Skip to content
Malai Try the demo

Security

Security posture you can audit.

This isn't a marketing page. It's the answers your RFP asks for, each one grounded in a control, table, or build-time gate in the codebase you can clone today. Where a control is on the v2 roadmap rather than shipped, we say so explicitly.

Audience: security reviewers, compliance leads, and cloud architects assessing Malai as a licensing or commissioning target.

Security posture

Six controls, each named against the artifact.

These are the controls reviewers ask about first. Every claim points at a concrete table, managed cloud service, or build-time gate you can verify by reading the repository.

Incident readiness

How you detect, and how you respond.

Reviewers care less about whether something can go wrong and more about what you have in place when it does. These are the three surfaces that answer the follow-up questions.

Compliance framing

What Malai is — and what it explicitly is not.

The credibility move: we name what we are not so you can trust what we claim we are. Every item below is a deliberate constraint, not an oversight.

Malai is a reference platform — its job is to be evaluated, not to hold customer money.

What's deliberately not v1

Security roadmap, written down.

We picked production-shaped over over-promising. These are the v2 security candidates — each one is a separate decision under DECISIONS.md, not vapour.