Skip to content

Is it safe?

Yes — Hydra is built to be pointed at a live Frappe Desk. It acts only as you, shows you a plan before it changes anything, checks its own work, and logs every action. One condition: run it on a development site.

IMPORTANT

Use Hydra on a development or sandbox site, not production. It's the site owner's responsibility to connect Hydra to a non-production site. Need it on production? The Enterprise plan adds that — with BYOC / on-prem, your own LLM keys, and SOC 2 / HIPAA.

It acts as you — never above you

Hydra works under your own Frappe Desk login. If your account can't see or change something, neither can Hydra. It can't give itself extra access.

You approve before anything changes

In Plan mode, nothing happens until you click Proceed — and you see the full plan first. Just want to look around with zero risk? Ask mode can't change a thing.

It checks its own work

Before saving an automation, Hydra safely test-runs it. If it would error, it's fixed or dropped — a broken script never lands on your system.

Everything is on the record

Every action is logged: what Hydra did, to which record, when. Your team can review the full history anytime, and sensitive values (passwords, salaries, bank details) are hidden in the log.

Your data stays yours

Hydra only reads what your request needs — it never bulk-exports your data. Your records stay in your own Frappe Desk; only your chat messages, the specific records a request touches, and the related tool-call metadata (what Hydra looked up to do the job) are sent to the AI service to do the work.

No surprise bills

Usage is measured in credits — a question costs about 2, a full build about 15. You can always see how much you have left, you get a heads-up near the limit, and Hydra pauses if you reach it — no overage, no quietly running up a bill.

Next