Skip to content
Shastra · Security

A governance product has to be worth trusting.

Pre-registration open

Shastra is intended to hold information about the most sensitive data your organisation has. That sets the bar for how it must be built, and for how carefully we describe it.

Principles

How we are building it.

  • Least data

    Governance state is not the same as a copy of your data. The design goal is to hold what is needed to govern, not to accumulate a second database of personal information.

  • Explicit access

    Integrations reach only what you configure. That is also why the Copilot has no independent access to your infrastructure.

  • Auditable actions

    Actions taken within Shastra are recorded, including those initiated through the Copilot.

  • Separation by tenant

    One customer’s governance state is isolated from another’s.

What we are not claiming

No certifications, no absolutes.

We do not hold a security certification for Shastra, and we are not going to imply one. Where we obtain independent assessment, we will name the assessment and its scope.

More detail

You will not find "military-grade", "unhackable" or "bank-level security" on this site. Those phrases mean nothing, and a security company using them is telling you something about itself.

Shastra is pre-launch. Detailed security documentation (architecture, data handling, sub-processors, retention) will be published as part of launch, and we would expect you to ask for it before trusting us with anything.

Our own systems

Found something in ours?

We publish a responsible disclosure policy for our own systems, because a company building disclosure infrastructure that does not accept reports itself would be absurd.

Early access

Shastra is pre-launch.

Pre-registration is open, and no pricing is published while the product is still being built.

Related: the DPDP Act explained · the Compliance Copilot