Skip to content
Vagary LabsVagary Labs LLP
HomeProductsPricingPlatformDocsOSSBlogRead the docs
Company / Trust Center

Trust Center

Vagary Labs LLP · Effective Date: 2026-07-29 · Version v2.0

Everything a customer, partner or reviewer needs to assess Vagary Labs LLP in one place: our legal documents, who processes data on our behalf, how to report a vulnerability, and — first, because it is the question that matters most — what we are not certified for.

1. Certifications — the honest position

We do not hold SOC 2. We do not hold ISO 27001. No independent auditor or assessor has examined our infrastructure, and we have never commissioned a penetration test.

We state that first rather than in a footnote. A trust page that leads with controls and buries the absence of an audit is doing something other than building trust.

What we do have is a control set that is real and operating, and an internal assessment that is candid about which parts of it are mature and which are merely young. The distinction matters: a control documented last month and a control with a year of evidence behind it are not the same thing, and only the second survives an audit.

If you need a certified vendor today, that is a legitimate reason to choose one, and we will tell you so rather than talk you around it.

2. Our control inventory (CAIQ)

We maintain a self-assessment against the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ v4) — 197 controls across 17 domains, covering application security, cryptography and key management, identity and access, logging, incident response, supply chain, and endpoint management.

Two things about it, said plainly:

  • It is a Level 1 self-assessment. We answered it ourselves. CSA's own model reserves Level 2 for third-party audit, and we are not there.
  • It records what is not implemented as not implemented. Controls we do not operate are answered "No", not softened into "partially" or "planned". Roughly a fifth of the questionnaire is answered "No", and those answers are the most useful part of the document.

The completed assessment is available on request — email [email protected] and we will send it, along with a data-processing agreement or a completed copy of your own security questionnaire. Most enterprise questionnaires are a subset of CAIQ, so in practice this answers them.

3. Security

How we protect data — encryption, access control, network isolation, monitoring, vulnerability management, backups and multi-factor authentication — is set out on our Security page, along with our incident-response commitments and where data is processed. We describe controls we actually operate there, not aspirations.

To report a vulnerability: [email protected], or the machine-readable security.txt. We acknowledge within 48 hours and give an initial assessment within 5 business days. Good-faith research under our published policy will not be met with legal action. There is no paid bounty programme, and we say so rather than leave it ambiguous.

4. Subprocessors and data handling

The third parties that process data on our behalf are listed on our Subprocessors page. That list is not maintained by hand — it is derived from our source code by an automated check that fails our build if a service can reach a provider we have not disclosed. A disclosure list that depends on someone remembering to update it is a disclosure list that will eventually be wrong.

How we collect, use, retain and delete personal data is in our Privacy Policy; how to request erasure is in Data deletion; what we store in your browser and why nothing non-essential loads before you opt in is in our Cookie policy.

5. Documents

DocumentWhat it covers
Privacy PolicyWhat personal data we process, why, on what legal basis, and your rights
Terms of ServiceThe contract governing use of our products
Acceptable Use PolicyWhat may not be done with our services
Cookie PolicyBrowser storage, consent, and the tags that load only after opt-in
Data DeletionHow to request erasure of your data
SubprocessorsThird parties processing data on our behalf
SecurityControls we operate, vulnerability reporting, incident response
security.txtRFC 9116 machine-readable security contact
Refund & CancellationRefund eligibility and how to cancel
DeliveryHow and when services are delivered
AccessibilityOur accessibility commitment and how to report a barrier
DisclaimerLimits on the information we publish
Grievance OfficerStatutory grievance contact and escalation timelines
ContactHow to reach us

6. Service status

Live availability is published at status.vagarylabs.com. Our infrastructure runs on virtual private servers we administer directly, supported by the third-party services named on the Subprocessors page.

7. Enterprise review

For a security review, a data-processing agreement, a completed security questionnaire, or the CAIQ self-assessment, contact [email protected]. Tell us what your review process needs and we will tell you honestly whether we can meet it.

Our statutory grievance contact is Chinmay Ramraika — [email protected].

Vagary Labs LLP · LLPIN ADA-4675 · Registered with limited liability

The company site of Vagary Labs LLP. The entity record and its legal policies are published on this site.

Site

  • Platform
  • Docs
  • Open source
  • Notes

Company

  • Company
  • Contact
  • The plan
  • Trust Center
  • Privacy
  • Terms
  • Grievance officer

Engineering

  • Fleet console
  • vagary-core plan
  • Topology
  • Fleet status
  • Changelog
© 2026 Vagary Labs LLP. All rights reserved. Trademark: application pending