Trust Center
Everything a customer, partner or reviewer needs to assess Vagary Labs LLP in one place: our legal documents, who processes data on our behalf, how to report a vulnerability, and — first, because it is the question that matters most — what we are not certified for.
1. Certifications — the honest position
We do not hold SOC 2. We do not hold ISO 27001. No independent auditor or assessor has examined our infrastructure, and we have never commissioned a penetration test.
We state that first rather than in a footnote. A trust page that leads with controls and buries the absence of an audit is doing something other than building trust.
What we do have is a control set that is real and operating, and an internal assessment that is candid about which parts of it are mature and which are merely young. The distinction matters: a control documented last month and a control with a year of evidence behind it are not the same thing, and only the second survives an audit.
If you need a certified vendor today, that is a legitimate reason to choose one, and we will tell you so rather than talk you around it.
2. Our control inventory (CAIQ)
We maintain a self-assessment against the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ v4) — 197 controls across 17 domains, covering application security, cryptography and key management, identity and access, logging, incident response, supply chain, and endpoint management.
Two things about it, said plainly:
- It is a Level 1 self-assessment. We answered it ourselves. CSA's own model reserves Level 2 for third-party audit, and we are not there.
- It records what is not implemented as not implemented. Controls we do not operate are answered "No", not softened into "partially" or "planned". Roughly a fifth of the questionnaire is answered "No", and those answers are the most useful part of the document.
The completed assessment is available on request — email [email protected] and we will send it, along with a data-processing agreement or a completed copy of your own security questionnaire. Most enterprise questionnaires are a subset of CAIQ, so in practice this answers them.
3. Security
How we protect data — encryption, access control, network isolation, monitoring, vulnerability management, backups and multi-factor authentication — is set out on our Security page, along with our incident-response commitments and where data is processed. We describe controls we actually operate there, not aspirations.
To report a vulnerability: [email protected], or the machine-readable security.txt. We acknowledge within 48 hours and give an initial assessment within 5 business days. Good-faith research under our published policy will not be met with legal action. There is no paid bounty programme, and we say so rather than leave it ambiguous.
4. Subprocessors and data handling
The third parties that process data on our behalf are listed on our Subprocessors page. That list is not maintained by hand — it is derived from our source code by an automated check that fails our build if a service can reach a provider we have not disclosed. A disclosure list that depends on someone remembering to update it is a disclosure list that will eventually be wrong.
How we collect, use, retain and delete personal data is in our Privacy Policy; how to request erasure is in Data deletion; what we store in your browser and why nothing non-essential loads before you opt in is in our Cookie policy.
5. Documents
| Document | What it covers |
|---|---|
| Privacy Policy | What personal data we process, why, on what legal basis, and your rights |
| Terms of Service | The contract governing use of our products |
| Acceptable Use Policy | What may not be done with our services |
| Cookie Policy | Browser storage, consent, and the tags that load only after opt-in |
| Data Deletion | How to request erasure of your data |
| Subprocessors | Third parties processing data on our behalf |
| Security | Controls we operate, vulnerability reporting, incident response |
| security.txt | RFC 9116 machine-readable security contact |
| Refund & Cancellation | Refund eligibility and how to cancel |
| Delivery | How and when services are delivered |
| Accessibility | Our accessibility commitment and how to report a barrier |
| Disclaimer | Limits on the information we publish |
| Grievance Officer | Statutory grievance contact and escalation timelines |
| Contact | How to reach us |
6. Service status
Live availability is published at status.vagarylabs.com. Our infrastructure runs on virtual private servers we administer directly, supported by the third-party services named on the Subprocessors page.
7. Enterprise review
For a security review, a data-processing agreement, a completed security questionnaire, or the CAIQ self-assessment, contact [email protected]. Tell us what your review process needs and we will tell you honestly whether we can meet it.
Our statutory grievance contact is Chinmay Ramraika — [email protected].