Keeping it safe

Where your systems run, who can open what, and how backups work. What we will never do with your data, and how we stop an assistant from doing harm.

Where things run

Anything that holds your customers' details runs in India. We rent servers in data centres in Mumbai, Chennai or Bengaluru from providers such as Amazon Web Services, Google Cloud, Microsoft Azure and DigitalOcean. Each of these centres is ISO 27001-certified, which is the international standard for how a data centre is run and audited. The server is rented in your name where possible, so the bill and the login are yours.

If you would rather keep everything inside your building, we can set it up on a machine in your office. The trade-offs are explained under Where your data lives.

Where the AI models themselves run is a separate question, answered on The AI itself. In short: your records stay on your server. When an assistant reads a message or a document, only the words it needs for that one task are sent to the model. The providers we use do not keep them or train on them under business terms. Where a task is sensitive, we can use a model hosted in India.

Who can access what

Every login is a named person with a role, and every role gets the least access that does the job. The person who approves invoices can see invoices. The person who answers WhatsApp cannot see the bank. Nobody, including us, uses a shared password.

Your staff
Their own logins, with two-factor sign-in on anything that touches money or customer data. You decide the roles. We set them up and show you how to change them.
Us, during the build
Named logins for the two or three people working on your project, with the same two-factor rule. Every action we take is logged, and you can see the log.
After handover
Our logins are removed at the end of the fixes period: 30 days after a Sprint launch, or 60 after a Project. If you keep a support plan, one named person keeps access, with the role you agree to, and the log stays on.

Two-factor sign-in means a password plus a one-time code on the phone. It stops the most common way accounts are broken into, which is a guessed or leaked password.

Backups

A backup is only useful if you can get the data back. So we do three things, not one. Every night we take a copy of all your records and every uploaded document. We encrypt that copy (scramble it so that nobody without the key can read it). We keep it off-site, in a second data centre in India run by a different provider, so a fire or a billing mistake at one cannot reach the other. And every quarter we restore a backup onto a fresh server, run the reports on it, and write down how long it took.

What we never do with your data

These five are written into every agreement we sign, and they do not change with the size of the project.

  • Never train models on it. Your invoices, messages and price lists are not used to teach anyone's AI, ours or a vendor's.
  • Never sell it or share it. Not with partners, not even with the names removed, not at all.
  • Never move it abroad without asking. Your records stay in India. If a task needs a model that runs outside India, we say so before we build it and you decide.
  • Never keep it after a project ends. On handover day you get the full copy and our copies are deleted, unless you ask us to keep one.
  • Never look at it without a reason. We open your data to build, fix or support what we agreed to, and the log shows when we did.

Protecting against misuse

An assistant that can send messages and post vouchers needs limits, the same way a new employee does. We build five in.

  • Rate limits: an assistant can send a set number of messages an hour and no more, so a mistake or a prank cannot become a flood.
  • Approval steps for money: anything that moves money, changes a price or deletes a record stops and waits for a named person to say yes. The assistant drafts, a person approves.
  • Logs: every message sent, every voucher posted and every login is written down with the time and who, or what, did it. You can read the log, and so can your auditor.
  • Audits: every quarter we go through the roles, the logs and the software versions with you, and fix what has drifted.
  • An assistant that says "I do not know": when a question is outside what it was given, it says so and hands over to a person. It never makes something up. AI assistants explains how the handover works.

Approval steps

What happens when an assistant is asked to move money

The same route applies to a refund, a price change or deleting a customer: the assistant prepares, a person decides, and the log records both.

Scroll sideways to see the whole route. The list below says the same thing in words.

How an approval step worksA request that involves money is drafted by the assistant, checked against the limits you set, sent to a named person for approval, and only then carried out and logged.yesapprovedA customer asks for arefund on WhatsAppThe assistant draftsitreply and credit noteWithin the limits youset?amount and customerA named personapprovesone tap on the phoneRefund sent, voucherpostedlogged with who approvedCustomer told onWhatsAppcredit note attached

In words

  1. A customer asks for a refund on WhatsApp.
  2. The assistant drafts the reply and the credit note. Nothing is sent yet.
  3. The draft is checked against the limits you set: the amount, the customer, how often. Outside the limits, it stops and a person is told.
  4. A named person sees the draft on their phone and approves it with one tap, or says no.
  5. Only then is the refund sent and the voucher posted, logged with who approved it and when.
  6. The customer is told, with the credit note attached. Requests that do not move money, such as an address change, skip the approval step but are still logged.

