Vagary Labs Incorporated 2026 · Madhya Pradesh, India

Security

Vagary Labs LLP · Effective Date: 2026-07-29 · Version v2.0

1. Reporting a vulnerability

If you have found a security issue in a Vagary Labs LLP product, please tell us. We would rather hear it from you than from an incident.

Email: [email protected]
Machine-readable: /.well-known/security.txt
Include: what you found, how to reproduce it, and what an attacker could do with it.

2. Safe harbour

We will not pursue legal action against you for security research conducted in good faith under this policy: testing only against accounts you control, not accessing or modifying other people's data, not degrading the service, and giving us a reasonable chance to fix the issue before disclosing it publicly.

We do not currently run a paid bug-bounty programme. We say so plainly rather than leaving it ambiguous.

3. How we protect data

These are controls we actually operate, not aspirations.

AreaWhat is in place
Encryption in transitTLS on all public endpoints, with certificates issued and renewed automatically
Encryption at restApplied at the storage layer for backups and object storage
Secrets managementCredentials held in a dedicated secrets vault and injected at runtime — not in source control, not in images
Access controlLeast-privilege access; administrative interfaces sit behind an identity-aware proxy and a private network rather than the public internet
Network isolationInternal services reachable only over a private mesh network; a single reviewed reverse proxy fronts public traffic
MonitoringMetrics, logs and traces collected centrally, with 24×7 automated alerting on infrastructure and application faults
Vulnerability managementAutomated dependency updates, container image scanning, and secret-scanning in the commit path
BackupsAutomated encrypted backups to more than one independent provider, with restore procedures documented
Multi-factor authenticationEnforced on administrative and vendor accounts

4. Incident response

We maintain documented recovery procedures and alerting that pages a human. Where an incident affects personal data, we notify affected people and the relevant regulator within the periods the applicable law requires — which for the GDPR means notifying the supervisory authority within 72 hours of becoming aware, and for India's CERT-In directions means reporting a covered cyber incident within 6 hours.

5. Where data is processed

Our infrastructure runs on virtual private servers we administer, supported by the third-party services listed on our Subprocessors page. International transfers, and the safeguards applied to them, are described in our Privacy Policy.

6. Certifications — stated honestly

We do not currently hold SOC 2 or ISO 27001 certification. We would rather say that than imply a certification we do not have. The controls above are real and operating; they have not been audited by an independent assessor. If you need a certified vendor today, that is a legitimate reason to choose one, and we will tell you so rather than talk you around it.

Enterprise customers who need a security review, a data-processing agreement or a completed questionnaire can request one at [email protected].

7. Service status

Availability is published at status.vagarylabs.com.