
Read-Only MCP & PDPA Compliance
Connect enterprise systems to AI with absolute confidence: zero data leaks, zero risk of data mutation.
For CTOs, CIOs, and legal counsel, the primary blockers to AI adoption are data integrity and compliance with privacy regulations such as the Personal Data Protection Act (PDPA). Thara MCP's architecture is engineered from the ground up to eliminate these risks entirely.
Read-Only Architecture by Design
Thara MCP operates as an architectural "one-way mirror." The MCP tools we deploy contain no mutations, updates, insertions, or deletion endpoints whatsoever.
Even if an AI misunderstands an inquiry or a user enters a strange prompt, Thara lacks the technical capability to alter live records in your ERP, PMS, or accounting database. Data integrity remains 100% guaranteed.
- Zero possibility for AI to alter prices, modify inventory, or manipulate ledgers.
- Enforced database-level user credentials with SELECT-only privileges.
- Your underlying system remains the untouched single source of truth.
Full Compliance with Thailand's PDPA
Thara adheres strictly to Data Minimization and Purpose Limitation principles under PDPA. We never scrape or copy entire database tables into third-party storage.
Only the specific numerical facts and statistics required to answer a prompt are retrieved. Furthermore, all AI models communicate via commercial enterprise APIs with Zero Data Retention agreements — your enterprise data is never used to train public foundation models.
- Data Minimization: Only summarized metrics needed for the specific answer are fetched.
- Configurable Masking & Anonymization: Automatically filters, masks, or anonymizes Personally Identifiable Information (PII) like national ID numbers or phone numbers, as well as custom sensitive business fields designated by your organization, before reaching AI.
- Zero Retention: Your business operations data is never retained to train public AI models.
Role-Based Access Control (RBAC) & Audit Trails
Not all employees should see all data. Thara's security layer enforces granular role-based access permissions calibrated by department and seniority.
Every prompt, retrieved data point, and generated response is recorded in an immutable audit log, enabling full retrospective audits for IT and compliance teams.
- Branch managers only query their branch; C-level executives access group-wide aggregates.
- Finance queries financial ledgers; operations cannot access executive payroll figures.
- Comprehensive audit trails record timestamps, user IDs, queries, and accessed data fields.
On-Premise & Private Cloud AI Options
For organizations with stringent air-gap policies prohibiting data egress to external cloud environments, Thara supports self-hosted local foundation models (Private LLMs).
The entire AI stack operates entirely within your private infrastructure, keeping all network packets strictly on your internal network or VPN.
- Compatible with high-performance open-source models running on on-premise hardware.
- Inquiries and answers never traverse the public internet.
- Tailored for banking institutions, healthcare providers, and regulated enterprises.
Review security standards with Thara engineers
Book a 30-minute discovery call to evaluate security architecture and PDPA compliance for your organisation.