Legal

Privacy policy

How Vclabs Enterprise Private Limited handles data in connection with the Xyla platform.

1. Who we are

Xyla is developed and operated by Vclabs Enterprise Private Limited (“Vclabs”, “we”, “us”). This policy describes how we handle data in connection with the Xyla platform and this website.

2. What Xyla reads

Xyla analyses source code, configuration and repository metadata that a customer explicitly connects. It builds a semantic representation of that code in order to produce security and compliance findings.

Xyla is not designed to ingest production personal data, and we do not act as a data processor of your end users’ personal data under the Digital Personal Data Protection Act, 2023. Findings reference code identifiers — for example a database column name such as User.email — not the records stored in those columns.

3. Integration credentials

Where you connect a provider, credentials are write-only: they are submitted once, sealed on arrival, and never returned through the interface or the API. Xyla requests read-only scopes and does not request write scope on connected systems.

4. Account and usage data

We process the account information you provide (such as name, work email and organisation) to operate the service, and technical logs to keep it secure and available.

5. Retention

Scan artefacts and audit records are retained for the period configured on your tenant. Audit events are stored in an append-only, hash-chained ledger; revoking a connection marks it revoked rather than deleting its sync history.

6. Your rights

Where the DPDP Act or another applicable law grants you rights over personal data we hold about you — access, correction, completion, updating, erasure and grievance redressal — you may exercise them by contacting us.

7. Contact

Questions about this policy, or a request relating to your rights, can be sent to admin@thevectorcompany.com.

DPDP Rules, 2025