Enterprise-grade care for your data.
Agastya handles your customers and their conversations, so security isn't a feature — it's the foundation. Here's exactly how your data is protected, who can access it, and the control you keep.
The essentials
Six commitments, in plain language
No jargon, no hand-waving — what we actually do with your data and why you stay in control.
Encrypted, always
All traffic is encrypted in transit (TLS) and data is encrypted at rest. Secrets and API keys are stored encrypted, never in plaintext.
Per-business isolation
Every business's customers, conversations and knowledge are strictly separated. Agastya only ever sees and discusses one customer's own details — never another's.
You control every action
You choose exactly what Agastya may do — read-only lookups, or booking and ordering. Nothing is enabled by default; each capability is switched on by you, per integration.
Your systems, your keys
Integrations call YOUR endpoint with YOUR key. Customer actions flow into systems you own and control — not a black box. Revoke access anytime.
India DPDP-aligned
Built for India's Digital Personal Data Protection principles: purpose-limited use, implied consent to reply on the channel a customer contacts you on, and honoring opt-outs.
Never sold, never leaked
Your data is never sold, never shared across customers, and never used to train third-party models. It's used only to run your support and improve your own agent.
How it works under the hood
Where your data lives and moves
- ✓Conversations and customer records are stored in a managed, access-controlled database with row-level security — reachable only by the server, never the public.
- ✓When Agastya acts in your systems, it sends a signed request to the single endpoint you configured, authenticated with your key. You decide which actions that endpoint accepts.
- ✓The AI reasons over your own website, documents and verified facts — grounded in your information, not guesses. It only states prices, policies and statuses your data confirms.
- ✓Payments are handled by the payment provider's rails — Agastya orchestrates and shares a link; it does not store card details.
- ✓Every customer can opt out in one tap; opt-outs are honored across all channels immediately.
Access & governance
Who can see what
Only your team
Your dashboard is sign-in protected (passwordless magic links). Only the owner and invited team members can see your conversations, tickets and customers.
Least privilege
Members see the queue; sensitive actions are owner-gated. Integrations run with the minimum access you grant, and can be turned off instantly.
Auditable
Every booking, ticket and AI action is logged against the conversation, so there's always a clear record of what happened and when.
Have a security or compliance question?
Tell us your requirements — data residency, DPDP, integration security — and we'll walk you through it.
