Legal

Security Policy

Effective: April 2026 · Version 1.1 · Supersedes all prior versions

Amendment notice: For existing clients, material changes take effect 30 days after written notice. For new engagements, changes take effect on the effective date shown above.

Privacy PolicyTerms of ServiceRefund PolicyDelivery PolicyData PolicyCookies PolicySecurity PolicyResponsible Disclosure
ISO 27001 AlignedIT Act 2000DPDP Act 2023CERT-In GuidelinesICAI Standards

Vext Audit Capital audits the information security and data protection practices of other organisations. We hold ourselves to the same standard we apply to our clients. This Security Policy describes our security measures with full transparency.

Important qualification: The security controls described in this policy represent the Firm's current standard practice and are reviewed and updated periodically. They do not constitute a warranty or guarantee of absolute security against all threats. No security system is impenetrable. The Firm's liability in the event of a security incident is governed exclusively by the Terms of Service and applicable law.

1. Security governance

2. Access control

3. Data security in transit and at rest

4. Device and endpoint security

5. Third-party security

All third-party processors are assessed before onboarding and hold at minimum ISO 27001 or SOC 2 certification. The Firm does not use any processor that does not meet this minimum standard. Certifications: Google Workspace (ISO 27001, SOC 2, PCI-DSS); Razorpay (PCI-DSS Level 1, ISO 27001); Vercel (SOC 2 Type 2); Make.com (ISO 27001).

6. Incident response

On a confirmed or suspected incident: contain within 1 hour; assess scope within 24 hours; notify affected B2B clients within 24 hours of confirmation to support their own notification obligations; notify the relevant data protection authority within 72 hours where required by applicable law (Data Protection Board of India for Indian data; relevant EU/UK/other authority for international clients' data); document in Security Incident Register. Contact support@vextaudit.com with subject "Security Incident" immediately if you believe your data has been compromised.

7. Responsible disclosure

Security vulnerabilities in the Firm's systems should be reported in accordance with the Responsible Disclosure Policy.

8. Contact

Security Contact | Vext Audit Capital
Email: support@vextaudit.com
Subject: "Security Query" or "Security Incident"
Incidents: Within 2 Business Hours · General queries: Within 1 Business Day