GARUDAYA policy

Security Policy

Security expectations for accounts, admin access, documents, payments and responsible reporting.

Applies to:
All users, internal admins, security reviewers and partners.

Last updated:
08 August 2026

Entity:
GARUDAYA PRIVATE LIMITED / GARUDAYA AGRO INDUSTRIES

Private company and approval disclaimer

GARUDAYA PRIVATE LIMITED is a private company, not a government department, statutory authority, regulator, embassy, customs office, bank or insurer. A GARUDAYA review, checklist, referral or document submission does not itself grant a licence, certificate, permit, export clearance, tax registration or government approval. Any approval must be issued by the competent authority or contracting organization named in the applicable process. Users remain responsible for truthful information, fees, renewals and lawful compliance.

Account security

Users must protect passwords, OTPs, approved devices and email accounts. Internal admin users are subject to MFA, approved-device checks, role permissions and step-up requirements for sensitive actions.

Prohibited security activity

  • Bypassing access controls or RLS policies.
  • Testing without written authorization.
  • Uploading malware, malicious documents or scripts.
  • Attempting privilege escalation, IDOR, scraping, spam or denial-of-service activity.

Responsible disclosure

Security reports should include impact, reproduction steps and affected URLs, and be sent to admin@garudaya.in. Do not access, modify or disclose user data while testing.

Independent providers and regulatory verification

GARUDAYA may apply to regulated, government or private providers for payment processing, email/SMS delivery, DigiLocker or API Setu access, PAN/Aadhaar checks, bank-account validation, logistics and other integrations. Displaying an integration workflow or accepting an application does not mean that a provider, regulator or government body has endorsed GARUDAYA. A feature is treated as live only after the relevant provider approves the account, production credentials are securely configured, and GARUDAYA completes acceptance testing. Until then, the website labels the result as pending, manual review or unavailable and does not represent it as verified.

Official contact and notices

Questions about security policy should be sent from the registered account email wherever possible. GARUDAYA may request order IDs, application IDs, invoice numbers, KYC references or proof of authority before sharing account-specific information. Official notices may be sent to legal@garudaya.in; operational support may be sent to support@garudaya.in. Registered office: C/O Sabita Jena Nuagam, Dasamundali, Sheragada, Aska, Ganjam – 761106, Odisha, India.

DeskEmail
Grievance and legal noticeslegal@garudaya.in
Customer supportsupport@garudaya.in
Payments and accountsaccounts@garudaya.in
KYC and privacykyc@garudaya.in
Exportexport@garudaya.in