Loading
Loading
Our ISO 27001-aligned security program, the controls behind every engagement, and how to disclose vulnerabilities responsibly.
Last updated · May 2026
Security is a precondition of every system we ship. Aayulogic operates an ISO 27001-certified Information Security Management System (ISMS) and aligns its engineering, infrastructure, and operational practices with SOC 2 Trust Services Criteria. This page summarizes the controls that protect customer data and our platforms.
Our security program is independently audited and built on widely adopted frameworks.
Production workloads run on hardened AWS, Azure, and GCP environments operated by Aayulogic. We treat infrastructure as code and apply defense in depth.
Security is embedded in our SDLC — designed in, not bolted on.
Access to production systems is gated on the principle of least privilege.
We instrument every system we operate. Structured logs, metrics, and traces feed into a 24x7 monitoring stack with on-call rotations.
Our incident response playbooks define severity, escalation, communication, and post-incident review obligations. Customers affected by material incidents are notified in accordance with contractual and regulatory commitments.
Mission-critical services run with multi-zone redundancy. We maintain documented backup, restore, and disaster-recovery procedures with regular tests of recovery time and recovery point objectives.
All Aayulogic engineers undergo background checks proportionate to their role, complete annual security awareness training, and sign confidentiality agreements at onboarding.
We welcome reports from independent researchers. If you believe you have found a security vulnerability in any Aayulogic system, please email us at [email protected] with technical detail and reproduction steps.
Please do not perform testing that could disrupt production systems, expose customer data, or violate privacy. We will acknowledge your report within two business days and work in good faith to triage and remediate.
For security questionnaires, audit support, customer due diligence, or to report a vulnerability, contact our security team directly. We typically respond within one business day.