Security

The posture as facts, including the honest limits. This is a private single-operator deployment engineered like a product, not a certified enterprise service — both halves of that sentence matter.

Updated 2026-10-03. English reference · Overview in five languages · Machine-readable guide. What the * means.

Data protection

  • User files encrypted at rest (authenticated encryption); transport is HTTPS everywhere with HSTS.
  • Nightly backups are encrypted before leaving the node and stored off-site in Google Drive. A full database, uploads, music, vault, and key restore was verified on 2 September 2026.
  • Cached document text is stored no more readably than the file it came from.

Access control

  • Real accounts with refresh-token sessions; login rate limiting; per-user storage, daily-token, and spend quotas with a circuit breaker.
  • File downloads use short-lived, download-scoped tokens — never the access token in a URL.
  • Documents are owner-scoped; sharing is an explicit per-document grant; thread attachments are visible to thread members only.

Acting safely (the ladder)

  • Every action follows the authority ladder: observe → advise → draft → act with confirmation → act & report → act silently. Since September a clear, private, low-risk request you make runs directly: a note, a list, a reminder, a file you asked for, your own lights. Sending a message, sharing, changing a memory, admin changes and anything the server rates sensitive or risky wait for your yes, and an ambiguous private request gets a separate, tool-free review first. Ownership, recipient, budget and capability checks stay on the server either way. A conversational action leaves a receipt with your account; admin requests go to the tamper-evident audit log.
  • Prompt-injection posture: content fetched from the outside world — web pages, email — is treated as data, never as instructions: it can never authorize an action, and outward-facing or sensitive writes keep their confirmation precisely because assistants that act on injected instructions are a known failure class.*
  • Sensitivity is classified the moment data arrives, so disclosure rules and provider routing can hang off it.*

Operator access

Support access is a recorded, revocable grant — and during the beta it starts on for each account unless its owner switches it off, shown in the account with a one-tap opt-out, until Sathi runs reliably without the operator looking; every admin request lands in a tamper-evident audit log. Running the deployment (quotas, suspensions, deletion on request) never requires reading anyone's content. See /privacy for the member-facing view of the same rule.

Honest limits

  • Enforcement of operator separation is application-level and audited, not yet cryptographic — the operator still runs the database. Cryptographic separation is planned for the first community the operator does not run.*
  • No SOC2 / ISO certification, no external pen test yet — a compliance program is a public-phase cost, deliberately.
  • The temporary Google Drive backup connection uses rclone's shared OAuth client. It must be replaced with a Sathi-owned client before launch so a shared quota or client retirement cannot stop nightly backups.
  • Voice audio and reply text can reach the configured speech providers. Self-hosted speech is a direction; a private archive does not imply local-only processing. The processing boundary is described on Trust.

Reporting

Security findings are welcome at security@sathi.ai; the mailbox reaches the operator directly, and a redacted proof is enough. Good-faith research against your own account's data is appreciated; other members' data is off-limits. The same contact is published in machine-readable form at /.well-known/security.txt (RFC 9116).