Skip to main content

Trust centre

Financial data deserves bank-grade protection

Everything below is contractual, audited, and verifiable — not marketing. Your security team can hold us to each line.

01

SOC 2 Type II

Controls across security, availability, and confidentiality — independently audited every year. Reports available under NDA.

02

ISO 27001

A certified information-security management system governing how we build, operate, and improve the platform.

03

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, HSM-backed key storage with scheduled rotation. No plaintext financial data, anywhere.

04

Identity & access

SAML/OIDC SSO, SCIM provisioning, enforced MFA, device binding on mobile, and step-up authentication for sensitive actions.

05

Granular RBAC

Role- and attribute-based access to field level, scoped per legal entity — satisfying segregation-of-duties requirements out of the box.

06

Immutable audit logs

Every read and write is logged, tamper-evident, retained per your policy, and streamable to Splunk, Sentinel, or any syslog endpoint.

07

Backups & recovery

Continuous encrypted backups with cross-zone replication. RPO under 15 minutes, RTO under 4 hours, restore drills quarterly.

08

Data residency

Choose India, EU, US, or Singapore at onboarding. Data — including backups — never leaves your selected region.

09

Secure development

Peer-reviewed changes, dependency scanning, static analysis in CI, and quarterly independent penetration tests with published remediation SLAs.

10

Vendor governance

Sub-processors are risk-assessed, contractually bound, and published. Changes are notified in advance with objection rights.

11

Incident response

24/7 monitoring with a tested response runbook. Contractual notification timelines and transparent post-incident reports.

12

Privacy compliance

GDPR and India DPDP-aligned processing terms, data minimisation, configurable retention, and deletion workflows with certificates.

Enterprise assurance package

Available to evaluating enterprises under NDA: SOC 2 Type II report, ISO 27001 certificate, latest penetration-test summary, security whitepaper, sub-processor list, DPA with SCCs, and completed CAIQ/SIG questionnaires.

Request via the contact form — our security team responds within two business days.

FAQ

Questions finance leaders ask us

Straight answers — the same ones we give in evaluations.

Where is our data hosted?
You choose the region at onboarding: India (Mumbai), EU (Frankfurt), US (Virginia), or Singapore. Data — including backups — never leaves the selected region.
Which compliance certifications does MyVyay hold?
SOC 2 Type II and ISO 27001, with GDPR and India DPDP-aligned data-processing terms. Reports and the latest penetration-test summary are available under NDA.
How does MyVyay handle vulnerabilities?
Continuous dependency scanning, quarterly independent penetration tests, a private bug-bounty programme, and a published SLA for remediation by severity.
Can we bring our own SSO and SIEM?
Yes. SAML and OIDC SSO with SCIM provisioning is standard on enterprise plans, and audit-log streaming to Splunk, Sentinel, or any syslog endpoint is supported.

Get started

Your close doesn't have to be a crunch.

See MyVyay run against your policies, your ERP, and your document types — in a 30-minute working session.

2–4 week implementation · No lock-in · Priced per active user