Security and data
How we look after your data
- Live
Databases in Bengaluru
Our application database runs on servers in Bengaluru, India.
- Live
Protected sign-in
Single-use codes stored only as hashes, with limits on how often codes can be requested.
- Live
Workspaces kept apart
Only members can reach a workspace. Anyone else gets a “not found” reply.
- Live
No training on your data
We do not use your content to train AI models.
Where your data livesLive
- Our application database runs on DigitalOcean servers in Bengaluru, India. Your account, workspaces, projects, team members, agents, tasks, leads and sign-in records are stored there.
- Photos and PDFs sent in chats are stored in DigitalOcean Spaces in New York, United States. They are private, are only served through our engine after it checks who is asking, and are deleted after 90 days.
- The website and app are served by Vercel. The app's server code runs in Vercel's Mumbai region and passes your requests on to our engine in Bengaluru.
- A few services process data outside India: email delivery, Google sign-in if you use it, AI models when agents run tasks, and connected apps if your workspace uses them. They are listed under service providers below.
How sign-in is protectedLive
Email codes
- A sign-in code has 6 digits, works once and expires after 10 minutes.
- Asking for a new code cancels any unused earlier code. After 5 wrong tries, a code stops working.
- We store only a keyed hash (HMAC-SHA256) of each code, never the code itself.
- Code requests are limited to 5 an hour for each email address and 30 an hour from each network. Network addresses are stored only as hashes.
- The sign-in form gives the same response whether or not an account exists for an email address.
Sign in with Google
- We use Google's standard sign-in flow with PKCE and ask only for your name, email address and profile picture.
- We accept a Google sign-in only when Google confirms the email address is verified.
- Each attempt uses a one-time value that expires after 10 minutes, and after sign-in we only send you to pages inside our app.
Sessions
- After you sign in, your browser keeps a random session token in a cookie marked HttpOnly, so page scripts cannot read it, and Secure, so it is only sent over HTTPS. Our production engine will not start if secure cookies are switched off.
- We store only a SHA-256 hash of the token. A session lasts up to 30 days, and signing out ends it on our servers straight away.
Cross-site request protection
- The session cookie is sent with SameSite=Lax, and our engine refuses any request that changes data when it comes from a website other than our app.
- Our engine only answers app requests that come through our own app server with a shared secret key. Anything else gets a “not found” reply. The exceptions are a health check and incoming payment webhooks, which must carry the sender's signature.
- Our production engine will not start with development secrets or without HTTPS for the app.
Who can see whatLive
Everyone in a workspace has one of four roles. Each request is checked against your role before anything happens.
| Role | What it allows |
|---|---|
| Owner | Full control of the workspace. Only an owner can make someone an owner, or change or remove another owner. A workspace always keeps at least one owner. |
| Admin | Renames the workspace, invites and removes members, changes roles, manages projects, connects apps and deletes agents. |
| Builder | Builds, tests, publishes and pauses agents, and approves or rejects the actions they ask to take. |
| Viewer | Sees the workspace, its projects, members, agents, tasks and leads without changing them. |
- Invitations are sent to an email address and are accepted only when someone signs in with that verified address.
- Members and pending invitations both count toward your plan's seats. The free plan has 2.
- Workspaces are isolated. If you are not a member of a workspace, it answers “not found”, exactly as if it did not exist. Projects from another workspace are refused the same way. Automated tests check this.
- An agent can use only the tools and app actions switched on for it, and each tool's approval setting is checked before it runs.
- Sign-ins, sign-outs, invitations, membership changes, workspace and project changes, agent changes, approval decisions and app connections are recorded in an audit log.
Encryption in transitLive
- The website and app are served over HTTPS, and our app talks to our engine over HTTPS.
- Our pages cannot be shown inside frames on other websites, which guards against clickjacking.
AI and your data
- LiveWe do not use your content to train AI models, and we do not sell it.
- LiveWhen an agent runs a task, we send the AI model provider only the content that task needs, to get a result back.
- LiveEach step of a task records which model ran, the tokens it used and what it cost, so you can see it on the task.
- LiveTest chats send nothing to anyone. Actions in connected apps that only read data run for real in a test; anything that would change data is simulated.
- LiveEach task has a spending cap, and a daily AI spending cap across the platform pauses customer-facing AI work if it is reached.
