Confidentiality first
Attorney-client privilege is not a feature flag.
Trust centre
Data residency in India. Encrypted in transit and at rest. One tenant boundary per customer.
Posture
Attorney-client privilege is not a feature flag.
People and services see only what they need.
Compromise of one layer does not cascade into the next.
Your data stays in India and does not cross regions without your instruction.
Encrypted in transit and at rest, on every service, without exception.
Every customer is its own tenant. Storage and retrieval stop at that line.
Controls
| Control | What we do | Status |
|---|---|---|
| Data residency | Customer content is stored and processed in India. | India |
| DPDP Act 2023 | Data handling aligned to the Act. Any record deleted on request. | Aligned |
| SOC 2 Type II | Controls mapped to the Type II criteria. Roadmap on request. | Aligned |
| ISO/IEC 27001 | Controls mapped to the standard. Roadmap on request. | Aligned |
| GDPR | Data processing agreement for customers with EU data subjects. | DPA available |
| Encryption | Encrypted in transit and at rest across every service. | In place |
| Model training | Your documents and matters never train a shared or public model. | Never |
| Control | What we do | Status |
|---|---|---|
| In transit | TLS 1.3, with strict HSTS at a one-year max-age. | TLS 1.3 |
| At rest | AES-256 on the document vault. Backups use customer-isolated keys. | AES-256 |
| Retrieval boundary | The vector index is keyed by tenant and case, so the Notebook cannot return another tenant's matter however the prompt is built. | Tenant scoped |
| Roles | Role-based access with at least three roles: admin, member and view-only. | 3 roles minimum |
| Sign-in | User ID and password, with SMS OTP as the second factor. | OTP second factor |
| Sessions | A session ends after 60 minutes of inactivity. | 60 minutes |
| Audit logs | Every matter read and write, every Notebook query, every counsel-spend approval, with actor, timestamp and tenant. Write once. | Kept 1 year+ |
| Production access | Engineer access to production is just in time, ticket gated and audited. | Ticket gated |
| Incident response | Triaged within 30 minutes. Customers notified within 72 hours under DPDP. | 30 min triage |
We describe our posture precisely. Until an external audit is complete, we say aligned. The second block above is scoped to Case Trail because that is where those controls are published. Ask security@lawyerdesk.ai for the current status of any framework, or for the LegiScore equivalent.
Data handling
Account details, the matter and property content you upload, anonymised usage metrics, and access logs.
Encrypted at rest in India, inside your own tenant boundary.
To run your workspace. Aggregated, non-identifying metrics improve reliability. Nothing else.
Any record, any time. All matter content goes within 30 days of termination unless law requires otherwise.
Matters are tenant-isolated with least-privilege access and full audit logging. In Case Trail, the AI Court Notebook cites only the documents placed in that matter, so privileged material never leaves its boundary or informs another client’s work.
No shared training, ever. Your documents and matters stay inside your tenant and are used only to serve your workspace. We do not pool client data into a common model.
Data residency is India by default and we do not move your data across regions without your instruction. Where you instruct a transfer, it relies on Standard Contractual Clauses and equivalent safeguards.
Access, correct, delete, restrict or port your personal information, and object to certain processing. Write to privacy@lawyerdesk.ai and we respond within 30 days.
Coordinated disclosure
Send the detail and the steps to reproduce to security@lawyerdesk.ai. One address, monitored by the engineers who can fix it.
One business day. You get a named owner and the triage outcome, then updates until the report is closed.
We credit responsible disclosure. Give us time to ship the fix before you publish, and test only against your own tenant.
We do not run a bug bounty. Good-faith research gets safe harbour, not a legal letter.
Read the security documentDependencies
We notify customers at least 30 days before adding or replacing a sub-processor that handles customer content.
Purpose and region for eachSecurity reviewLawyerDesk Advocacy Private Limited
We complete security questionnaires, share the audit roadmap, and answer in writing.
Questionnaires and DPA: security@lawyerdesk.ai