Saathi Bot v1.0 Live — BYOK Multi-Provider RAGTry free
Zero-Knowledge BYOK Privacy Architecture

Cookie & Local Storage Privacy Vault

At Saathi Bot, your data sovereignty is non-negotiable. Custom LLM credentials (OpenAI, Gemini, Claude, Groq, DeepSeek) are never stored in our central PostgreSQL database or backup snapshots. They reside securely in your browser’s local cryptographic sandbox.

DB Key Storage

0 Bytes

Never saved to disk

RAM In-Flight TTL

0 Seconds

Ephemeral streaming

Payload Cipher

TLS 1.3 + HS256

Signed JWT validation

Local Keys Active

...

In this browser session

Hardware & Browser Isolation

Device Storage VaultLoading...

Inspect, export, toggle persistence modes, or wipe private LLM credentials stored on this computer.

Scanning browser local storage sandbox...
Audited Technical Ledger

Storage & Cookie Inventory

Every cookie, identifier, and client-side storage element utilized across the platform.

Key / IdentifierStorage LayerNetwork ScopeFunctional PurposeRetention
saathi_bot_key_<id>
LocalStorage / SessionStorageNever written to DatabaseStores your BYOK API keys (Gemini, OpenAI, Claude, Groq, DeepSeek) strictly inside your browser sandbox.User Controlled
saathi_storage_consent
LocalStorageClient Only (No Transfer)Remembers your cookie banner acknowledgment and telemetry consent preferences.1 Year
sb-*-auth-token
HttpOnly Secure CookieEncrypted via TLS to SupabaseMaintains authenticated dashboard session state with cryptographically signed JWT tokens.7 Days / Rolling
saathi_vid
LocalStorageAnonymous Visitor IDEnables continuous multi-turn chat memory across page navigation in the live embeddable widget.30 Days
Need to review or toggle tracking permissions again?
Cryptographic Isolation Proof

How Zero-Knowledge BYOK Protects You

Trace how your proprietary LLM API tokens travel through our runtime without ever touching persistent disks.

01

Client-Side Isolation

When entered in Bot Settings or Playground, your key is saved exclusively in your browser’s sandboxed storage. Our server-side database mutation deliberately strips the credential key from SQL writes.

Zero DB persistence
02

Ephemeral In-Flight RAM

During test streaming, the client transmits the key inside an encrypted TLS header (x-client-api-key). The server holds it in volatile RAM only for the duration of the streaming tokens.

Volatile heap execution
03

Zero Disk Logging Guarantee

Our application loggers, telemetry trackers, and AI invocation tables (ai_logs) are strictly banned from logging API keys. As soon as the SSE stream terminates, the memory is garbage-collected.

Instant garbage collection
Transparent Explanations

Frequently Asked Security Questions

Ready to deploy your grounded, zero-leak AI bot?

Connect your website URLs, plug in your paid LLM key, and embed in under 60 seconds.