Last updated 8 October 2026
Security
How we protect Escanor, and how to report a vulnerability.
How we protect your data
- Keys and tokens for the services you connect are encrypted at rest and used only to carry out actions you request.
- All connections are encrypted in transit (HTTPS/TLS).
- Two-step verification with an authenticator app and backup codes.
- Sign-ins and changes are logged and kept for one year; you can export your workspace audit log.
- Production actions can require your approval before Escanor or an AI agent carries them out.
- Deleting an account signs you out everywhere and revokes every key immediately.
Report a vulnerability
Email support@escanor.in with the affected page or component, steps to reproduce, and the impact. Leave out real tokens and other people's data. We acknowledge within 24 hours and keep you updated until it is fixed. We will not take legal action against good-faith research that follows the rules below.
Rules for security research
- Test only against your own account and data.
- Do not access, change or keep other people's data; stop and report as soon as you find any.
- Do not degrade the service (no denial-of-service, spam or social engineering).
- Give us reasonable time to fix an issue before you disclose it.
Incidents
We report cyber security incidents to CERT-In within 6 hours as Indian law requires, and tell affected users without delay with what happened and what they should do.
Contact
- Company
- Escanor Labs
- Address
- ATF-39, Gaur World Smart Street, Sector-16B, Greater Noida West, Uttar Pradesh 201308, India
- Grievance Officer
- Lakshay Jain, Co-founder; Grievance Officer and data protection contact
- Email (support, grievances, privacy and security)
- support@escanor.in