Our approach
Security is foundational to XDrop AI: the platform holds confidential deal, legal, financial and board documents, so we design for the principle that a tenant's data is never exposed to another tenant. This page describes the measures we implement.
Tenant isolation and access control
Authorisation-layer isolation. Every record carries a workspace boundary, and every request resolves the caller's workspace membership and role before any data is returned. Document reads are scoped to the caller's active workspaces; document sets handed to the AI are filtered to what the caller may read.
Tested, not asserted. The isolation boundary is covered by an automated regression suite (anonymous access, privilege escalation, cross-tenant reads, storage-key masking, and the legacy grant path), so a regression fails a test rather than leaking data.
Explicit sharing only. Access across workspaces happens only through deliberate sharing by an authorised user, never by default.
Role ladder. Access to a boardroom follows a cumulative role model (view → comment → ask-AI → edit → manage → owner).
Permission-aware AI. The AI answers only from documents the requesting user is permitted to access.
NDA gating. Boardroom owners can require a per-boardroom NDA before access is granted, and can time-limit or revoke access.
Platform administration access, and its audit trail. A small number of authorised Company personnel can reach tenant content through an internal administration console, for fault investigation, data recovery, lawful orders and abuse/security investigation. Access requires a separate credential, failed attempts are rate-limited per source address, and every action is written to an append-only audit log - the sign-in, each boardroom opened, and each document viewed, with NDA-gated documents logged under their own action so that access is separately visible. This is disclosed in Privacy Policy §6.
Authentication and sessions
Passwordless sign-in via one-time codes (OTP) delivered to email and mobile; we do not store account passwords.
httpOnly session cookies, so the session token cannot be read by client-side scripts.
Session management - users can view and revoke active sessions/devices.
Encryption
Data is encrypted in transit using industry-standard TLS between your browser, our APIs and our service providers.
Auditing and monitoring
Every AI query is audited - who asked, which documents were retrieved, and what was answered supporting accountability and investigation.
Infrastructure and sub-processors
The Service runs on cloud hosting and object storage located in India (Mumbai), and uses third-party AI, monitoring, payment and communication providers, each engaged as a Sub-processor under confidentiality and security obligations and processing data only on our instructions.
Every sub-processor is named, with its location and purpose, in Privacy Policy §6 - including which of them process data outside India, and what reaches them (§9). We publish the list rather than supplying it on request.
Data retention, backups and deletion
We retain data while your account is active and as required by law, maintain routine backups, and delete Customer Content within a reasonable period after deletion or account termination (subject to limited backup retention and legal record-keeping). See our Privacy Policy.
Incident response and breach notification
We maintain processes to detect and respond to security incidents and will notify affected users and the Data Protection Board of personal-data breaches as and to the extent required by the Digital Personal Data Protection Act, 2023.
Responsible disclosure
If you believe you have found a security vulnerability, please report it to business@xdrop.ai. We appreciate responsible disclosure and ask that you avoid accessing or modifying other users' data while testing.