Bodhrik

Trust & Security

Before you trust us with your data or your AI adoption, here's exactly how we handle both.

We ask clients to trust us with sensitive business data and with decisions about AI adoption. This page answers, plainly, why that trust is warranted — not with a badge or a claim, but with specifics.

Why this page exists

Every AI vendor claims to take security and privacy seriously. Almost none make it easy to verify what that actually means in practice. We'd rather tell you exactly what we do — including where we're still working toward a certification, rather than implying we already have it — than give you a page full of confident-sounding claims with nothing behind them.

How we build and ship software securely

Security is built into how we develop software, not checked at the end.

Peer review before production

Every change goes through review by someone other than the person who wrote it before it reaches production.

Need-to-know access

Access to our systems and clients' environments is granted on a need-to-know basis and reviewed periodically — not left open by default.

Separated environments

Development, testing and live environments are kept separate, so changes are tested before they ever reach real data.

Dependency hygiene

Third-party components are kept up to date and screened for known vulnerabilities before release — not after something goes wrong.

How we handle your data

Used only for your engagement

We collect and use client data only to deliver the specific product, service, consulting engagement or talent placement you've engaged us for — never for any purpose beyond that without your knowledge.

Never used to train AI models

Your data is not used to train or improve Bodhrik's own AI products, or any third-party AI model, unless you've separately and explicitly agreed to that as part of a specific engagement.

Internal AI use stays internal

Where our team uses AI tools internally (for example, to accelerate drafting or analysis work), that use stays inside our own delivery process — it does not mean your data leaves our control to train someone else's model.

Retained only as long as necessary

Data is retained only as long as necessary for the engagement and applicable legal requirements, as set out in our Privacy Policy, and is securely deleted or anonymized after that.

Regulatory positions

India DPDP Act, 2023

Digital Personal Data Protection

We've built our data practices — for our website, our products, and how we handle client data across services and consulting engagements — around the principles of India's DPDP Act: collecting only what's necessary, using it only for the purpose it was collected for, and giving individuals a clear way to exercise their rights.

We've appointed a Grievance Officer to handle DPDP-related queries or concerns — details are in our Privacy Policy. Where we deliver DPDP compliance consulting to clients, we hold ourselves to the same standard we advise them to meet.

GDPR

EU / UK Data Subjects

Bodhrik is based in India and most client relationships are governed by Indian law. Where a client's business involves data subjects in the EU or UK, we're prepared to apply GDPR-aligned principles as part of that specific engagement — data minimization, a clear lawful basis for processing, respecting data subject rights, and appropriate safeguards for cross-border transfer.

Any specific GDPR commitments are set out in that engagement's own contract, not assumed to apply universally.

Sub-processors

We use a limited number of third-party providers to help deliver our services.

ProviderPurposeDetail

Microsoft Azure (Static Web Apps)

Website hosting

Hosts bodhrik.com and handles website traffic.

Google Analytics

Analytics

Understanding visitor behaviour on our site.

Bodhrik internal API

Contact form

Routes contact-form submissions — not an external vendor.

Google Workspace

Engagement tracking

Internal delivery tooling for client documents and assessments (Sheets, Drive, Apps Script).

See our Privacy Policy for the full sub-processor disclosure and data-handling detail.

Certification roadmap

Where we're working toward — stated honestly, not implied.

ISO/IEC 27001

Information Security Management

In progress

Targeted within the next 12–18 months.

60% of the way there

SOC 2 Type II

Service Organization Control

Under evaluation

Under evaluation as a future milestone — timeline to be confirmed as the company scales.

20% of the way there

Report a security concern

If you believe you've found a security issue or have a security-related question about working with Bodhrik, contact us directly.

security@bodhrik.com →

Incident response

If a security incident occurs, we follow a documented internal incident-response process that governs how we investigate, contain, and notify affected parties — including meeting India's regulatory reporting timelines as well as our own commitments to clients and individuals, as set out in our Privacy Policy.

We'd rather answer this honestly than impressively.

If something on this page isn't detailed enough to satisfy your due-diligence process, ask us directly — we'd rather have that conversation than have you guess.

Ask us a security question →