Security at Hayami
Last reviewed: 21 August 2026
This page describes how Hayami Ltd operates as a vendor. How the product protects your DNS (the private-VNet boundary, TLS, roles, auditing, and the rest) has its own page:product security, at docs.hayami.io.
The most important fact: we are not in your data path
Hayami operates no hosted service. DTM is deployed from the Azure Marketplace into your own Azure subscription and runs entirely there. It sends no telemetry, usage data, or DNS data to us. That means we holdno customer DNS data, no query logs, and no customer credentials, and a compromise of Hayami's own systems could not reach into your deployment: there is no connection to reach through.
Our entire hosted footprint is two static websites (this site and the documentation site). They have no user accounts, no forms, no databases, and set no cookies.
What customer information we hold
- Marketplace purchases: Microsoft processes the transaction and shares limited contact and subscription details with us as the publisher, which we use only to provide support and fulfil the order.
- Email you send us: support and security correspondence, kept only as long as needed.
That is the whole list. Details and retention are in theprivacy policy.
How we build and ship
- Every change to the product and to these websites goes through apull request with mandatory automated checks; direct changes to a release branch are blocked, for everyone.
- Those checks include static security analysis, dependency vulnerability scanning, secret scanning, and the full test suiteon every change, with additional scheduled security scans on top.
- Dependency updates are automated and continuous, and the product keeps a deliberately small third-party dependency footprint to shrink the supply-chain surface.
- You deploy a certified Azure Marketplace image, and Azure records its publisher, offer, plan and version against the virtual machine, so what you are running is verifiable from your own subscription rather than on our word.
How the websites are run
Both sites are prebuilt static pages served through Cloudflare, with astrict Content Security Policy, no third-party origins, no trackers, and no cookies. There is nothing to log in to and no server-side application to attack; you can verify the headers and the absence of third-party requests directly in your browser.
Our own accounts
The company operates on a deliberately small set of supplier accounts. Administrative access to them uses multi-factor authentication, follows least privilege, and has documented break-glass arrangements. We do not publish an inventory of our internal tooling; the controls above are the commitment.
Honest about our size
Hayami is a small company, and security questionnaires deserve a straight answer about that rather than borrowed enterprise language. What protects you does not depend on our headcount:
- A deployed DTM cluster keeps serving DNS with no dependency on Hayami: no license server, no phone-home, no hosted control plane.
- Backups and restore are customer-controlled and documented, and your DNS data never leaves your subscription.
- Each release is a self-contained image. Once it is deployed in your subscription it keeps working as deployed, with nothing to fetch and nothing to renew on our side.
Security fixes take priority over feature work, and the automated scanning described above is what surfaces them; we do not publish a response-time SLA we could not evidence.
Vulnerability reports
Report vulnerabilities to[email protected]. Thevulnerability disclosure policy covers our response commitments, the scope for good-faith testing, and safe harbour. Both sites publishsecurity.txt.
Certifications and questionnaires
We hold no security certifications today and will list them here when we do, not before. If your procurement process needs a completed questionnaire (for example a CAIQ), email[email protected] and we will answer it.
Changes
This page changes as our practices do; the review date above tells you how current it is.