Bahlul SI · Security and data
Your data stays in Bangladesh, on a server you control.
Super Intelligence (SI) from Bahlul World runs where your rules say your data must stay: on a server in your building, or in a Bangladesh data centre under your own contract. Access follows your staff accounts, every question is logged, and nothing goes abroad unless you decide it should, in writing.
Your situation
New laws, old habits, and a question from the auditor
Your auditor, your regulator and your board now ask the same question: where is the data, and who can see it? The Personal Data Protection Act 2026 adds duties on consent, security and breach notice. Bangladesh Bank's cloud guideline keeps customers' financial data out of cross-border public or hybrid cloud without its prior approval. The Cyber Security Act 2026 adds duties for organisations named critical information infrastructure.
Meanwhile staff paste documents into public AI tools because they are useful, and every paste is a transfer abroad that nobody approved. Bahlul SI gives them the useful tool on a server inside the building, so the habit and the rule stop pulling in opposite directions.
Where the data sits
On the server and on your backup, nowhere else
Your documents, the index built from them, every question, every answer and the log stay on the server and on your own backup target. The server has no internet route, in or out. The optional alternative is a Bangladesh data centre under your own contract, with the same rule. Lab work at Bahlul World uses public, masked or synthetic documents only. Your real documents reach our demo server only in a workspace for your proof, on your premises by default, and are wiped when the proof ends, with the wipe recorded.
Access
Your accounts, your groups, your administrators
Staff sign in through your own directory, so joiners, leavers and role changes take effect in Bahlul SI the moment your administrators make them. Every passage in the index carries its access group, and an answer is built only from passages the person asking may see. Administrators use named accounts with keys, never shared logins, and reach the server only from your management network.
The log
Who asked what, kept where you keep your logs
Every question is recorded with the user, the time, the sources used and the model version. The log is append-only, copied to your own log system if you have one, and kept for as long as your policy says. Admin commands are logged too. If a fault needs a look at the log, we work from a masked extract and delete it when the fault is closed.
How the server is hardened
The baseline every server gets
- Operating system hardened to a recognised benchmark (CIS level 1), with only the packages it needs
- Full-disk encryption on the data drives, with the recovery key held by your named custodian
- A host firewall that denies by default: the user port open to staff, the admin port to your management network only, no internet route
- Named administrator accounts with keys, no root login, and every admin command logged
- Software images built and scanned in our lab and pinned by checksum; models from the publisher's official source, checksums recorded
- Nightly backups to your target, a weekly copy to offline media, and a restore test every quarter
- For banks, the controls mapped to Bangladesh Bank's ICT security guideline with your ICT security team
Before go-live
A penetration test by a certified testing firm
Before a new server goes live, we recommend a penetration test of it by a certified testing firm, scoped and authorised in writing, BDT 4.5 lakh a test. The firm tests; we fix what it finds, or you accept a finding in writing with an owner and a date. Bahlul World does not test its own work and call it secure, and never claims a certification for itself or for you. The same firm can test your wider estate under the Security add-on.
The founders abroad
What the founders abroad may see
Two of the three founders live outside Bangladesh, in Irving, Texas and in Toronto. They work on designs, code, sizing and test-bench scores, which need no client data. Most of the time they never see yours.
If a fault on your server needs one of them to look at real data, it happens only with your written consent, which names the people, the data, the purpose and the method, and lasts no longer than the engagement. The session is view-only, for a set time, and logged, and the data stays stored in Bangladesh. You can withdraw consent at any time, and access ends within one working day. You can ask for the access log. Until a partner law firm confirms how the Act treats viewing from abroad, we do not ask for access to identity numbers or biometric data at all.
The Personal Data Protection Act 2026
Your duties under the Act, and where Bahlul SI fits
The Personal Data Protection Act 2026, as we read it, asks for clear and revocable consent, notice to the person, technical and organisational security measures, breach notice to the regulator and to affected people, and rights of access, correction, erasure and portability. It limits sending certain identifiers and biometric data abroad. Organisations classed as significant data controllers must appoint a Chief Data Officer. Fines run up to BDT 25 lakh, and up to BDT 50 lakh for significant data controllers. The officer and fine sections start after an 18-month transition, around October 2027. The regulator is the National Data Management Authority.
We read the statutes in translation and sell readiness, not legal opinions: confirm every duty with your lawyer. The first phase of Bahlul SI uses policies, manuals and circulars, not personal data, so most of these duties do not start with it. When you want customer or citizen files in scope, the Data add-on runs a data protection readiness package first: six weeks, BDT 9.5 lakh.
Duty by duty
What the design gives you for each duty
| Duty, as we read the Act | What a Bahlul SI server gives you |
|---|---|
| Security measures | A hardened, encrypted server with no internet route, an append-only log and nightly backups |
| Knowing who saw what | Access through your own directory, and a log of every question with the sources it used |
| Transfers abroad | Nothing leaves the server by default; access from abroad only with your written, revocable consent |
| Breach notice | The log and the backups show what was touched; an incident response plan template comes with the Security add-on |
| Access, correction and erasure | Documents are added and removed by your document owner, and the index is rebuilt from what remains |
A reading, not legal advice. Confirm each duty with your lawyer before you rely on it.
The first step
Start with documents that hold no personal data
The SI briefing, half a day and BDT 1 lakh, uses ten sample documents that are not confidential. The SI proof, three weeks and BDT 5.5 lakh, runs on your premises on our demo server with the documents you choose, and the server is wiped at the end. The SI server set-up, from BDT 14 lakh, includes the hardening above and the acceptance tests for sign-in, access, the log, a power cut, offline running and a restore. Proposed 2027 prices, before VAT.
FAQ
Questions we are asked
Does any of our data go abroad?
No, not by default. The server has no internet route, and the founders abroad see your data only with your written consent, in a logged, view-only session that you can end at any time.
Is Bahlul SI compliant with the Act?
Compliance is yours to show, and nobody can promise it for you. What the server gives you is the evidence: where the data is, who saw what, and a hardened design. The Data add-on prepares the records the Act asks for.
What about our customers' or patients' files?
Not in phase 1. Start with policies, manuals and circulars. Bring personal data into scope only after a data protection readiness review and a decision by your named approver, and keep the server in your building.
Bring your security officer to the first call
Tell us where your data must stay and who must approve it. We will show you the design, the log and the consent form before you sign anything.