Dhanur AI

Security and data

How we look after your data

Dhanur AI is in early access. This page describes what our systems do today, marks what is still to come, and lists every service that handles your data.
  • Live

    Databases in Bengaluru

    Our application database runs on servers in Bengaluru, India.

  • Live

    Protected sign-in

    Single-use codes stored only as hashes, with limits on how often codes can be requested.

  • Live

    Workspaces kept apart

    Only members can reach a workspace. Anyone else gets a “not found” reply.

  • Live

    No training on your data

    We do not use your content to train AI models.

Where your data livesLive

  • Our application database runs on DigitalOcean servers in Bengaluru, India. Your account, workspaces, projects, team members, agents, tasks, leads and sign-in records are stored there.
  • Photos and PDFs sent in chats are stored in DigitalOcean Spaces in New York, United States. They are private, are only served through our engine after it checks who is asking, and are deleted after 90 days.
  • The website and app are served by Vercel. The app's server code runs in Vercel's Mumbai region and passes your requests on to our engine in Bengaluru.
  • A few services process data outside India: email delivery, Google sign-in if you use it, AI models when agents run tasks, and connected apps if your workspace uses them. They are listed under service providers below.

How sign-in is protectedLive

Email codes

  • A sign-in code has 6 digits, works once and expires after 10 minutes.
  • Asking for a new code cancels any unused earlier code. After 5 wrong tries, a code stops working.
  • We store only a keyed hash (HMAC-SHA256) of each code, never the code itself.
  • Code requests are limited to 5 an hour for each email address and 30 an hour from each network. Network addresses are stored only as hashes.
  • The sign-in form gives the same response whether or not an account exists for an email address.

Sign in with Google

  • We use Google's standard sign-in flow with PKCE and ask only for your name, email address and profile picture.
  • We accept a Google sign-in only when Google confirms the email address is verified.
  • Each attempt uses a one-time value that expires after 10 minutes, and after sign-in we only send you to pages inside our app.

Sessions

  • After you sign in, your browser keeps a random session token in a cookie marked HttpOnly, so page scripts cannot read it, and Secure, so it is only sent over HTTPS. Our production engine will not start if secure cookies are switched off.
  • We store only a SHA-256 hash of the token. A session lasts up to 30 days, and signing out ends it on our servers straight away.

Cross-site request protection

  • The session cookie is sent with SameSite=Lax, and our engine refuses any request that changes data when it comes from a website other than our app.
  • Our engine only answers app requests that come through our own app server with a shared secret key. Anything else gets a “not found” reply. The exceptions are a health check and incoming payment webhooks, which must carry the sender's signature.
  • Our production engine will not start with development secrets or without HTTPS for the app.

Who can see whatLive

Everyone in a workspace has one of four roles. Each request is checked against your role before anything happens.

RoleWhat it allows
OwnerFull control of the workspace. Only an owner can make someone an owner, or change or remove another owner. A workspace always keeps at least one owner.
AdminRenames the workspace, invites and removes members, changes roles, manages projects, connects apps and deletes agents.
BuilderBuilds, tests, publishes and pauses agents, and approves or rejects the actions they ask to take.
ViewerSees the workspace, its projects, members, agents, tasks and leads without changing them.
  • Invitations are sent to an email address and are accepted only when someone signs in with that verified address.
  • Members and pending invitations both count toward your plan's seats. The free plan has 2.
  • Workspaces are isolated. If you are not a member of a workspace, it answers “not found”, exactly as if it did not exist. Projects from another workspace are refused the same way. Automated tests check this.
  • An agent can use only the tools and app actions switched on for it, and each tool's approval setting is checked before it runs.
  • Sign-ins, sign-outs, invitations, membership changes, workspace and project changes, agent changes, approval decisions and app connections are recorded in an audit log.

Encryption in transitLive

  • The website and app are served over HTTPS, and our app talks to our engine over HTTPS.
  • Our pages cannot be shown inside frames on other websites, which guards against clickjacking.

AI and your data

  • LiveWe do not use your content to train AI models, and we do not sell it.
  • LiveWhen an agent runs a task, we send the AI model provider only the content that task needs, to get a result back.
  • LiveEach step of a task records which model ran, the tokens it used and what it cost, so you can see it on the task.
  • LiveTest chats send nothing to anyone. Actions in connected apps that only read data run for real in a test; anything that would change data is simulated.
  • LiveEach task has a spending cap, and a daily AI spending cap across the platform pauses customer-facing AI work if it is reached.
  • NextSpending limits and alerts that you set for your own workspace.

Your rights

Under India's Digital Personal Data Protection Act, 2023, you can ask us to give you information about your personal data, correct, complete, update or erase it, and you can withdraw consent, nominate someone to act for you and have your grievances addressed.

Write to outreach@prodigalai.com from your registered email address. The privacy policy explains each right, how long we keep data and how we handle data inside a customer's workspace.

Service providers

These services process personal data for us, each only for the purpose shown. When we add channels such as WhatsApp, we will add them here.

