Security

How we protect what you share

Insurance advisors share their book with Pratibimb, and research teams share sensitive company context with Sarvada Intelligence. Protecting it is not a layer we added on top — it is built into how the products work.

Last updated: 14 July 2026

Encryption and access

Data is encrypted in transit and at rest using strong, industry-standard encryption, on managed cloud services built for handling business-critical data.

Access to production data is limited to the people who need it to run and support the service, and the team is small enough that this is a short list rather than a policy.

Every request into the product is authenticated. Web access is protected through a dedicated identity provider. WhatsApp messages are bound to the verified sender's number, and every incoming webhook is cryptographically signature-verified, so a message cannot be forged into someone else's account.

What our logs never contain

We keep detailed operational logs, because a service that holds someone's book has to be diagnosable when it breaks. Those logs are deliberately built so that they cannot leak the thing they are diagnosing.

We never write a customer's name, phone number, email, address, or the contents of a message or document into our logs. A phone number appears only as a one-way hash, which lets us trace a single conversation from end to end without ever storing the number itself. Inputs to our tools are redacted before they are recorded.

This is enforced in the code and covered by our tests, rather than left to the discipline of whoever writes the next log line.

Documents are data, never instructions

Our products read documents that we did not write, and anyone can put text into a document. A policy wording, a forwarded message, or a file name can contain text engineered to look like a command to an AI system.

Everything that arrives from outside — document contents, messages, tool results — is fenced and handled strictly as data. Our systems read it, quote it, and analyse it, and never carry out instructions found inside it. What the product is permitted to do is fixed, and no document can widen it.

Limits we build in on purpose

The strongest protection is a capability that does not exist. Pratibimb has no channel to an advisor's customers. It cannot message them, and this is not a setting that is switched off — the ability is not in the system. When a customer needs a reminder, Pratibimb prepares the message and the advisor sends it themselves.

In the same spirit, any action that changes an advisor's records is staged and confirmed before it is written, and money figures are computed in ordinary code rather than by an AI model, so that a plausible-sounding mistake cannot quietly become a saved number.

Your data is not our product

We never sell, rent, or broker your data, and we never share an advisor's book or their customers' details with an insurer, an agent, or another advisor. We are a software company, and we earn from software.

The full detail of what we collect, how we use it, and who processes it on our behalf is set out in our Privacy Policy.

Questions and reporting

If your organisation has specific security, data-handling, or procurement requirements, raise them with us at contact@sarvada.ai and we will answer them directly.

If you find a security issue, tell us at the same address and we will take it seriously and respond. We would much rather hear it from you than not hear it at all.

Ready to see Sarvada in action?

Open Pratibimb to run your book, or start a conversation with the team about Sarvada Intelligence.