Security & trust
A trusted IT partner, verified in your own systems.
We build and run AI and software inside your environment, through your identity provider, under your keys and in view of your audit log. Every control on this page is written into the contract, and every action leaves a record you hold.
- Your approval
- Every session requested, time-boxed and closed
- Your keys
- Encryption and credentials stay in your vault
- Your record
- Every action lands in your own audit log
Written into every contractThe numbers we are held to, and you can check each one.
- 0standing access. Every session is requested, approved by you and closed on time.
- 0keys in our hands. Encryption keys and root credentials stay in your vault.
- 0models trained on your data, by us or by any provider we call.
- 100%of sessions and agent actions recorded in your own audit log.
The controls
Every control, and where you check it.
A third party was involved in 48% of breaches in Verizon's 2026 Data Breach Investigations Report. Each control below closes a door a partner could leave open, and each one leaves its evidence in your own systems.
Our engineers reach your systems the way your own staff do: through your identity provider, and only for as long as the work needs.
| The control | Check it in | Written into |
|---|---|---|
| Named accounts in your identity provider, with SSO and phishing-resistant MFA. No shared logins. | Your identity provider's sign-in log | Security schedule |
| Just-in-time sessions: least privilege, scoped to the system in hand, approved by you, closed on time. | Your cloud audit trail: CloudTrail, Azure Activity Log or Cloud Audit Logs | Access terms |
| Emergency access agreed in the runbook ahead of time. Using it alerts your team and is reviewed after. | Your alerting and on-call history | Runbook |
| Revocable by you at any moment, in one step, without touching the systems that run. | Your identity provider | Termination terms |
AI under control
AI agents act inside the lines you draw.
An agent is a new kind of worker in your systems, and it works under the same rules as our engineers: named, scoped, approved and recorded, with a person deciding anything that matters.
- Models you chooseEnterprise endpoints with zero data retention, or open-weight models running inside your own environment.
- Never trained on your dataBy us or by any provider we call. The DPA says so in writing.
- Tools on an allow-listEach agent holds scoped credentials for named tools, and nothing more.
- People approve what mattersPayments, deletions, messages to customers and anything else you name wait for a person.
- Tested before and after releaseEvaluations and red-team runs against the OWASP Top 10 for LLM and agentic applications, mapped to NIST AI RMF and ISO/IEC 42001.
The threat model and controls a CISO should require of AI agents
- actor
- support-agent v3.2
- tool
- refunds.draft · on the allow-list
- input
- order 44817 · customer [redacted]
- policy
- within the refund limit · passed
- approval
- required · approved by your team
- model
- private endpoint · zero retention
- output
- refund draft 44817 · not yet issued
- record
- hash-chained · in your audit log
Written where your auditors already look, next to every human session.
The engagement
From the first check to the hand-back, in writing.
Each step is scoped and approved in writing before the next begins, and the way out is agreed before the way in.
Verify us
The company is on India's public register. Check the CIN before we meet. CIN U62099RJ2025OPC105518
NDA
Signed before any technical detail is shared, on your paper or ours.
Your review
Your questionnaire, SIG Lite, CAIQ, AI-CAIQ or your own, returned with our policies and third-party list.
Architecture
Where your data flows, who and what touches it, and which model sees what, drawn for your system.
Contract
The DPA with EU SCCs or the UK IDTA where your data needs them, the security schedule, notice terms and audit rights.
First access
Scoped, approved by you and recorded in your audit log. Every session after it runs the same way.
Hand-back
Code, keys, runbooks and records stay with you. Our access is revoked and working copies are returned or destroyed, confirmed in writing.
- Legal entity
- DigyAi Technologies (OPC) Private Limited
- CIN
- U62099RJ2025OPC105518
- Registered office
- Sardarshahar, Rajasthan 331403, India
- Security contact
- contact@digyai.com security.txt
- Verify the company
- Verify on mca.gov.in
Keep exploring
From the first session to a company that runs on intelligence.
Insights on security and governance
- AI Agent Security: The Threat Model and Controls a CISO Should Require
- AI Agent Guardrails: 8 Controls That Hold Up in Production
- EU AI Act Compliance in 2026: What the Omnibus Changed and What Is Due Now
Services that run inside these controls
Get in touch
Name the systems you would trust us with.
Write it as big as you imagine it.
20 answers, on the recordWhat security teams ask before granting access.
Choosing a partner
What makes an IT partner trustworthy?
Evidence you hold yourself. A trusted IT partner works through your identity provider, under your keys and in view of your audit log, so every session and change can be checked in your own systems; it writes each commitment into the contract; and it can be verified on a public register. Reputation and badges help, and none of them replaces a record you can read.
What are the biggest risks of handing systems to an outside partner?
Standing access, data copied outside your control, code you do not own and an exit nobody planned. Verizon's 2026 Data Breach Investigations Report found a third party involved in 48% of breaches. Each risk has a control: access that is requested, approved and closed; data processed only in your environment; IP assigned on creation with the repository in your organization; and a hand-back agreed before the work starts.
