Security and Trust

Your Clients' Data is Non-Negotiable

Vakil Sarthi is built around a single principle: a lawyer's client data is sacred and must be treated with the highest level of protection.

Core Commitments

Four Pillars of Our Security

Encryption at Every Layer

AES-256 encryption protects your data at rest. TLS 1.3 secures every byte in transit. No one — not even our own engineers — can read your client files.

Resilient Backups

Daily automated backups are stored in geo-redundant cloud regions across India. Recovery point objective is under 24 hours.

Regulatory Compliance

Full GDPR compliance with data export and erasure on demand. We follow India's Information Technology Act and are preparing for DPDP alignment.

Zero Data Monetisation

We do not sell, share, or use your data for advertising, analytics products, or any form of third-party monetisation — ever.

Access Controls

Role-based access, two-factor authentication support, and device-session management prevent unauthorised access to your account.

Audit Logs

Every login, file access, and data change is logged with a timestamp and device fingerprint — giving you a full audit trail at all times.

Data Architecture

How Your Data Travels

Every interaction with Vakil Sarthi passes through multiple layers of protection.

Your Device

Data is encrypted locally before leaving your phone or computer using device-level keys.

TLS 1.3 Transit

All network traffic uses TLS 1.3 with perfect forward secrecy — every session has a unique key.

Secured API Layer

Our API gateway validates tokens, enforces rate limits, and logs every request with tamper-proof audit entries.

AES-256 Storage

Stored data is encrypted with AES-256. Encryption keys are held in an isolated Hardware Security Module.

GDPR Compliance

Your Rights Over Your Data

Vakil Sarthi fully supports the data rights granted by GDPR and India's evolving privacy framework. You are always in control.

Right to Access

Request a full export of all data associated with your account at any time, in a machine-readable format.

Right to Erasure

Delete your account and all associated data permanently within the app. Erasure is processed within 72 hours.

Right to Portability

Download all your case data in JSON or PDF format. Take your data anywhere, anytime.

Right to Rectification

Correct any inaccurate personal data within your account profile directly from the settings panel.

Our Written Commitment

These are not just legal obligations — they are promises we make to every advocate on our platform.

  • We will never sell your personal or client data to any third party.
  • We will notify you within 72 hours of any discovered security breach affecting your account.
  • Our internal team members do not have access to your case data or client information.
  • All data deletion requests will be processed within 72 hours with written confirmation.
  • We conduct independent security audits at least once per year and share summaries publicly.
  • Our infrastructure undergoes automated vulnerability scanning daily.
Standards and Certifications

Built to Industry Standards

AES-256 Encryption

Used by governments and militaries worldwide for protecting classified information.

TLS 1.3 Protocol

The latest transport encryption standard with mandatory perfect forward secrecy.

GDPR Compliant

Full compliance with EU General Data Protection Regulation for user data rights.

PCI-DSS

Payment Card Industry Data Security Standard for all VSPay transactions.

Incident Response

Our Breach Response Protocol

In the unlikely event of a security incident, we follow a strict, time-bound response protocol.

0h

Detection and Isolation

Automated monitoring detects anomalous activity. Affected systems are immediately isolated to contain the incident.

6h

Internal Assessment

The security team assesses scope, affected accounts, and data categories involved. Senior leadership is briefed.

24h

User Notification Begins

Affected users receive a direct, plain-language email describing what happened and what data may be involved.

72h

Regulatory Disclosure

Relevant data protection authorities are notified within 72 hours as required under GDPR and applicable Indian law.

30d

Public Post-Incident Report

A full post-mortem report is published on our website describing root cause, remediation, and preventive measures taken.

Start with a Platform You Can Trust

Security is not a feature — it is the foundation of everything we build.