Hayami
DocsGet it on the Azure Marketplace

Security at Hayami

Last reviewed: 21 August 2026

This page describes how Hayami Ltd operates as a vendor. How the product protects your DNS (the private-VNet boundary, TLS, roles, auditing, and the rest) has its own page:product security, at docs.hayami.io.

The most important fact: we are not in your data path

Hayami operates no hosted service. DTM is deployed from the Azure Marketplace into your own Azure subscription and runs entirely there. It sends no telemetry, usage data, or DNS data to us. That means we holdno customer DNS data, no query logs, and no customer credentials, and a compromise of Hayami's own systems could not reach into your deployment: there is no connection to reach through.

Our entire hosted footprint is two static websites (this site and the documentation site). They have no user accounts, no forms, no databases, and set no cookies.

What customer information we hold

  • Marketplace purchases: Microsoft processes the transaction and shares limited contact and subscription details with us as the publisher, which we use only to provide support and fulfil the order.
  • Email you send us: support and security correspondence, kept only as long as needed.

That is the whole list. Details and retention are in theprivacy policy.

How we build and ship

  • Every change to the product and to these websites goes through apull request with mandatory automated checks; direct changes to a release branch are blocked, for everyone.
  • Those checks include static security analysis, dependency vulnerability scanning, secret scanning, and the full test suiteon every change, with additional scheduled security scans on top.
  • Dependency updates are automated and continuous, and the product keeps a deliberately small third-party dependency footprint to shrink the supply-chain surface.
  • You deploy a certified Azure Marketplace image, and Azure records its publisher, offer, plan and version against the virtual machine, so what you are running is verifiable from your own subscription rather than on our word.

How the websites are run

Both sites are prebuilt static pages served through Cloudflare, with astrict Content Security Policy, no third-party origins, no trackers, and no cookies. There is nothing to log in to and no server-side application to attack; you can verify the headers and the absence of third-party requests directly in your browser.

Our own accounts

The company operates on a deliberately small set of supplier accounts. Administrative access to them uses multi-factor authentication, follows least privilege, and has documented break-glass arrangements. We do not publish an inventory of our internal tooling; the controls above are the commitment.

Honest about our size

Hayami is a small company, and security questionnaires deserve a straight answer about that rather than borrowed enterprise language. What protects you does not depend on our headcount:

  • A deployed DTM cluster keeps serving DNS with no dependency on Hayami: no license server, no phone-home, no hosted control plane.
  • Backups and restore are customer-controlled and documented, and your DNS data never leaves your subscription.
  • Each release is a self-contained image. Once it is deployed in your subscription it keeps working as deployed, with nothing to fetch and nothing to renew on our side.

Security fixes take priority over feature work, and the automated scanning described above is what surfaces them; we do not publish a response-time SLA we could not evidence.

Vulnerability reports

Report vulnerabilities to[email protected]. Thevulnerability disclosure policy covers our response commitments, the scope for good-faith testing, and safe harbour. Both sites publishsecurity.txt.

Certifications and questionnaires

We hold no security certifications today and will list them here when we do, not before. If your procurement process needs a completed questionnaire (for example a CAIQ), email[email protected] and we will answer it.

Changes

This page changes as our practices do; the review date above tells you how current it is.

Hayami
DNS-based traffic management for Azure.
Docs · How it works
Contact · Privacy · Terms
© 2026 Hayami Ltd. Registered in Northern Ireland, no. NI742645. ™ unregistered.No cookies. No tracking. Cookieless analytics only.