Skip to content

Legal

Security

Last updated 28 July 2026

We build security software, so we hold this site and our own practices to the standard we're asking customers to trust us with. That means saying plainly what's true today and what isn't yet — not borrowing the language of certifications we don't hold.

01

Where we are

CuriousDevs is a pre-launch, founding-stage team. We are not currently SOC 2 or ISO 27001 certified. Where those frameworks appear elsewhere on this site — for example, on the industry solutions pages — they describe regulatory or compliance frameworks a given scenario touches, not certifications CuriousDevs holds. We think that distinction matters enough to state it twice.

02

This website, specifically

  • Served entirely over HTTPS/TLS.
  • No cookies, analytics, or third-party tracking scripts (see our Privacy Policy).
  • Contact, booking, and careers submissions are sent by email over an authenticated SMTP connection and are not stored in a database.
  • Resume attachments are capped at 8MB and are validated on both the browser and server before being accepted.
03

Responsible disclosure

If you find a security issue on this website or in anything we've published, we want to know before anyone else does. Email hello@curiousdevs.com with the subject line "Security report" and a way to reach you. We'll acknowledge within one business day. We don't yet run a paid bug bounty — we intend to once a paid product is live — but we will credit you publicly if you'd like, and we won't pursue legal action against good-faith, non-destructive research.

04

What's on the roadmap

Before AgentGuard, CurioComply, or AeroOS reach general availability, our plan is to pursue SOC 2 Type II and complete a third-party penetration test, and to publish an architecture overview for security teams evaluating the product ahead of a deployment decision. None of that exists yet; this line will be updated the moment any of it does, not before.

05

Contact

hello@curiousdevs.com · CuriousDevs, Noida, India.