> legal.security
Security
Last updated · July 2026
Security is not a feature at Vyaahar — it's a prerequisite. Books, ledgers, and bank data are the most sensitive things a business owns. Here is how we treat yours.
At a glance:TLS 1.2+ · AES-256 encryption at rest · SOC 2 Type II — in progress
Encryption
- All traffic to Vyaahar is TLS 1.2+ end-to-end.
- Data at rest is encrypted with industry-standard AES-256.
- Passwords are hashed with bcrypt; we never see the plaintext.
Access controls
- Role-based access within each organisation — owner, admin, accountant, viewer.
- All authenticated actions are audit-logged.
- Two-factor authentication is on the roadmap for all paid tiers.
Infrastructure
- Hosted on vetted cloud providers with SOC 2 / ISO 27001 attestations.
- Databases are backed up daily with point-in-time recovery.
- Environments are isolated — no shared credentials between dev, staging, and production.
Compliance roadmap
We are honest about where we stand. SOC 2 Type II certification is currently in progress. We do not claim certifications we do not hold, and we'll update this page the moment our status changes.
Your data is never training data
We do not share your ledger, invoices, or bank data with any third-party model provider for training. The AI Copilot queries your books at run-time; we do not batch-export your data anywhere.
Responsible disclosure
Found a security issue? Please email hello@scitus.ai with the subject line "Security report". We commit to acknowledging within two business days.