  • DigitalOcean

    What it does:
    Servers and databases
    Where:
    Bengaluru, India
    When:
    Always
  • DigitalOcean Spaces

    What it does:
    File storage for photos and PDFs sent in chats
    Where:
    New York, United States
    When:
    When photos or PDFs are sent in chats
  • Vercel

    What it does:
    Website and app hosting
    Where:
    App server code runs in Mumbai, India; pages are delivered through a global network
    When:
    Always
  • Cloudflare

    What it does:
    DNS
    Where:
    Global network
    When:
    Always
  • Postmark

    What it does:
    Email, such as sign-in codes and invitations
    Where:
    Outside India
    When:
    When we email you
  • Google

    What it does:
    Optional sign-in
    Where:
    Outside India
    When:
    Only if you choose Sign in with Google
  • Razorpay

    What it does:
    Payments
    Where:
    India
    When:
    When you buy credits
  • AI model providers, such as Anthropic

    What it does:
    Processing the content a task needs to return a result
    Where:
    Outside India
    When:
    When an agent runs a task
  • Brave

    What it does:
    Web search: only the search words, kept up to 90 days for billing and not linked to a person
    Where:
    Outside India
    When:
    Only for agents a workspace lets search the web
  • Voyage AI

    What it does:
    Finding knowledge by meaning
    Where:
    Outside India
    When:
    When agents search knowledge. Voyage keeps nothing and trains on nothing we send
  • fal.ai

    What it does:
    Making images: the image description and the image
    Where:
    Outside India
    When:
    Only for agents a workspace lets create images. fal keeps no copy
  • Recall.ai

    What it does:
    The meeting notetaker: the meeting link, its recording and transcript
    Where:
    United States
    When:
    Only when a workspace's team sends a notetaker. Recording deleted once transcribed
  • Google, Slack and HubSpot

    What it does:
    Apps a workspace connects directly: its calendar and Gmail, its Slack, its HubSpot
    Where:
    Outside India
    When:
    Only if the workspace connects them
  • Pipedream

    What it does:
    Connected apps: signing in to your apps and running the app actions you add to agents
    Where:
    Outside India
    When:
    Only if your workspace connects an app (pilot)

Governance checklist

What is in place today, what is partly done and what is still planned. A date is when it reached customers; we don't give dates for work that hasn't started.

ControlStatusDate
Data stored in India. Databases in Bengaluru and app servers in Mumbai. Photos and PDFs sent in chats are still stored in New York.PartialNo date yet for the rest
Workspaces kept apart. Only members reach a workspace; anyone else gets “not found”.DoneFrom launch
Roles for every person. Owner, Admin, Builder and Viewer, each limited to what the job needs.DoneFrom launch
AI says it is AI. Every agent says so in its first reply, on every channel.DoneFrom launch
An agent can only use the tools you give it. Tool allow-lists per agent, checked on every step.DoneFrom launch
People approve what matters. Actions can ask first, and connected-app deletes always ask.DoneFrom launch
Approval limits by amount. Above your limit, an action such as a refund always waits for a person.Done24 September 2026
Spending caps and a kill switch. A cap per task, a daily platform cap, and a switch that pauses customer-facing AI work.DoneFrom launch
Tests before changes go live. Test sets, with an option to block publishing until they pass.Done17 September 2026
Checks on real conversations. Daily quality checks against each business's rules, when the business turns them on.Done24 September 2026
Undo a bad change. Any earlier version of an agent can be put back live in one click.Done24 September 2026
Activity log for owners and admins. Who did what, by area, with a CSV download. IP addresses are never shown.Done24 September 2026
Contact details hidden from Viewers. An agent setting that masks phone numbers and emails in tasks, exports, leads and memory.Done17 September 2026
Secrets kept encrypted. Connection tokens and tool secrets are encrypted and never shown again.Done17 September 2026
ID and card numbers hidden from the AI. Aadhaar, PAN, card and bank numbers, OTPs and UPI PINs are replaced before the AI reads a message. On by default.Done24 September 2026
Rules for every agent. Workspace-wide rules for what always asks first, what is switched off and approval limits. The stricter setting wins.Done26 September 2026
Failures in one place. Needs attention lists failed tasks, broken connections and undelivered messages, with a daily email to Owners and Admins.Done26 September 2026
Traces in your own monitoring tool. Each finished task sent as an OpenTelemetry trace, with no message text.Done26 September 2026
Public uptime history. Each part checked every minute, with 90 days of figures and published incidents at dhanurai.com/uptime. No uptime promise until 90 days are measured.Done26 September 2026
Single sign-on and SCIM. For larger teams.PlannedNo date yet
SOC 2 audit. We will not claim it until an independent audit is complete.PlannedNo date yet

If something goes wrong

If a security breach affects personal data we hold, we will tell the people affected and the Data Protection Board of India without delay, saying what happened, what it means for them and what we are doing about it. We will send the Board a full report within 72 hours of finding out, as India's data protection rules require, and post an update on our company page.

Certifications

We do not hold any security certification yet, and we will not claim one until an independent audit is complete. Here is what we plan to work on next.

  • PlannedSOC 2 readiness. Preparing our controls and evidence for a SOC 2 audit.
  • PlannedSingle sign-on and SCIM. Sign in through your company's identity provider, and manage users from it.

Reporting a security issue

If you think you have found a security problem in Dhanur AI, email outreach@prodigalai.com with “Security report” in the subject. Please include what you found, the steps to reproduce it, the pages or requests involved, and how we can reach you.

While you look

  • Test only against your own account and workspace.
  • Do not access, change or delete other people's data. If you reach it by accident, stop and tell us.
  • Do not run denial-of-service tests, send spam or try to trick our team.
  • Give us a reasonable time to fix the issue before you share it publicly.

We read every report and will keep you updated while we work on a fix. We do not run a paid bug bounty at the moment.

Questions

Where is my data stored?

Our application databases are in Bengaluru, India, and photos and PDFs sent in chats are stored with DigitalOcean in New York. Some services we use, such as email delivery, Google sign-in, AI models and connected apps, process data outside India. The list of providers is on this page.

Do you train AI models on my data?

No. We send an AI model provider only the content a task needs, to get a result back, and we do not use your content to train models.

Do you have SOC 2 or ISO certification?

Not yet. SOC 2 readiness is on our roadmap. We will say so here when anything changes.

How do I report a security issue?

Email us with the details. The responsible disclosure section on this page explains what to include.

Questions about your data?

Write to us before you sign up if you need more detail for your own review.