Security & Privacy

Built to hold privileged work

Your case files are privileged. We treat them that way — with encryption, Indian data residency, and a hard rule that your work never trains anyone's AI.

Our commitments

Encryption everywhere

All traffic is encrypted in transit with TLS. Data at rest is encrypted with AES-256, and documents live in access-controlled storage buckets.

Your data stays in India

Case data and documents are stored on Indian infrastructure in the Mumbai region — relevant for privilege, and for the DPDP Act.

No AI training on your work

Your cases, documents, drafts, and research queries are never used to train AI models. Nyra works for you; she does not learn from you for anyone else.

No passwords to steal

Sign-in is delegated to Google, Microsoft, or Apple. We never store a password, and your account inherits your provider’s protections — including two-factor authentication.

Role-based access for teams

Owner, Admin, Member, and Viewer roles — plus custom roles with per-feature read/write/delete permissions. Matters are private until deliberately shared, with per-share controls over editing, billing visibility, and access management.

Workspace isolation

Every firm and corporate workspace’s data is isolated. Sharing across workspaces happens only through explicit, revocable assignments.

Payments handled by Razorpay

Subscriptions and card details are processed by Razorpay, a PCI-DSS compliant payment gateway. Your card number never touches our servers.

Deletion that actually deletes

Request account deletion and your data is permanently erased after a short grace period — cases, documents, embeddings, and backups included. You can export your data first.

Enterprise-grade infrastructure

LawCentral runs on Amazon Web Services, whose data centres maintain SOC 2 and ISO 27001 certifications. We layer our own access controls and security reviews on top.

What we never do

  • Sell, rent, or monetise your data
  • Train AI models on your cases, documents, or queries
  • Share case data with third parties
  • Read your documents except to provide the service you asked for

Compliance

DPDP Act, 2023

LawCentral is designed to meet the requirements of the Digital Personal Data Protection Act — consent-based processing, purpose limitation, data-principal rights, and erasure on request.

IT Act, 2000

Reasonable security practices under Section 43A, with documented access controls and encryption for sensitive personal data.

GST-compliant billing

Subscription invoices are proper GST tax invoices from Partwigo Labs Private Limited, with sequential numbering and credit notes for refunds.

Data concerns or grievances? Write to support@lawcentral.ai or use the contact form — it reaches the founders directly.

Found a vulnerability?

We take reports seriously and respond to every one. Please report security issues privately — don't open a public issue or post — and give us reasonable time to fix before disclosure.

security@lawcentral.ai

Questions about how we handle your data?

Read the fine print, or ask us directly — we answer.