Security
Security and privacy are core to how Vyomi is built. This page describes our posture and how to report a vulnerability responsibly.
Report a vulnerability
Found a security issue in vyomi.cloud, the appliance, or the in-browser simulator? Please tell us before disclosing it publicly.
[email protected]Local-first by design
Vyomi runs on your own machine or entirely in your browser. The cloud resources you create, your application code, your credentials and the data you generate never leave your environment — there is no server-side copy for an attacker to reach, because we never receive them. The in-browser simulator runs client-side in WebAssembly and keeps everything in your tab.
What we protect & how
- Encryption in transit — traffic to vyomi.cloud is served over TLS.
- Minimal data — we collect only limited account and install telemetry, and never your resources or PII from them (see our Privacy Policy).
- Authenticated access — accounts support sign-in via email and OAuth (Google, GitHub, LinkedIn).
- Least privilege & isolation — the appliance runs your workloads in isolated local containers/VMs on your own hardware.
Scope
In scope: vyomi.cloud and its subdomains, the downloadable appliance, and the in-browser simulator. Out of scope: third-party services we link to, social-engineering, physical attacks, and volumetric denial-of-service testing.
What we ask
- Give us a reasonable time to investigate and remediate before any public disclosure.
- Do not access, modify or destroy data that isn't yours, and don't degrade the service for others.
- Provide enough detail (steps, impact, proof-of-concept) for us to reproduce the issue.
What to expect from us
- We aim to acknowledge reports within a few business days.
- We will keep you updated on remediation progress and, with your permission, credit you once the issue is resolved.
- Safe harbor: we will not pursue legal action for good-faith research that follows this policy.
Contact
Security reports: [email protected]. General questions: [email protected].