Trust

Security practices.

Last updated September 4, 2026

We are a small studio, not an enterprise security organisation, and this page says exactly what we do rather than implying certifications we do not hold. If your procurement process needs something specific, ask — we would rather answer honestly than fail an audit later.

Access

  • Multi-factor authentication is required on every account that can reach client material or production systems.
  • Access is granted per project, to the people working on it, and removed when the engagement ends.
  • Credentials you share with us are stored in a password manager, never in a document, a message or a repository.
  • We ask you to revoke our access at handover, and we will remind you if you do not.

Data in transit and at rest

Everything we run is served over TLS. Managed databases and object storage used by our products are encrypted at rest by the provider. Workstations that hold client material use full-disk encryption.

Software we build

  • Secrets live in environment variables and a secret manager, never in source control.
  • Dependencies are pinned and updated; security advisories on the stacks we ship are monitored.
  • Authorisation is enforced on the server. Where a view is read-only for a client, that is enforced by the API, not hidden in the interface.
  • Payment card data never touches our systems — our products use Paddle as merchant of record.

Vendors

We keep the vendor list short and prefer providers with their own published security posture: Vercel for hosting, Neon for databases, Vercel Blob for file storage, Resend for email, Paddle for payments. Each is covered by a data processing agreement. The current list is in our privacy policy.

Retention and deletion

Project material is archived for 12 months after delivery so we can support what we shipped, then deleted. If you want it deleted sooner, or returned, email us and we will do it and confirm in writing.

Reporting a vulnerability

If you believe you have found a security issue in anything we run, email security@ayuvam.com with enough detail to reproduce it. We will acknowledge within three working days and keep you updated until it is resolved.

Please give us reasonable time to fix an issue before disclosing it publicly, do not access or modify data that is not yours, and do not run denial-of-service or automated scanning against production. We will not pursue legal action against researchers who follow that.

If something goes wrong

If a breach affects your data we will tell you without undue delay and within 72 hours of becoming aware, describe what happened and what we are doing, and support any notification you are required to make.