Security & trust

Enterprise-grade care for your data.

Agastya handles your customers and their conversations, so security isn't a feature — it's the foundation. Here's exactly how your data is protected, who can access it, and the control you keep.

The essentials

Six commitments, in plain language

No jargon, no hand-waving — what we actually do with your data and why you stay in control.

🔒

Encrypted, always

All traffic is encrypted in transit (TLS) and data is encrypted at rest. Secrets and API keys are stored encrypted, never in plaintext.

🧱

Per-business isolation

Every business's customers, conversations and knowledge are strictly separated. Agastya only ever sees and discusses one customer's own details — never another's.

🎚️

You control every action

You choose exactly what Agastya may do — read-only lookups, or booking and ordering. Nothing is enabled by default; each capability is switched on by you, per integration.

🔗

Your systems, your keys

Integrations call YOUR endpoint with YOUR key. Customer actions flow into systems you own and control — not a black box. Revoke access anytime.

🇮🇳

India DPDP-aligned

Built for India's Digital Personal Data Protection principles: purpose-limited use, implied consent to reply on the channel a customer contacts you on, and honoring opt-outs.

🚫

Never sold, never leaked

Your data is never sold, never shared across customers, and never used to train third-party models. It's used only to run your support and improve your own agent.

How it works under the hood

Where your data lives and moves

  • Conversations and customer records are stored in a managed, access-controlled database with row-level security — reachable only by the server, never the public.
  • When Agastya acts in your systems, it sends a signed request to the single endpoint you configured, authenticated with your key. You decide which actions that endpoint accepts.
  • The AI reasons over your own website, documents and verified facts — grounded in your information, not guesses. It only states prices, policies and statuses your data confirms.
  • Payments are handled by the payment provider's rails — Agastya orchestrates and shares a link; it does not store card details.
  • Every customer can opt out in one tap; opt-outs are honored across all channels immediately.

Access & governance

Who can see what

👥

Only your team

Your dashboard is sign-in protected (passwordless magic links). Only the owner and invited team members can see your conversations, tickets and customers.

🗝️

Least privilege

Members see the queue; sensitive actions are owner-gated. Integrations run with the minimum access you grant, and can be turned off instantly.

🧾

Auditable

Every booking, ticket and AI action is logged against the conversation, so there's always a clear record of what happened and when.

Have a security or compliance question?

Tell us your requirements — data residency, DPDP, integration security — and we'll walk you through it.