Saathi Bot v1.0 Live — BYOK Multi-Provider RAGTry free
Enterprise Security & Trust Center

Built from the ground up for strict data isolation

When you connect your documentation to an AI platform, trust is paramount. Here is how Saathi Bot isolates, encrypts, and defends your data at every architectural layer.

Multi-Tenant Row-Level Security (RLS)

Every document chunk, vector embedding, and visitor conversation is stored in a multi-tenant PostgreSQL database protected by native Row-Level Security (RLS) policies. Queries enforce a mandatory bot_id partition filter before vector math occurs. Organization A can never query, infer, or leak Organization B's data.

CREATE POLICY tenant_isolation ON document_chunks FOR ALL USING (bot_id IN (SELECT id FROM bots WHERE org_id = current_org_id()));

Zero-Server Key Vault Guarantee

With our Bring-Your-Own-Key (BYOK) architecture, you maintain direct control over your AI model accounts. When you test in Playground mode, your private LLM API keys (Google Gemini, Groq, OpenAI, Claude, DeepSeek) are stored strictly in client-side device memory and are never written to our central PostgreSQL database.

Zero plain-text credential persistence in DB logs

Origin Whitelisting & CORS Defense

Embeddable widgets can be restricted to specific authorized domain hostnames and wildcard subdomains (*.yourcompany.com). Inbound chat requests verify HTTP headers and refuse to serve chat tokens to unauthorized origins, preventing widget hijacking and token theft.

Shadow DOM CSS encapsulation + Origin verification

Crawler SSRF Shielding

When our web ingestion engine indexes your public documentation, all URLs undergo pre-flight DNS resolution against our hardened blocklist. Any domain resolving to loopback addresses, internal RFC 1918 subnets, or cloud metadata endpoints (169.254.169.254) is dropped immediately before network calls begin.

Automated denial of private subnets and metadata IPs

Encryption & Transport Standards

In Transit

TLS 1.3 / HTTPS

All client-to-server traffic is forced over encrypted HTTPS. HTTP requests are redirected permanently (301).

At Rest

AES-256 Storage

Underlying PostgreSQL volumes and binary storage buckets are encrypted using industry-standard AES-256 block ciphers.

Authentication

Signed HS256 JWTs

Visitor sessions are cryptographically signed using HS256 secret keys, preventing session spoofing and unauthorized replay.

Responsible Vulnerability Disclosure

We welcome independent security researchers to inspect our platform. If you discover a security vulnerability or potential tenant isolation weakness, we commit to prompt verification, triage, and resolution.

Email our direct security triage inbox with proof-of-concept steps:

security@saathibot.com

Submit Security Report