GARUDAYA policy
Security Policy
Security expectations for accounts, admin access, documents, payments and responsible reporting.
Applies to:
All users, internal admins, security reviewers and partners.
Last updated:
23 July 2026
Entity:
GARUDAYA PRIVATE LIMITED / GARUDAYA AGRO INDUSTRIES
Account security
Users must protect passwords, OTPs, approved devices and email accounts. Internal admin users are subject to MFA, approved-device checks, role permissions and step-up requirements for sensitive actions.
Prohibited security activity
- Bypassing access controls or RLS policies.
- Testing without written authorization.
- Uploading malware, malicious documents or scripts.
- Attempting privilege escalation, IDOR, scraping, spam or denial-of-service activity.
Responsible disclosure
Security reports should include impact, reproduction steps and affected URLs, and be sent to admin@garudaya.in. Do not access, modify or disclose user data while testing.
Official contact and notices
Questions about security policy should be sent from the registered account email wherever possible. GARUDAYA may request order IDs, application IDs, invoice numbers, KYC references or proof of authority before sharing account-specific information. Official notices may be sent to legal@garudaya.in; operational support may be sent to support@garudaya.in. Registered office: C/O Sabita Jena Nuagam, Dasamundali, Sheragada, Aska, Ganjam – 761106, Odisha, India.
| Desk | |
|---|---|
| Legal | legal@garudaya.in |
| Support | support@garudaya.in |
| Accounts | accounts@garudaya.in |
| KYC | kyc@garudaya.in |
| Export | export@garudaya.in |