Security
1. Reporting a vulnerability
If you have found a security issue in a Vagary Labs LLP product, please tell us. We would rather hear it from you than from an incident.
Email: [email protected]
Machine-readable: /.well-known/security.txt
Include: what you found, how to reproduce it, and what an attacker could do with it.
- We acknowledge within 48 hours.
- We give an initial assessment within 5 business days.
- We tell you when it is fixed, and we are happy to credit you unless you prefer otherwise.
2. Safe harbour
We will not pursue legal action against you for security research conducted in good faith under this policy: testing only against accounts you control, not accessing or modifying other people's data, not degrading the service, and giving us a reasonable chance to fix the issue before disclosing it publicly.
We do not currently run a paid bug-bounty programme. We say so plainly rather than leaving it ambiguous.
3. How we protect data
These are controls we actually operate, not aspirations.
| Area | What is in place |
|---|---|
| Encryption in transit | TLS on all public endpoints, with certificates issued and renewed automatically |
| Encryption at rest | Applied at the storage layer for backups and object storage |
| Secrets management | Credentials held in a dedicated secrets vault and injected at runtime — not in source control, not in images |
| Access control | Least-privilege access; administrative interfaces sit behind an identity-aware proxy and a private network rather than the public internet |
| Network isolation | Internal services reachable only over a private mesh network; a single reviewed reverse proxy fronts public traffic |
| Monitoring | Metrics, logs and traces collected centrally, with 24×7 automated alerting on infrastructure and application faults |
| Vulnerability management | Automated dependency updates, container image scanning, and secret-scanning in the commit path |
| Backups | Automated encrypted backups to more than one independent provider, with restore procedures documented |
| Multi-factor authentication | Enforced on administrative and vendor accounts |
4. Incident response
We maintain documented recovery procedures and alerting that pages a human. Where an incident affects personal data, we notify affected people and the relevant regulator within the periods the applicable law requires — which for the GDPR means notifying the supervisory authority within 72 hours of becoming aware, and for India's CERT-In directions means reporting a covered cyber incident within 6 hours.
5. Where data is processed
Our infrastructure runs on virtual private servers we administer, supported by the third-party services listed on our Subprocessors page. International transfers, and the safeguards applied to them, are described in our Privacy Policy.
6. Certifications — stated honestly
We do not currently hold SOC 2 or ISO 27001 certification. We would rather say that than imply a certification we do not have. The controls above are real and operating; they have not been audited by an independent assessor. If you need a certified vendor today, that is a legitimate reason to choose one, and we will tell you so rather than talk you around it.
Enterprise customers who need a security review, a data-processing agreement or a completed questionnaire can request one at [email protected].
7. Service status
Availability is published at status.vagarylabs.com.