Security
How maaya.works protects your data — India hosting, encryption, least-privilege access, an append-only audit trail, and approval-gated AI.
Last updated: June 2026
Hosting and data residency
The service runs on Amazon Web Services in the ap-south-1 (India) region. Your business records stay in India in the normal course of providing the service.
Encryption
Data is encrypted in transit using TLS and encrypted at rest. Access to production systems is restricted and monitored.
Access control
We follow least-privilege access: people and services get only the access they need, separated by role. Administrative access is limited, logged, and reviewed.
Audit trail and approvals
Every AI action is logged, and the record is append-only — entries are corrected by reversing entries, never silently overwritten. Nothing an AI-hire proposes becomes final without human approval, so the books cannot be changed behind your back.
Resilience
We take regular backups and design for recovery so your data is durable and available.
Certifications
We build to recognised security practices and are working toward formal certification. We will publish certifications here as they are earned — we do not claim what we have not yet achieved.
Reporting a vulnerability
If you believe you have found a security issue, please email security@maaya.works. We welcome responsible disclosure and will work with you to confirm and address valid reports.