Security built for the
most private document
in your life.
Your financial life lives in DhanSafe. That's a responsibility we don't take lightly. Here's exactly how we protect it.
Five security pillars
How we keep your data safe.
AES-256 Encryption
The same encryption standard used by Indian banks, US defense, and password managers. Every document encrypted at rest and in transit. No exceptions.
Zero-Knowledge Architecture
Encryption keys live only on your device. Even DhanSafe engineers cannot read the contents of your vault. If we got hacked, your data is mathematical gibberish to the attacker.
Aadhaar-Gated Family Access
Family members can't just "log in" to your vault. They verify via UIDAI-issued Aadhaar OTP — the same protocol used for bank account opening — ensuring only the right person sees your data.
DPDP Act Compliance
Built ground-up for India's Digital Personal Data Protection Act, 2023. Data residency in Indian data centres, explicit user consent for every share, full audit log of every access.
ISO 27001 Aligned Controls
Annual third-party audits. Quarterly penetration tests. SOC2-aligned operational controls including least-privilege access for every team member.
Where your data lives
Your data never leaves India.
Mumbai & Hyderabad data centres
AWS Mumbai (ap-south-1) primary, Hyderabad backup. RBI- and DPDP-compliant infrastructure.
Tamper-evident audit trail
Every read, write, and share is logged. You can see who accessed what, when, and from where — in your own dashboard.
One-click data export
Download every document, every record, anytime. If you ever leave us, you take all your data with you.
Our commitments
Five things we will never do.
- closeSell your data. Not anonymised, not aggregated, not ever. Our entire revenue is from your membership.
- closeShow ads. The product surface stays clean — for you and your family.
- closeTake commissions on products. No insurance, no funds, no kickbacks.
- closeShare data with marketers. Period. We don't even use Google Analytics on logged-in surfaces.
- closeHold your data hostage. Cancel anytime, export everything in one click.
Security FAQ
Your concerns, answered.
What if DhanSafe gets hacked?add
Because of zero-knowledge encryption, even a successful breach of our servers would reveal only encrypted ciphertext to the attacker. Your decryption keys never leave your devices. We'd notify you within 72 hours per DPDP Act requirements.
What if DhanSafe shuts down?add
We're committed to a minimum 12-month wind-down notice. You can export every document any time. We also maintain a third-party escrow of customer data with an independent custodian.
Can government agencies request my data?add
We comply only with valid Indian legal orders. Where the request is for data covered by the DPDP Act, we challenge or narrow scope where possible, and notify you unless legally restrained.
How does AI document extraction work — does it expose data?add
Documents are processed inside our India-based encrypted pipeline. We use on-premise AI models — your data is never sent to OpenAI, Anthropic, or any third-party AI provider.
Do you do penetration testing?add
Yes — quarterly external pen-tests by a CERT-In empanelled vendor. Critical findings remediated within 7 days, full reports available on request to enterprise customers.
Security questions? Email service@dhansafe.com
Your data, locked tight. Your family, prepared.
verified_userBecome a DhanSafe member₹2,499/year · Recovery included · Cancel anytime
