Security & Privacy
Built to hold privileged work
Your case files are privileged. We treat them that way — with encryption, Indian data residency, and a hard rule that your work never trains anyone's AI.
Our commitments
Encryption everywhere
All traffic is encrypted in transit with TLS. Data at rest is encrypted with AES-256, and documents live in access-controlled storage buckets.
Your data stays in India
Case data and documents are stored on Indian infrastructure in the Mumbai region — relevant for privilege, and for the DPDP Act.
No AI training on your work
Your cases, documents, drafts, and research queries are never used to train AI models. Nyra works for you; she does not learn from you for anyone else.
No passwords to steal
Sign-in is delegated to Google, Microsoft, or Apple. We never store a password, and your account inherits your provider’s protections — including two-factor authentication.
Role-based access for teams
Owner, Admin, Member, and Viewer roles — plus custom roles with per-feature read/write/delete permissions. Matters are private until deliberately shared, with per-share controls over editing, billing visibility, and access management.
Workspace isolation
Every firm and corporate workspace’s data is isolated. Sharing across workspaces happens only through explicit, revocable assignments.
Payments handled by Razorpay
Subscriptions and card details are processed by Razorpay, a PCI-DSS compliant payment gateway. Your card number never touches our servers.
Deletion that actually deletes
Request account deletion and your data is permanently erased after a short grace period — cases, documents, embeddings, and backups included. You can export your data first.
Enterprise-grade infrastructure
LawCentral runs on Amazon Web Services, whose data centres maintain SOC 2 and ISO 27001 certifications. We layer our own access controls and security reviews on top.
What we never do
- Sell, rent, or monetise your data
- Train AI models on your cases, documents, or queries
- Share case data with third parties
- Read your documents except to provide the service you asked for
Compliance
DPDP Act, 2023
LawCentral is designed to meet the requirements of the Digital Personal Data Protection Act — consent-based processing, purpose limitation, data-principal rights, and erasure on request.
IT Act, 2000
Reasonable security practices under Section 43A, with documented access controls and encryption for sensitive personal data.
GST-compliant billing
Subscription invoices are proper GST tax invoices from Partwigo Labs Private Limited, with sequential numbering and credit notes for refunds.
Data concerns or grievances? Write to support@lawcentral.ai or use the contact form — it reaches the founders directly.
Found a vulnerability?
We take reports seriously and respond to every one. Please report security issues privately — don't open a public issue or post — and give us reasonable time to fix before disclosure.
security@lawcentral.aiQuestions about how we handle your data?
Read the fine print, or ask us directly — we answer.