Skip to content

, Trust

Security

How we run our own systems, how we handle client data, and how to report something you have found.

Last updated · 7 August 2026

Reporting a vulnerability

If you believe you have found a security issue in our website, infrastructure or published software, email [email protected] with enough detail to reproduce it.

  • We acknowledge every report within two working days.
  • We aim to provide an initial assessment within five working days and to agree a remediation timeline with you.
  • We will credit you publicly when the issue is resolved, unless you prefer otherwise.
  • We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to fix an issue before disclosing it.

We do not currently operate a paid bug bounty. We would rather say so plainly than imply one exists.

How we operate

Access. Multi-factor authentication is mandatory on every company account. Access follows least privilege and is reviewed quarterly. Production credentials are held in a managed secret store and never in source control.

Code. All changes go through review and automated checks before merge. Dependencies are scanned continuously, and we maintain a patching window for critical advisories.

Infrastructure. This website is a static build served from a content delivery network, with no server-side application and no database. There is very little to attack here by design.

Devices. Company endpoints use full-disk encryption, automatic screen lock and managed OS updates.

Client data

Where an engagement involves client data, the terms of that engagement take precedence over this page. Our defaults, which we will confirm in writing:

  • We do not use client data to train models, to build products, or for any purpose outside the engagement.
  • We do not send client data to third-party model providers without explicit written approval of the specific provider and configuration.
  • Where practical we work inside the client’s own environment rather than copying data into ours.
  • Data is deleted or returned at the end of an engagement, on a schedule agreed in the contract.
  • Nothing derived from a client corpus appears in a public repository, benchmark, dataset or research note, in any form.

AI-specific practices

Systems we build ship with an evaluation suite that includes adversarial and abuse cases, not only accuracy cases. Prompt-injection resistance, data-exfiltration paths through tool use, and behaviour under out-of-distribution input are treated as security properties and tested as such rather than left to the model provider.

Certifications

Rudvanth does not currently hold ISO 27001 or SOC 2 attestation. We are early in that process and we will not imply otherwise. Where an engagement requires a formal control framework, we are happy to work within the client’s and to complete their vendor security assessment.

Template notice

This document is a good-faith starting point drafted for a small Indian technology company. It is not legal advice. Before relying on it commercially, and certainly before signing an enterprise agreement or processing personal data at scale, have it reviewed by a qualified lawyer against the Digital Personal Data Protection Act, 2023 and any sector rules that apply to your customers.