What security measures should an outsourcing provider use to protect sensitive data?
At least these: named accounts through your SSO with phishing-resistant MFA, just-in-time and least-privilege access, encryption with keys you hold, no production data on laptops, masked data outside production, secret and dependency scanning, an SBOM with every release, tested backups, and every action logged where you can read it. Every one of them is on this page, with where you check it.
Access and data
Who at DigyAi can see our production data?
Only the engineers named for your work, through access you grant for a task and a window, and can revoke at any moment. Each session runs through your identity provider and is recorded in your own audit trail, so you can see who reached what, when, without taking our word for it.
Is our data used to train AI models?
No. We never train on your data, and every model provider we call is contracted and configured so it does not either: enterprise endpoints with zero data retention, or open-weight models running inside your environment. It is written into the data processing agreement.
Which AI providers see our data?
Only the provider named in writing for your work, listed among the third parties we return with your questionnaire, called on an enterprise endpoint with zero data retention. Where nothing may leave your perimeter, open-weight models run inside your own environment and no provider sees your data at all.
How do you keep AI agents under control?
The same way as people: named, scoped, approved and recorded. Each agent holds credentials for an allow-list of tools, anything consequential waits for a person, and every action is written to your audit log with its inputs, decision, approver and result. Agents are tested against the OWASP Top 10 for LLM and agentic applications before release and after.
Code and ownership
Who owns the source code in an outsourced project?
You do, from the moment it is written. Our agreement assigns all work product to you on creation, worldwide and permanently: the code, and also the prompts, evaluation sets, vector indexes and any fine-tuned weights. No clause lets anyone hold delivered work back.
Who owns code generated by AI?
You do, by contract. The assignment covers all work product however it was written, including code drafted with AI assistants, and that code sits in your repository from the first commit, reviewed by an engineer before it merges.
Should the client own the repository during development?
Yes, and with us it does from the first commit. The repository lives in your GitHub or GitLab organization, and we work inside it as collaborators. The cloud accounts, billing and root credentials are yours too.
What happens to our code and data when the engagement ends?
Everything stays with you, and our access closes. The hand-back is agreed at the start: code, infrastructure as code, keys, runbooks and records are already in your systems, working copies are returned or destroyed, and you receive written confirmation. Your systems keep running exactly as before.
Your review
Will you complete our security questionnaire?
Yes. Send your SIG Lite, CAIQ, AI-CAIQ, AI vendor questionnaire or your own, and we return it with our policies, the list of third parties that would touch your data and a data-flow drawing for your system. Answering it before any access keeps procurement moving.
What should an AI vendor security questionnaire ask?
Where the data goes and who can see it; whether it trains any model; which model providers are used and on what retention terms; how agents are limited and who approves their actions; how outputs are tested and red-teamed; what is logged and where; and who owns the prompts, indexes and weights. This page answers each of them for DigyAi.
Will you sign our NDA and DPA?
Yes, before any technical detail is shared. We work from your paper or ours, add the EU standard contractual clauses, the UK IDTA or the UK Addendum where your data requires them, and incident notice runs on the terms of your DPA, in writing.
What should a data processing agreement include?
The subject, duration, nature and purpose of the processing; the types of data and people involved; the processor's duties on security, confidentiality and assistance; the approved sub-processors and how changes are notified; breach notice terms; audit rights; international transfer safeguards such as SCCs; and return or deletion at the end. Ours covers each, and your legal team is welcome to strengthen any of it.
Do you hold SOC 2 or ISO 27001 yourselves?
Our work runs inside your environment, so the controls your auditor already tests are the ones that govern us. We do not hold a separate certificate of our own. The practice that meets your SOC 2, ISO 27001, ISO/IEC 42001, HIPAA or GDPR controls is written into the contract, and its evidence sits in your systems, where your auditor can check it.
How do you support GDPR, the EU AI Act, DORA and HIPAA?
By working inside your controls and putting what each regulation asks of a supplier into the contract: a GDPR Article 28 DPA with transfer clauses, the information your DORA register of information needs along with audit and exit terms, a business associate agreement where HIPAA applies, and for the EU AI Act the documentation, logging and human oversight your use case requires.
The company
How do we verify the company is real?
DigyAi Technologies (OPC) Private Limited is registered with India's Ministry of Corporate Affairs under CIN U62099RJ2025OPC105518. Search the company master data on mca.gov.in with that number; the registered office and directors are public record.
What if an engineer leaves mid-project?
Their access is removed and logged the same day, and the work carries on. Everyone on your work is named in the proposal, a change needs your written approval, and the code, decision records and runbooks live in your repository from day one, so the knowledge stays in the system.
How do we report a security issue to DigyAi?
Write to contact@digyai.com with "Security" in the subject line; the same contact is published in our security.txt file at /.well-known/security.txt. You get a reply within one business day.
Not answered here? Two lines are enough.
Ask your own question