Defensive security on the platform we operate

We Secure the Platform We Run
And We Show Our Working

Technical Dost builds AI automation for Indian businesses — WhatsApp messaging, lead capture, invoicing. That platform holds our customers’ business data, so securing it is engineering work we do on our own systems: code review, dependency triage, abuse detection, patch validation, and incident readiness.

UDYAM-CG-14-0131807

Udyam registered enterprise

Raipur, Chhattisgarh

Registered in

90-day policy

Coordinated disclosure

RFC 9116

Security contact

The boundary

What We Refuse

Stated up front, because a defensive claim means little without a stated limit.

Refused without exception
  • Development, refinement, or packaging of ransomware or any payload whose purpose is to deny a victim access to their own systems or data
  • Mass or indiscriminate data exfiltration from any system
  • Testing, scanning, or analysis of any system we do not own or operate, absent written authorisation from the party that does
  • Building or operating command-and-control infrastructure for use against third parties
  • Developing techniques whose primary purpose is evading security controls or forensic detection for an attacker's benefit
  • Use of our own messaging and automation infrastructure for spam, phishing, or impersonation, whether by us or by a customer
  • Surveillance, tracking, or intrusion targeting private individuals, journalists, or civil-society organisations
Controls

Why the Boundary Is Auditable

The mechanisms that would surface misuse if it happened.

Scope limited to what we operate

Defensive work is performed against the Technical Dost platform, its dependencies, and its infrastructure — systems we own and run. Assessing anything outside that boundary requires written authorisation from its owner, and without that authorisation the work does not happen.

Named human accountability

A named individual is accountable for security decisions on the platform. Model-assisted analysis is reviewed by a person; no finding is acted on and no change reaches production on the basis of unreviewed model output alone.

Review before deployment

Security-relevant changes are reviewed before they ship rather than after. A patch is only considered done once it has been checked against the defect it was written for, which is why patch validation is listed as work in its own right.

Least-privilege production access

Access to production systems and customer data is scoped to what the task requires and held by as few people as the work allows. Credentials are not shared between environments, and access is reviewed when someone's role changes.

Customer data minimised in model context

Where analysis is model-assisted, customer messaging content and personal data are excluded or redacted unless the analysis genuinely requires them. The default is to work against code, configuration, and schema rather than live records.

Coordinated disclosure by default

Defects we find in third-party software are reported to the vendor and disclosed on a coordinated timeline. We do not sell, trade, or stockpile vulnerability details. Reports about our own systems are handled under our published disclosure policy.

Model access

Verified Access, Through the Front Door

Where our work needs capability that providers gate behind verification, we apply through their program and operate within its terms. We do not attempt to circumvent a provider’s safeguards.

Anthropic

Cyber Verification Program (CVP)

A free, application-based program that lifts default restrictions on high-risk dual-use cyber tasks — penetration testing, exploitation reasoning, privilege escalation and lateral movement analysis — for verified organisations with a legitimate defensive purpose. Prohibited-use categories are not unlocked by it.

Official intake
OpenAI

Trusted Access for Cyber (TAC)

An identity- and trust-based program granting verified defenders enhanced cyber capability, scoped in tiers to defensive use cases and subject to ongoing monitoring.

Official intake

Applications go through each provider’s own intake, not through this site. What each reviewer checks

Found Something in Our Systems?

We respond within 72 hours, remediate and disclose within 90 days, and offer safe harbour for good-faith research.

The platform this protects

Technical Dost builds AI workflow automation for Indian businesses — WhatsApp messaging, lead capture, vernacular content, and GST invoicing. It handles customer conversations, contact records, and billing data, which is what the security work above exists to protect. The product is the reason for the practice, not a separate line of business.

Checking us out?

Legal identity, registration number, accountable personnel, and governance documents are collected on one page, each intended to be independently confirmable.

Organisation verification