Verified scope
This statement covers the public Vayreach website. Configuration is supplied through environment variables rather than committed secrets, input is validated before submission, and credentials are never written to browser storage. The site is served over HTTPS.
Controls requiring production verification
Authentication, tenant isolation, staff access, encryption at rest, backups, webhook signatures, audit logs, dependency patching, rate limiting, incident playbooks, deletion jobs and recovery testing are not evidenced as complete. No certification, penetration test or 24×7 monitoring claim is made.
Incident obligations
Vayqube should maintain an incident point of contact, preserve applicable security logs, assess reportable events and follow applicable CERT-In and data-protection notification requirements as they apply. Public copy does not expose security-sensitive implementation details.
Vulnerability reporting
Report a suspected vulnerability privately with affected URL, impact and reproducible steps. Do not access other people’s data, disrupt service, use social engineering or publish sensitive details before a reasonable remediation opportunity.
Contact
Vayqube Technologies Private Limited, T3b 604-606, Nx-one Techzone-4, Greater Noida, Gautam Buddha Nagar, Gautam Budh Nagar 201318, India. Email: support@vayreach.com. Phone: +91 8796955128.