Trust center

Compliance by architecture.

Most vendor-risk questionnaires ask how we protect your data. Our answer: it never leaves your building. Here is how the standard questions resolve.

DPDP Act 2023

Built around the DPDP Act, 2023.

Under the Digital Personal Data Protection Act, your organisation remains the sole Data Fiduciary — on-premise BodhAI introduces no data processor for your documents, no cross-border transfer, no consent chain. Most DPDP vendor questions are moot by construction.

Data-subject requests and DPDP grievances are routed through the contact form — select “Security” as the purpose. We do not operate a separate DSAR portal or a named grievance officer at our current scale; every request reaches the team directly.

Data-handling matrix
Data classWhere it livesWho can read itReaches BodhAI cloud?
Documents & extracted contentYour serverYour users, by groupNEVER
Chat, queries & answersYour server (SQLite)Your users, by roleNEVER
Knowledge graph & embeddingsYour server (Qdrant)Your users, by groupNEVER
TelemetryOur cloudBodhAI opsYes — hashed queries, counts, org ID only
Account & licenseOur cloudBodhAI opsYes — admin email, org name, plan, seats
Billing & GST invoicesOur cloud + RazorpayBodhAI ops · RazorpayYes — required for invoicing
Certifications roadmap

We hold no certifications yet — we'd rather tell you that plainly than imply otherwise. The path:

ISO 27001 planned
SOC 2 Type II after ISO
DPA template drafting
Security whitepaper drafting