A governance product has to be worth trusting.
Shastra is intended to hold information about the most sensitive data your organisation has. That sets the bar for how it must be built, and for how carefully we describe it.
How we are building it.
Least data
Governance state is not the same as a copy of your data. The design goal is to hold what is needed to govern, not to accumulate a second database of personal information.
Explicit access
Integrations reach only what you configure. That is also why the Copilot has no independent access to your infrastructure.
Auditable actions
Actions taken within Shastra are recorded, including those initiated through the Copilot.
Separation by tenant
One customer’s governance state is isolated from another’s.
No certifications, no absolutes.
We do not hold a security certification for Shastra, and we are not going to imply one. Where we obtain independent assessment, we will name the assessment and its scope.
More detail
You will not find "military-grade", "unhackable" or "bank-level security" on this site. Those phrases mean nothing, and a security company using them is telling you something about itself.
Shastra is pre-launch. Detailed security documentation (architecture, data handling, sub-processors, retention) will be published as part of launch, and we would expect you to ask for it before trusting us with anything.
Found something in ours?
We publish a responsible disclosure policy for our own systems, because a company building disclosure infrastructure that does not accept reports itself would be absurd.
Shastra is pre-launch.
Pre-registration is open, and no pricing is published while the product is still being built.
Related: the DPDP Act explained · the Compliance Copilot