Before you sign with anyone

Questions to ask any vendor

Ask these of anyone who wants to hold your data, including us. Our own answers are next to each one, and we put them in writing in the agreement.

  • Where exactly is my data stored?

    In a named data centre in India, on a server rented in your name where possible. The location is written into the agreement.

  • Who at your company can see it, and how would I know?

    Two or three named people during the build, each with a two-factor login. Every access is logged, and you can read the log.

  • What happens to your access when the project ends?

    It is removed at the end of the fixes period: 30 days after a Sprint launch, or 60 after a Project. It stays only if you keep a support plan, and then only for one named person.

  • Do you train AI on my data?

    No. Not ours, not a vendor's. It is written into every agreement we sign.

  • Is it backed up, and have you ever restored one?

    Every night, encrypted, off-site in India. We restore a copy every quarter and tell you how it went.

  • Does it ever leave India?

    Your records, no. If a task needs an AI model that runs outside India, we tell you before we build it and you decide.

  • What can the assistant do without a person?

    Read, draft and answer. Anything that moves money, changes a price or deletes a record waits for a named person.

  • What happens when something goes wrong?

    A written incident plan: who is called, in what order, what is switched off, and what you are told and when. You get it before launch.

  • Can I take everything and leave?

    Yes. Code, logins, documents and data are yours, and everything keeps running without us.

  • Is the software kept up to date?

    Yes. Security fixes go in within the week, other updates in a monthly window you agree to, and we note both in the quarterly review.

  • Are you set up for India's data protection law?

    Yes. Consent is recorded next to each phone number. Every copy sits in one place, so deletion is one action. A named contact is published, as the Digital Personal Data Protection Act, 2023 asks. The detail is under India's data protection law.

Safeguards

What we do, how, and how often

The full list in one table, so you can hold it against anyone else's.

Scroll sideways to see all the columns: How and How often.

Safeguards, how they work, and how often they happen
WhatHowHow often
Data while it travelsEncrypted with TLS between your phone, the server and every connected tool. Nothing travels in readable form.Always
Data while it is storedEncrypted on the server's disk and in every backup, using keys the provider looks after.Always
LoginsA named login per person, two-factor sign-in on anything touching money or customer data, no shared passwords.Every login
Access reviewRoles, logins and who still needs what, checked with you. Unused logins removed.Every quarter
BackupsA full copy of your records and documents, encrypted, kept off-site in a second Indian data centre.Every night
Restore testA backup brought up on a fresh server and the month-end report run on it. The result is written down.Every quarter
Software updatesSecurity fixes applied within the week. Other updates in a monthly window you agree to.Weekly and monthly
LogsEvery message sent, voucher posted and login recorded with the time and who did it. Kept for the period you set.Continuous
Rate limitsA ceiling on messages an hour and actions a minute for each assistant, set with you.Always
Approval stepsMoney, prices and deletions wait for a named person. The assistant drafts, a person approves.Every time
Incident planA written plan: who is called, what is switched off, and what you are told and when. Rehearsed with the restore test.Reviewed every quarter
Data centreISO 27001-certified providers in India: Mumbai, Chennai or Bengaluru.Chosen once, written into the agreement

Standards named here: TLS for encryption while data travels, and ISO 27001 for how a data centre is run. The Digital Personal Data Protection Act, 2023 covers how personal data is handled. Ask us for the written incident plan before you sign.

For your technical teamEncryption, secrets, access, firewall, backups, patching, audit log, incident runbook
Encryption
TLS 1.2 or later everywhere, with HSTS on. Disk encryption on volumes and backups.
Secrets
Kept in the provider's secret manager, never in the repository.
Access
SSH by key only, no password logins. Two-factor on the cloud console, the code host and every admin panel.
Firewall
A host firewall that allows only the ports in use.
Backups
Nightly encrypted dumps to a second provider in an Indian region.
Patching
Dependency and operating-system patching on a schedule.
Rate limits
Per-assistant limits enforced at the gateway.
Audit log
Append-only.
Incident runbook
Written, with named contacts. Rehearsed every quarter alongside the restore test.

Ask us the hard questions

Bring the list above, or your own. We answer in writing and put the answers into the agreement. We reply within one working day.

Talk to us

hello@pakshitechnologies.com

Monday to Saturday, 9:30 am to 6:30 pm IST