Advocates hold confidences. Here is exactly how we protect them — including what is not done yet.
Last updated:
We would rather tell you precisely what is in place than make large promises. Everything in the first two tables is implemented today; the last table lists what we have not done.
Who can see a case
Protection
How it works
Chambers are walled off
Every cases, clients, fees, notes and documents request is checked against your active chamber. A user in another chamber cannot open your data even with its ID. Automated tests check this isolation on every release.
Sharing is explicit and revocable
Nothing leaves your chamber unless you create a share link for one case. The recipient must sign in and accept; access is view-only or edit as you choose; you can restrict a link to one mobile number or email and revoke it any time.
Roles
Owner, associate and clerk roles; only the chamber owner can add members.
Documents are private
Uploaded files are kept outside the public web folder. They can only be downloaded by a signed-in user who has access to that case — there are no public file URLs.
Accounts and sign-in
Protection
How it works
Verified mobile number
Sign-up and OTP sign-in use a 6-digit code sent to your phone. Codes are stored only as hashes, expire after 10 minutes, allow 5 wrong attempts, and can be re-requested only after 30 seconds.
Passwords
Stored only as salted one-way (bcrypt) hashes — we cannot read your password. Minimum 8 characters.
Brute-force and SMS-bombing limits
Rate limits on OTP and sign-in endpoints at both the web server and the application, per number and per IP. Forgot-password gives the same answer whether or not an account exists, so it cannot be used to find who has one.
Sign-in tokens
Signed, short-lived access tokens (24 hours); switching chambers issues a new token scoped to that chamber.
Alerts
You are notified on WhatsApp (and by email if verified) of every sign-in, and when your password is changed, so account misuse is noticed quickly.
Email only after verification
We never send mail to an address you have not proved is yours with a code.
Infrastructure
Protection
How it works
Encryption in transit
All traffic between your device and our servers uses HTTPS (TLS). Plain HTTP is redirected.
Isolated runtime
The application runs under its own operating-system user and PHP process pool, with its own database and a database user that can access only that database. The database accepts local connections only.
Secrets
API keys and passwords live in server environment files that are not in the code repository and not readable by other users.
Backups
Nightly database and document backups, kept 14 days.
Payments
When online payments launch, card and UPI details go straight to the payment gateway; we never see or store them.
Third parties
Only message delivery partners (SMS / WhatsApp / email) receive the minimum needed — the recipient and the message — and never the contents of your cases. See the Privacy Policy.
Privacy by design
The Android app asks only for internet access; no contacts, location, SMS, camera or microphone. No advertising or tracking SDKs.
What we have not done yet
No independent security audit or certification (such as ISO 27001) yet. We plan a third-party penetration test before large-scale launch.
Encryption at rest of the database and document storage is provided only to the extent of the hosting platform's disk protection; we do not yet add application-level encryption of stored case content.
Off-site backup copy and a documented disaster-recovery drill are being set up; today backups protect against mistakes and failures but not against the loss of the whole server.
No in-app audit log (who viewed or changed what) and no extra second factor beyond the OTP + password yet.
Data export is by request to us; a self-service export is planned.
If something goes wrong
Incident response. If a breach affects personal data we will contain it, tell affected users without undue delay, and notify the Data Protection Board of India as the law requires.
Report a vulnerability. Email hello@thecasediary.in with the subject "Security report". Please give us reasonable time to fix a problem before you disclose it publicly, and do not access other people's data. We will acknowledge within 2 working days.
What you can do
Use a strong, unique password, and change it from Account → Change password if you suspect it leaked.
Keep your phone locked; your mobile number is your account's key.
Share a case with a specific number rather than an open link where you can, and revoke shares when work ends.