Trust centre
Financial data deserves bank-grade protection
Everything below is contractual, audited, and verifiable — not marketing. Your security team can hold us to each line.
SOC 2 Type II
Controls across security, availability, and confidentiality — independently audited every year. Reports available under NDA.
ISO 27001
A certified information-security management system governing how we build, operate, and improve the platform.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit, HSM-backed key storage with scheduled rotation. No plaintext financial data, anywhere.
Identity & access
SAML/OIDC SSO, SCIM provisioning, enforced MFA, device binding on mobile, and step-up authentication for sensitive actions.
Granular RBAC
Role- and attribute-based access to field level, scoped per legal entity — satisfying segregation-of-duties requirements out of the box.
Immutable audit logs
Every read and write is logged, tamper-evident, retained per your policy, and streamable to Splunk, Sentinel, or any syslog endpoint.
Backups & recovery
Continuous encrypted backups with cross-zone replication. RPO under 15 minutes, RTO under 4 hours, restore drills quarterly.
Data residency
Choose India, EU, US, or Singapore at onboarding. Data — including backups — never leaves your selected region.
Secure development
Peer-reviewed changes, dependency scanning, static analysis in CI, and quarterly independent penetration tests with published remediation SLAs.
Vendor governance
Sub-processors are risk-assessed, contractually bound, and published. Changes are notified in advance with objection rights.
Incident response
24/7 monitoring with a tested response runbook. Contractual notification timelines and transparent post-incident reports.
Privacy compliance
GDPR and India DPDP-aligned processing terms, data minimisation, configurable retention, and deletion workflows with certificates.
Enterprise assurance package
Available to evaluating enterprises under NDA: SOC 2 Type II report, ISO 27001 certificate, latest penetration-test summary, security whitepaper, sub-processor list, DPA with SCCs, and completed CAIQ/SIG questionnaires.
Request via the contact form — our security team responds within two business days.
FAQ
Questions finance leaders ask us
Straight answers — the same ones we give in evaluations.
Where is our data hosted?
Which compliance certifications does MyVyay hold?
How does MyVyay handle vulnerabilities?
Can we bring our own SSO and SIEM?
Get started
Your close doesn't have to be a crunch.
See MyVyay run against your policies, your ERP, and your document types — in a 30-minute working session.
2–4 week implementation · No lock-in · Priced per active user