Security & Trust

Enterprise-grade security
from day one

Daksh Search is built for companies that take data security seriously. Every architectural decision prioritises your data's confidentiality and integrity.

Core Principles

How we protect your data

🔒

Tenant Isolation

Each customer's data is stored in fully isolated collections. Your data is never co-mingled with other organisations' data. Strict multi-tenant separation at every layer.

🔐

Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Database credentials and API keys are stored in environment variables, never in code or logs.

🛡️

Zero Data Retention on AI

AI inference for search answers does not retain your queries or results. We use Anthropic's Claude API with zero data retention policy — your data is never used to train models.

🔑

Role-Based Access Control

Granular permissions ensure users only see documents they're authorised to access. Permissions from source systems (Google, Jira, etc.) are respected and enforced during indexing.

📋

Full Audit Logs

Every search, document access, admin action, and connector change is logged with user, timestamp, and tenant context. Exportable for compliance needs.

☁️

AWS Infrastructure

Hosted on AWS ap-south-1 (Mumbai) — within India's data residency requirements. VPC isolation, IAM least-privilege, and security group policies at the infrastructure layer.

🔍

Penetration Testing

Regular third-party penetration tests and vulnerability assessments. Critical vulnerabilities are patched within 24 hours of discovery.

📜

SOC 2 Compliance

We are working towards SOC 2 Type II certification. Our controls cover Security, Availability, and Confidentiality trust service criteria.

🇮🇳

India DPDP Act Compliant

Our data handling practices are designed to comply with India's Digital Personal Data Protection Act, 2023. Data residency within India available by default.

Responsible Disclosure

Found a security issue?

We take security reports seriously and will respond within 24 hours. Please report vulnerabilities responsibly to security@dakshapp.com. We do not pursue legal action against researchers acting in good faith.

Questions about security?

Our security team is happy to answer questions, provide documentation, or walk you through our architecture.

Talk to our team