Security
Security at DhiTantra.
Legal and compliance workflows demand absolute, non-negotiable confidentiality. DhiTantra is engineered from the ground up so that tier-1 law firms, corporate legal departments, and enterprise organizations can deploy legal automation workflows on high-stakes, sensitive matters with the ironclad controls expected from modern infrastructure.
Encryption & Infrastructure
- Industry-Standard Encryption at Rest (e.g., AES-256) for all stored documents and user data.
- Modern Encrypted Transport Protocols (e.g., TLS 1.2+ / 1.3) for all API and web traffic.
- Infrastructure & Residency: Core databases and hosting infrastructure are localized in secure Indian cloud regions. Where specialized third-party AI models are utilized, data is transmitted via secure, encrypted enterprise APIs with strict zero-retention and zero-training policies.
Identity & Access Management
- Role-Based Access Control (RBAC) ensuring strict data governance.
- Workspace Logical Isolation: Complete separation of user and enterprise environments.
- Secure Authentication protocols with session timeouts and monitoring.
Enterprise AI Security
- Prompt Isolation: Query inputs are isolated and never bleed across sessions.
- Zero Cross-Customer Data Leakage: Architecture designed for multi-tenant physical security and single-tenant logical isolation.
- Training Wall: No customer data, uploaded files, or workspace content is ever used for shared model training without explicit contractual consent.
Operational Security & Compliance
- Comprehensive Audit Logging for enterprise administrators.
- Automated encrypted backups with strict retention policies.
- Continuous threat monitoring and incident response readiness.
- Compliance Roadmap: Our security program continues to evolve alongside rigorous customer, regulatory, and DPDP requirements.
Reporting a Vulnerability
Email security@dhitantra.ai with a clear description and reproduction steps. Please give us reasonable time to address issues before public disclosure.