Security

Last updated: March 6, 2026

Security matters a lot to us. This page explains how we protect your data, what we do to keep Saroya.ai secure, and how to report security issues if you find one.

Data Protection

We encrypt everything. Data sitting on our servers is encrypted with AES-256. Data moving between your device and our servers uses TLS 1.3. Encryption keys are managed through hardware security modules, and we rotate them regularly.

Encryption at Rest

AES-256 for all stored data - your training content, account info, AI models, everything.

Encryption in Transit

TLS 1.3 secures data traveling between you and our servers.

Key Management

Keys handled through hardware security modules with regular rotation.

Data Isolation

Each customer's data is cryptographically isolated. Your training data never mixes with anyone else's.

Infrastructure & Access

Our servers run in ISO 27001 certified data centers with 24/7 monitoring. We use firewalls, intrusion detection, and DDoS protection. Team members have to use multi-factor authentication, and we follow the principle of least privilege - people only have access to what they actually need for their job.

Daily backups happen automatically, and we have a disaster recovery plan in place. Not that we ever want to use it, but it's there.

Account Security

You can enable two-factor authentication on your account (we recommend doing this). Session tokens are encrypted and expire automatically. Passwords are hashed using bcrypt, and we'll notify you if we detect any suspicious login activity.

Payment Security

We don't store your full credit card information. Payment processing is handled by Dodo Payments, which is PCI DSS Level 1 certified - that's the highest level of payment security certification. They handle card tokenization, fraud detection, and 3D Secure authentication. Your card details never touch our servers.

AI Model Security

Your Digital Mind is trained in a completely isolated environment. There's no cross-contamination between users - your training data is NEVER used to train anyone else's AI. You own your trained model and all your training data. Deployed models use authenticated APIs with rate limiting.

Here's the thing: Your knowledge, your expertise, your voice - it's yours alone. We never use your training data to train Digital Minds for other creators. Each AI is trained in isolation and remains your exclusive property.

Compliance

We comply with GDPR for EU users and India's DPDPA for domestic users. Payment processing meets PCI DSS standards through certified providers. We run annual security assessments and penetration testing by independent third parties.

Found a Security Issue?

If you discover a vulnerability, we'd appreciate hearing about it before you go public. Here's what we commit to:

We'll respond within 48 hours
We'll keep you updated on our progress
We'll credit you for the discovery if you want
We offer bug bounties based on severity

To report a vulnerability: Email security@saroya.ai with the details. Please give us time to fix it before disclosing publicly.

If Something Goes Wrong

We have an incident response plan. Here's what happens if there's a security incident:

Detection: Our monitoring systems alert the security team
Investigation: We figure out what happened and how bad it is
Containment: We stop any further damage
Notification: We inform affected users and authorities as required by law
Recovery: We restore systems and do a post-incident review

Data breaches: If personal data is involved, we'll notify affected users as quickly as possible and in compliance with legal requirements, including GDPR's 72-hour rule.

Questions?

For security stuff or vulnerability reports: security@saroya.ai