together, and definitely before any outside money.

Common mistake

Splitting equity on a handshake with no vesting. A co-founder who leaves in month four keeps their full stake, and that dead equity on your cap table is the single most common reason a seed round stalls.

File a trademark for your name and logo

Search the IP India register first, then file in the classes that match what you actually sell. This is what lets you stop someone else trading under your brand.

Recommended

When you need it

Before you spend on marketing the name.

Common mistake

Building brand equity on a name someone else has already registered, then being forced to rebrand after launch — losing your domain authority, app store reviews, and press coverage with it.

Phase 2: Product Foundation

Set up the technical building blocks you need before real customer traffic lands on your product.

Buy your domain and lock brand basics

Secure your main domain, your email domain, and the public name users will recognise. Match it to the entity and trademark you just filed.

Mandatory

When you need it

Before you share the product publicly or wire up email flows.

Common mistake

Launching on a platform subdomain, then changing every link and email address later — which resets your search ranking and breaks anything a customer bookmarked.

Choose your primary app stack

Decide where your frontend, backend, database, auth, and storage will run. If you will handle payment data, check the region now — RBI requires payment data to sit on servers in India.

Mandatory

When you need it

Before you write too much code or invite outside users.

Common mistake

Defaulting to a US region because it is the provider's default, then discovering the data-localisation problem during payment gateway onboarding.

Set up authentication and role boundaries

Pick how users sign in, and keep admin actions separated from user actions with an audit trail.

Recommended

When you need it

As soon as your app handles accounts, data, or paid features.

Common mistake

Shipping an admin panel behind nothing but an unguessable URL, so one leaked link exposes every customer record.

Phase 3: Money & Trust

Prepare the user-facing trust layer before you accept payments or ask customers for personal information.

Choose a payment setup you can operate

Pick a gateway and payment flow that matches your product, refund needs, and settlement expectations.

Mandatory

When you need it

Before collecting any money, subscriptions, or advance deposits.

Common mistake

Integrating payments before writing refund and cancellation terms. Razorpay and Cashfree both check for those pages at onboarding, so the merchant account stalls right when you wanted to launch.

Publish your privacy policy, terms, and refund policy

Create the policies customers, payment partners, and scanners expect to find.

Mandatory

When you need it

Before launch and definitely before onboarding real customers.

Common mistake

Pasting a template that describes data practices you do not actually follow. Under DPDP the notice must match reality, so a mismatched policy is worse than a plain one.

ShipSafe tie-in: The scan already checks for privacy, terms, and refund policy gaps.

Create a visible support channel

Publish a support email or contact route customers can use when something breaks.

Recommended

When you need it

Before your first public users and before enabling payments.

Common mistake

Launching with no visible support route, so your first angry customer escalates on Twitter instead of email.

ShipSafe tie-in: The scan can verify whether a contact path is discoverable on the site.

Phase 4: Compliance & Risk

Cover the India-specific trust and risk basics that become painful only after launch if ignored.

Map your DPDP obligations

Understand what personal data you collect, why you collect it, and what consent or notice you need.

Mandatory

When you need it

Before launch if you store user names, emails, phone numbers, payment-linked data, or contact submissions.

Common mistake

Assuming DPDP applies only to big companies. It applies from your first Indian user, and consent has to be collected correctly at signup — retrofitting it later means re-consenting your whole base.

ShipSafe tie-in: ShipSafe can later scan for consent and privacy signals on the live product.

Decide who handles grievances and compliance contact

Publish a responsible contact point for users, partners, and payment providers.

Mandatory

When you need it

Before onboarding to payment systems and before public launch.

Common mistake

Leaving the grievance contact undefined until a payment processor asks during onboarding, which holds up activation.

ShipSafe tie-in: The scan checks for grievance and security contact signals.

Write a minimal incident response plan

Document who responds when credentials leak, data is exposed, or service goes down.

Recommended

When you need it

Before launch, even if it is just a one-page founder playbook.

Common mistake

Having no runbook when it happens. CERT-In expects certain incidents reported within six hours of detection, and six hours is not enough time to also decide who is doing what.

Phase 5: Launch Readiness

Add the operational systems that let you notice, diagnose, and recover from failures once users arrive.

Set up monitoring, error tracking, and logs

Install uptime checks, error monitoring, and a place to inspect failures quickly.

Mandatory

When you need it

Before any public launch or beta with real users.

Common mistake

Learning about your first outage from a customer. You lose the trust and the diagnostic window at the same time.

ShipSafe tie-in: The scan already looks for analytics, uptime, and error tracking signals.

Prepare transactional email and deliverability basics

Set up your sender domain, auth records, and the emails needed for auth, receipts, or support.

Recommended

When you need it

Before onboarding flows, payment confirmations, or account actions depend on email.

Common mistake

Testing only from a sandbox sender, then finding every password-reset email lands in spam on launch day.

ShipSafe tie-in: The scan can remind you to confirm transactional email setup.

Enable backups and recovery checks

Make sure your database and critical files can be restored, not just backed up silently.

Mandatory

When you need it

Before launch if you store anything you cannot recreate manually.

Common mistake

Trusting that backups exist because the provider mentions them, and never once restoring one. An untested backup is a hope, not a backup.

ShipSafe tie-in: The scan flags missing backup readiness as a manual launch check.

Phase 6: Pre-Ship Check

Once the essentials are in place, use ShipSafe to validate the live product before you announce it widely.

Run a launch-readiness scan on the real app

Scan the deployed product so you catch DPDP, legal, SEO, security, and monitoring gaps in one pass.

Mandatory

When you need it

Right before launch, and again whenever the product changes materially.

Common mistake

Testing only on localhost. Security headers, consent banners, and policy pages behave differently on the real deployed domain.

Run the ship readiness scan→

Turn your setup work into a concrete readiness score before launch day.