Shodh
Product · Security and Deployment

One organisation's run stays one organisation's.

How Shodh is isolated, where it can run, and what we do not claim.

Engine runs on
Shodh's infrastructure
Provider keys
Shodh's provider accounts
Models
Shodh's default routing, overridable per agent
Isolation
Row-level, bound per run

The engine is identical in all three. Moving between them is configuration, not a rebuild.

Bound per run

A run carrying the wrong organisation is rejected outright. Reads and writes are scoped to both.

Three places to run it

Shared core, a dedicated instance under your own keys, or inside your own network.

Where material goes

Questions and documents reach the model and search providers your deployment configures. Which ones is your decision.

No certification held

No SOC 2, no ISO 27001, and we will not imply otherwise. DPDP work is in progress.

In this layer
  • Per-run organisation binding
  • Tenant-scoped reads and writes
  • Row-level security
  • Keys held server-side
  • Shared, dedicated or in-network
  • Published data-rights process

Everything here describes how the system is built, and can be walked through with your team.