Trust & Security

What you're exposed to when you work with us.

Procurement and IT teams ask these questions. Here are the honest answers, before the contract. Looking for how Aagman handles visitor data specifically? That lives on the Aagman site.

Your data during a build

We work from the smallest slice of real data that will do the job, and prefer anonymised or synthetic data wherever it does. Production access is read-only until there is a written reason for anything more. Nothing is copied to a personal machine or a third-party tool without you agreeing to it first.

Code and IP ownership

Ownership of what we build for you is settled in writing before work starts, including which components are pre-existing, which are new, and what you are licensed to keep using. We do not reuse client-specific code on another engagement.

Access and offboarding

Access is requested per system, per person, and named. At the end of an engagement, credentials are revoked, working copies are removed, and we confirm the offboarding in writing rather than leaving it assumed.

Confidentiality and publication

We sign your NDA. Nothing about your engagement appears on this site, in a proposal or on social without your written permission, which is why several projects on our work page carry no client name and one carries no images at all.

Where things run

Hosting region and data residency are agreed per project, not assumed. On-premises and private-cloud deployment is available where the workload or your policy requires it. Any third-party service in the path is named before it is introduced.

Certifications

We follow industry-standard practices for data handling. We do not hold SOC 2 Type II or ISO 27001, and we do not claim them. If a certification is a hard requirement for your procurement process, tell us early so nobody wastes a cycle.

Incident response

Security issues should be reported to security@kaizenlabs.co.in. We acknowledge within 1 business day and target a fix or a written status within 5 business days, depending on severity.

Need a deeper review for procurement?

We can walk through DPA language, data-flow diagrams, IP and licensing terms, and reference checks for IT and security teams.