Account security
LiveHow sign-in, sessions and workspace access are protected, and what you can do to keep your account safe.
Sign-in without passwords
Dhanur AI has no passwords to steal or reuse. You sign in with a one-time code sent to your email, or with Google.
Email codes
- A code is 6 random digits. It works once and expires after 10 minutes.
- After 5 wrong tries, the code stops working.
- Requesting a new code cancels the previous one.
- Each email address can request 5 codes an hour, and each network 30.
- We store only a hash of the code, never the code itself.
- The sign-in page never says whether an account exists for an email address.
- We ask Google only for your basic profile: name, email and picture. We get no access to your mailbox, files or calendar.
- Google must confirm that it has verified your email address.
- Each Google sign-in attempt uses a one-time link that expires after 10 minutes. It is protected against tampering with the industry-standard PKCE check.
Sessions
- When you sign in, your browser gets a random session token in a cookie called
dh_session. We store only a hash of the token. - Scripts on the page can't read the cookie, and it is sent only over secure connections. Browsers also hold it back when another website tries to send data to Dhanur AI in the background.
- A session lasts 30 days from sign-in.
- Signing out ends the session on our servers, not just in your browser.
- The app refuses changes that come from other websites. If a request is blocked this way, you'll see "Cross-site request blocked."
Workspace access
- Every request checks that you are a member of the workspace, and that your role allows the action.
- If you aren't a member, the app says "Workspace not found." It never confirms that another business's workspace exists.
- Roles decide who can invite, change roles and manage projects. See Members and roles.
- A workspace always keeps at least one Owner.
- Security-related actions, such as sign-ins, invites, role changes, removals, agent changes, approval decisions and app connections, are written to an audit log.
- Connected apps are connected by Owners and Admins, on each app's own sign-in screen. We don't see or keep your app passwords.
- IP addresses are stored only in hashed form.
What you can do
- Protect your email account. Whoever can read your inbox can sign in as you, so turn on two-step verification for your email or Google account.
- Never share a sign-in code. We will never ask you for one, by phone, email or chat.
- Sign out on shared computers. Use Sign out in the account menu.
- Keep your team list current. Remove people who leave, and revoke invites you no longer need. See Remove a member.
- Keep two Owners, so you are never locked out.
- Give people the lowest role they need. Viewer is enough for someone who only needs to look.
If something looks wrong
If you got a sign-in code you didn't ask for, you can ignore it. Nobody can sign in without the code.
If you think someone else has used your account, or you have lost a device that is signed in, email outreach@prodigalai.com or call +91 96548 13810. Use the same contacts to report a security weakness.
Planned. Single sign-on (SSO) and SCIM for larger teams, plus a way to view and export the audit log.
Last updated 24 September 2026
Something unclear or wrong? Tell us