- NextSpending limits and alerts that you set for your own workspace.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you can ask us to give you information about your personal data, correct, complete, update or erase it, and you can withdraw consent, nominate someone to act for you and have your grievances addressed.
Write to outreach@prodigalai.com from your registered email address. The privacy policy explains each right, how long we keep data and how we handle data inside a customer's workspace.
Service providers
These services process personal data for us, each only for the purpose shown. When we add channels such as WhatsApp, we will add them here.
DigitalOcean
- What it does:
- Servers and databases
- Where:
- Bengaluru, India
- When:
- Always
DigitalOcean Spaces
- What it does:
- File storage for photos and PDFs sent in chats
- Where:
- New York, United States
- When:
- When photos or PDFs are sent in chats
Vercel
- What it does:
- Website and app hosting
- Where:
- App server code runs in Mumbai, India; pages are delivered through a global network
- When:
- Always
Cloudflare
- What it does:
- DNS
- Where:
- Global network
- When:
- Always
Postmark
- What it does:
- Email, such as sign-in codes and invitations
- Where:
- Outside India
- When:
- When we email you
Google
- What it does:
- Optional sign-in
- Where:
- Outside India
- When:
- Only if you choose Sign in with Google
Razorpay
- What it does:
- Payments
- Where:
- India
- When:
- When you buy credits
AI model providers, such as Anthropic
- What it does:
- Processing the content a task needs to return a result
- Where:
- Outside India
- When:
- When an agent runs a task
Brave
- What it does:
- Web search: only the search words, kept up to 90 days for billing and not linked to a person
- Where:
- Outside India
- When:
- Only for agents a workspace lets search the web
Voyage AI
- What it does:
- Finding knowledge by meaning
- Where:
- Outside India
- When:
- When agents search knowledge. Voyage keeps nothing and trains on nothing we send
fal.ai
- What it does:
- Making images: the image description and the image
- Where:
- Outside India
- When:
- Only for agents a workspace lets create images. fal keeps no copy
Recall.ai
- What it does:
- The meeting notetaker: the meeting link, its recording and transcript
- Where:
- United States
- When:
- Only when a workspace's team sends a notetaker. Recording deleted once transcribed
Google, Slack and HubSpot
- What it does:
- Apps a workspace connects directly: its calendar and Gmail, its Slack, its HubSpot
- Where:
- Outside India
- When:
- Only if the workspace connects them
Pipedream
- What it does:
- Connected apps: signing in to your apps and running the app actions you add to agents
- Where:
- Outside India
- When:
- Only if your workspace connects an app (pilot)
| Provider | What it does | Where | When |
|---|---|---|---|
| DigitalOcean | Servers and databases | Bengaluru, India | Always |
| DigitalOcean Spaces | File storage for photos and PDFs sent in chats | New York, United States | When photos or PDFs are sent in chats |
| Vercel | Website and app hosting | App server code runs in Mumbai, India; pages are delivered through a global network | Always |
| Cloudflare | DNS | Global network | Always |
| Postmark | Email, such as sign-in codes and invitations | Outside India | When we email you |
| Optional sign-in | Outside India | Only if you choose Sign in with Google | |
| Razorpay | Payments | India | When you buy credits |
| AI model providers, such as Anthropic | Processing the content a task needs to return a result | Outside India | When an agent runs a task |
| Brave | Web search: only the search words, kept up to 90 days for billing and not linked to a person | Outside India | Only for agents a workspace lets search the web |
| Voyage AI | Finding knowledge by meaning | Outside India | When agents search knowledge. Voyage keeps nothing and trains on nothing we send |
| fal.ai | Making images: the image description and the image | Outside India | Only for agents a workspace lets create images. fal keeps no copy |
| Recall.ai | The meeting notetaker: the meeting link, its recording and transcript | United States | Only when a workspace's team sends a notetaker. Recording deleted once transcribed |
| Google, Slack and HubSpot | Apps a workspace connects directly: its calendar and Gmail, its Slack, its HubSpot | Outside India | Only if the workspace connects them |
| Pipedream | Connected apps: signing in to your apps and running the app actions you add to agents | Outside India | Only if your workspace connects an app (pilot) |
Governance checklist
What is in place today, what is partly done and what is still planned. A date is when it reached customers; we don't give dates for work that hasn't started.
