Trust

Security is not a feature.
It's the substrate.

Bhashini.tech treats government data with the seriousness it deserves — sovereign, encrypted, refusal-first, and audit-clean by default.

Aligned withMeitY GIGW 3.0WCAG 2.1 AADPDP Act 2023SOC 2-readyISO 27001 controls

India-first hosting

Deployable on MeghRaj, NIC, or approved on-prem environments — never off-shore by default.

Row-level security

Every row scoped by department, role, and language. Officers only see what they should.

Encryption in transit & at rest

TLS 1.3, AES-256, and Aadhaar-safe field-level protection on sensitive columns.

GIGW & WCAG 2.1 AA

Government web-standards and accessibility from day one — not retrofitted.

Refusal-first AI

If a query has no grounded source in your corpus, the system refuses. No hallucinations.

Audit trail for RTI

Every query, translation, and source citation is signed, timestamped, and logged.

Controls that map to your review checklist

Identity & access

  • SAML / OIDC SSO
  • Department + role-based RBAC
  • Session and API key expiry
  • Optional Aadhaar-linked officer sign-in

Data handling

  • No training on your corpus, ever
  • PII redaction pipeline before embedding
  • Configurable retention windows
  • Encryption keys in your KMS

Operational assurance

  • SOC2-ready pipeline & controls
  • Signed audit logs for RTI review
  • Quarterly penetration testing
  • Documented incident response

Answers your security team will ask

Does any document leave our servers?

No. Ingestion, embeddings, retrieval, and generation all run inside your deployment perimeter. Nothing is uploaded to a third-party cloud unless you explicitly opt in.

How do you prevent hallucinated answers?

The engine refuses to answer any question that cannot be grounded in an ingested chunk. Every response ships with a page + paragraph citation the officer can open in one click.

Who can see what?

RBAC + row-level security scope every read by department, role, and even language. An officer in one district cannot see another district's queries or drafts.

What about accessibility?

The kiosk meets WCAG 2.1 AA — high-contrast mode, dyslexia-friendly typography, voice-first interaction, and full keyboard navigation.

Editable trust statement

This page is maintained by Bhashini.tech.

It describes the controls, practices, and architecture Bhashini.tech ships by default. It is not an independent certification. For a shared-responsibility matrix or a DPA tailored to your department, reach out and we'll send the latest packet the same day.