maaya.works
Legal

Security

How maaya.works protects your data — India hosting, encryption, least-privilege access, an append-only audit trail, and approval-gated AI.

Last updated: June 2026

Hosting and data residency

The service runs on Amazon Web Services in the ap-south-1 (India) region. Your business records stay in India in the normal course of providing the service.

Encryption

Data is encrypted in transit using TLS and encrypted at rest. Access to production systems is restricted and monitored.

Access control

We follow least-privilege access: people and services get only the access they need, separated by role. Administrative access is limited, logged, and reviewed.

Audit trail and approvals

Every AI action is logged, and the record is append-only — entries are corrected by reversing entries, never silently overwritten. Nothing an AI-hire proposes becomes final without human approval, so the books cannot be changed behind your back.

Resilience

We take regular backups and design for recovery so your data is durable and available.

Certifications

We build to recognised security practices and are working toward formal certification. We will publish certifications here as they are earned — we do not claim what we have not yet achieved.

Reporting a vulnerability

If you believe you have found a security issue, please email security@maaya.works. We welcome responsible disclosure and will work with you to confirm and address valid reports.