| Control | Status | Date |
|---|---|---|
| Data stored in India. Databases in Bengaluru and app servers in Mumbai. Photos and PDFs sent in chats are still stored in New York. | Partial | No date yet for the rest |
| Workspaces kept apart. Only members reach a workspace; anyone else gets “not found”. | Done | From launch |
| Roles for every person. Owner, Admin, Builder and Viewer, each limited to what the job needs. | Done | From launch |
| AI says it is AI. Every agent says so in its first reply, on every channel. | Done | From launch |
| An agent can only use the tools you give it. Tool allow-lists per agent, checked on every step. | Done | From launch |
| People approve what matters. Actions can ask first, and connected-app deletes always ask. | Done | From launch |
| Approval limits by amount. Above your limit, an action such as a refund always waits for a person. | Done | 24 September 2026 |
| Spending caps and a kill switch. A cap per task, a daily platform cap, and a switch that pauses customer-facing AI work. | Done | From launch |
| Tests before changes go live. Test sets, with an option to block publishing until they pass. | Done | 17 September 2026 |
| Checks on real conversations. Daily quality checks against each business's rules, when the business turns them on. | Done | 24 September 2026 |
| Undo a bad change. Any earlier version of an agent can be put back live in one click. | Done | 24 September 2026 |
| Activity log for owners and admins. Who did what, by area, with a CSV download. IP addresses are never shown. | Done | 24 September 2026 |
| Contact details hidden from Viewers. An agent setting that masks phone numbers and emails in tasks, exports, leads and memory. | Done | 17 September 2026 |
| Secrets kept encrypted. Connection tokens and tool secrets are encrypted and never shown again. | Done | 17 September 2026 |
| ID and card numbers hidden from the AI. Aadhaar, PAN, card and bank numbers, OTPs and UPI PINs are replaced before the AI reads a message. On by default. | Done | 24 September 2026 |
| Rules for every agent. Workspace-wide rules for what always asks first, what is switched off and approval limits. The stricter setting wins. | Done | 26 September 2026 |
| Failures in one place. Needs attention lists failed tasks, broken connections and undelivered messages, with a daily email to Owners and Admins. | Done | 26 September 2026 |
| Traces in your own monitoring tool. Each finished task sent as an OpenTelemetry trace, with no message text. | Done | 26 September 2026 |
| Public uptime history. Each part checked every minute, with 90 days of figures and published incidents at dhanurai.com/uptime. No uptime promise until 90 days are measured. | Done | 26 September 2026 |
| Single sign-on and SCIM. For larger teams. | Planned | No date yet |
| SOC 2 audit. We will not claim it until an independent audit is complete. | Planned | No date yet |
If something goes wrong
If a security breach affects personal data we hold, we will tell the people affected and the Data Protection Board of India without delay, saying what happened, what it means for them and what we are doing about it. We will send the Board a full report within 72 hours of finding out, as India's data protection rules require, and post an update on our company page.
Certifications
We do not hold any security certification yet, and we will not claim one until an independent audit is complete. Here is what we plan to work on next.
- PlannedSOC 2 readiness. Preparing our controls and evidence for a SOC 2 audit.
- PlannedSingle sign-on and SCIM. Sign in through your company's identity provider, and manage users from it.
Reporting a security issue
If you think you have found a security problem in Dhanur AI, email outreach@prodigalai.com with “Security report” in the subject. Please include what you found, the steps to reproduce it, the pages or requests involved, and how we can reach you.
While you look
- Test only against your own account and workspace.
- Do not access, change or delete other people's data. If you reach it by accident, stop and tell us.
- Do not run denial-of-service tests, send spam or try to trick our team.
- Give us a reasonable time to fix the issue before you share it publicly.
We read every report and will keep you updated while we work on a fix. We do not run a paid bug bounty at the moment.
Questions
Where is my data stored?
Our application databases are in Bengaluru, India, and photos and PDFs sent in chats are stored with DigitalOcean in New York. Some services we use, such as email delivery, Google sign-in, AI models and connected apps, process data outside India. The list of providers is on this page.
Do you train AI models on my data?
No. We send an AI model provider only the content a task needs, to get a result back, and we do not use your content to train models.
Do you have SOC 2 or ISO certification?
Not yet. SOC 2 readiness is on our roadmap. We will say so here when anything changes.
How do I report a security issue?
Email us with the details. The responsible disclosure section on this page explains what to include.
Questions about your data?
Write to us before you sign up if you need more detail for your own review.