Security

Client confidentiality is the core of legal practice. These are the controls that protect it.

Every firm is walled off

Isolation is enforced by the database itself (row-level security), not just application code, and tested on every change.

Nothing reaches a client without approval

Case updates need an approval from the matter lawyer. Sending re-checks that approval, the client’s consent and WhatsApp’s rules at the moment of sending.

Strong sign-in

Two-step verification required for administrators and available to everyone, with one-time recovery codes. Sessions can be reviewed and ended.

Encrypted and in India

Data is stored in India and encrypted in transit and at rest; uploaded documents are scanned for malware before anyone can open them.

A record nobody can edit

Logins, approvals, exports, date changes and AI suggestions are written to an append-only audit log.

Careful AI

Off until the firm turns it on. Aadhaar and PAN numbers are removed first, outputs are suggestions a person confirms, and data is never used to train models.

Backups and recovery

Encrypted daily backups kept off the main server, with restores tested.

Your exit

Export everything at any time. Close the workspace and everything is deleted after 30 days.

Found a vulnerability? Please write to support@corp8labs.com with “Security” in the subject.