Skip to main content

Capability · Platform

Security & Trust

Enterprise-grade security, verified by independent audit.

SOC 2 Type II and ISO 27001 aligned controls, encryption everywhere, granular RBAC, immutable audit logs, and data residency options across regions.

Quick answer

MyVyay is built on SOC 2 Type II and ISO 27001-aligned controls with AES-256 encryption at rest, TLS 1.3 in transit, SSO/SCIM, granular RBAC, immutable audit logs, and regional data residency.

Security & Trust

99.95%
uptime SLA
24/7
security monitoring
4
data-residency regions

Capabilities

What Security & Trust does for you

Independent audits

SOC 2 Type II reports and ISO 27001 certification, refreshed annually.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, with key rotation and HSM-backed storage.

SSO, SCIM & MFA

SAML/OIDC single sign-on, automated user lifecycle, enforced MFA.

Granular RBAC

Role- and attribute-based access down to field level, entity-scoped.

Immutable audit logs

Every read and write logged, tamper-evident, exportable to your SIEM.

Data residency

Regional hosting in India, the EU, the US, and Singapore with no cross-region drift.

Process

How it works, step by step

01

Authenticate

SSO with enforced MFA and device policies via your IdP.

02

Authorise

RBAC scopes every action to role, entity, and data sensitivity.

03

Protect

Data is encrypted, residency-pinned, and continuously monitored.

04

Prove

Audit logs, reports, and certifications support every assurance ask.

Key takeaways

  • Security posture is independently audited, not self-attested.
  • Access control reaches field level, satisfying segregation-of-duties requirements.
  • Audit logs are immutable and SIEM-ready for your security operations.
  • Data residency options meet Indian, EU, and sector-specific mandates.

FAQ

Security & Trust — frequently asked

Answers our solutions team gives in real evaluations.

Where is our data hosted?
You choose the region at onboarding: India (Mumbai), EU (Frankfurt), US (Virginia), or Singapore. Data — including backups — never leaves the selected region.
Which compliance certifications does MyVyay hold?
SOC 2 Type II and ISO 27001, with GDPR and India DPDP-aligned data-processing terms. Reports and the latest penetration-test summary are available under NDA.
How does MyVyay handle vulnerabilities?
Continuous dependency scanning, quarterly independent penetration tests, a private bug-bounty programme, and a published SLA for remediation by severity.
Can we bring our own SSO and SIEM?
Yes. SAML and OIDC SSO with SCIM provisioning is standard on enterprise plans, and audit-log streaming to Splunk, Sentinel, or any syslog endpoint is supported.

Get started

Your close doesn't have to be a crunch.

See MyVyay run against your policies, your ERP, and your document types — in a 30-minute working session.

2–4 week implementation · No lock-in · Priced per active user