We Secure the Platform We Run
And We Show Our Working
Technical Dost builds AI automation for Indian businesses — WhatsApp messaging, lead capture, invoicing. That platform holds our customers’ business data, so securing it is engineering work we do on our own systems: code review, dependency triage, abuse detection, patch validation, and incident readiness.
Found in our own code
Review, dependency advisory, or a report from you
Triaged for reachability
Model-assisted, reviewed by a person
Patched, then validated
Fix checked against the defect it was written for
Scope is the platform we operate. Nothing reaches production on the basis of unreviewed model output.
Udyam registered enterprise
Raipur, Chhattisgarh
Registered in
Coordinated disclosure
Security contact
Defensive Work, Named Precisely
Five workflows, each against a system we own and operate, described in operational terms rather than marketing terms.
What We Refuse
Stated up front, because a defensive claim means little without a stated limit.
- Development, refinement, or packaging of ransomware or any payload whose purpose is to deny a victim access to their own systems or data
- Mass or indiscriminate data exfiltration from any system
- Testing, scanning, or analysis of any system we do not own or operate, absent written authorisation from the party that does
- Building or operating command-and-control infrastructure for use against third parties
- Developing techniques whose primary purpose is evading security controls or forensic detection for an attacker's benefit
- Use of our own messaging and automation infrastructure for spam, phishing, or impersonation, whether by us or by a customer
- Surveillance, tracking, or intrusion targeting private individuals, journalists, or civil-society organisations
Why the Boundary Is Auditable
The mechanisms that would surface misuse if it happened.
Scope limited to what we operate
Defensive work is performed against the Technical Dost platform, its dependencies, and its infrastructure — systems we own and run. Assessing anything outside that boundary requires written authorisation from its owner, and without that authorisation the work does not happen.
Named human accountability
A named individual is accountable for security decisions on the platform. Model-assisted analysis is reviewed by a person; no finding is acted on and no change reaches production on the basis of unreviewed model output alone.
Review before deployment
Security-relevant changes are reviewed before they ship rather than after. A patch is only considered done once it has been checked against the defect it was written for, which is why patch validation is listed as work in its own right.
Least-privilege production access
Access to production systems and customer data is scoped to what the task requires and held by as few people as the work allows. Credentials are not shared between environments, and access is reviewed when someone's role changes.
Customer data minimised in model context
Where analysis is model-assisted, customer messaging content and personal data are excluded or redacted unless the analysis genuinely requires them. The default is to work against code, configuration, and schema rather than live records.
Coordinated disclosure by default
Defects we find in third-party software are reported to the vendor and disclosed on a coordinated timeline. We do not sell, trade, or stockpile vulnerability details. Reports about our own systems are handled under our published disclosure policy.
Verified Access, Through the Front Door
Where our work needs capability that providers gate behind verification, we apply through their program and operate within its terms. We do not attempt to circumvent a provider’s safeguards.
Cyber Verification Program (CVP)
A free, application-based program that lifts default restrictions on high-risk dual-use cyber tasks — penetration testing, exploitation reasoning, privilege escalation and lateral movement analysis — for verified organisations with a legitimate defensive purpose. Prohibited-use categories are not unlocked by it.
Official intakeTrusted Access for Cyber (TAC)
An identity- and trust-based program granting verified defenders enhanced cyber capability, scoped in tiers to defensive use cases and subject to ongoing monitoring.
Official intakeApplications go through each provider’s own intake, not through this site. What each reviewer checks
Found Something in Our Systems?
We respond within 72 hours, remediate and disclose within 90 days, and offer safe harbour for good-faith research.
The platform this protects
Technical Dost builds AI workflow automation for Indian businesses — WhatsApp messaging, lead capture, vernacular content, and GST invoicing. It handles customer conversations, contact records, and billing data, which is what the security work above exists to protect. The product is the reason for the practice, not a separate line of business.
Checking us out?
Legal identity, registration number, accountable personnel, and governance documents are collected on one page, each intended to be independently confirmable.
Organisation verification