Trust

Security & Data Stewardship

How a small, senior engineering firm keeps client data safe: deployments run in your infrastructure, our access is scoped and contracted, and EU data stays in the EU. Security by architecture, documented and auditable.

The short version

Production deployments run on your infrastructure, under your custody and administrative control. Our access is named, scoped and revocable by you. For European clients, EU personal data is processed in the EU — and our self-hosted AI architecture means audio, text and video never transit a third-party AI provider at all.

The sovereignty operating model

The single most important fact about working with Vaagmodo: production deployments run in the client's infrastructure, not ours.

  • Your servers, your custody. The platforms and AI stacks we build are deployed on infrastructure the client owns or contracts directly — your data center, your cloud account, your dedicated GPU servers. Production data lives and is processed there, under your custody and your jurisdiction's law.
  • You keep administrative control. Root ownership, account control and the power to revoke access rest with the client. We do not hold your data on Vaagmodo-controlled systems.
  • Our access is scoped support access. Vaagmodo engineers work through named, individual accounts granted under the engagement contract — scoped to what the work requires, revocable by you at any time, and used for engineering and operations, not for data consumption. Where the client's policy requires it, access is time-bounded, logged and auditable on the client's side.
  • EU processing stays in the EU. For European clients, personal data is processed on EU-located infrastructure under the client's control. Our self-hosted AI architecture exists precisely so that audio, text and video never transit third-party AI APIs — and never need to leave your environment at all.

"You're an Indian company — how can our EU data be safe with you?"

Every data-protection officer asks this, and deserves a direct answer.

Vaagmodo is an Indian company. Under the operating model above, that matters less than it first appears: client data never reaches Vaagmodo-controlled infrastructure. Processing happens in the client's EU environment; what crosses borders is not a copy of your data but scoped remote access by named engineers — the same question posed by any remote administrator, wherever they sit, and one GDPR has an established toolbox for.

Concretely, for EU engagements we support:

  • Data processing agreements (DPAs) under Art. 28 GDPR, with Standard Contractual Clauses (SCCs) where our remote support access constitutes a third-country transfer.
  • Access minimization by design: production personal data is not needed for most engineering work; where support access to production systems is required, it is scoped, individual and revocable as described above.
  • Client-side controls: we work within your bastion hosts, VPNs, session recording and approval workflows — your controls, on your infrastructure.
  • A dedicated European-market point of contact for clients working through these questions with their DPO — a working mode shaped by years of delivery for German enterprise clients.

The honest summary for your DPO: the vendor is Indian; the data stays in your EU infrastructure and under your control.

Secure development practices

The basics, actually practiced — not a framework poster:

  • Code review before merge on production codebases; changes ship through CI/CD pipelines, not by hand.
  • Least-privilege access to client environments and secrets; individual accounts, no shared credentials.
  • Secrets management — credentials kept out of code and repositories, injected at deploy time.
  • Dependency and patch hygiene — containerized, reproducible builds; base images and dependencies updated deliberately, not never and not blindly.
  • Environment separation — development and testing do not run against production data; sensitive-data debugging happens in the client's environment under the client's rules.
  • Monitoring and alerting as standard on everything we operate, so incidents are seen and handled — and clients are informed without games.
  • Backup and recovery designed per engagement, on client infrastructure, matching the client's retention policy.

GDPR alignment

  • Data minimization by architecture: self-hosted AI removes third-party processors from the data path — the hardest transfer questions never arise.
  • Retention and deletion designed in: data flows, storage and retention are documented per deployment so your DPO can audit them.
  • DPA and records: we sign data processing agreements and maintain records of processing appropriate to our role (typically processor or subprocessor with narrowly scoped access).
  • Our privacy policy covers this website itself, which by design collects no analytics data at all.

For financial-services clients (DORA)

We know that since January 2025 the EU's Digital Operational Resilience Act (DORA) makes our clients responsible for their ICT third-party providers: register entries, contractual provisions on access, audit and exit, incident-notification expectations. We engage as a DORA-aware provider — contract terms that fit your register of information, cooperation with audits, defined exit and handover support. Our long-term stewardship model (same team, documented operations) is a resilience argument, not just a service model.

How we work to ISO 27001-aligned practice

The controls an information-security standard asks for are the controls we run day to day, and they are described above rather than summarized on a certificate: least-privilege named access, secrets kept out of repositories, code review before merge, environment separation, containerized reproducible builds, patch and dependency hygiene, monitoring on everything we operate, and backup and recovery designed per engagement on client infrastructure. Data residency, retention and access are decided at architecture time and documented per deployment, so a data-protection officer or an auditor can follow the data rather than take our word for it.

Client-specific security questionnaires and due-diligence calls: gladly — write to us, and we will answer them directly.


Have a security questionnaire or a skeptical DPO?

Send it over — you will get direct, specific answers.