Data security

Advocates hold confidences. Here is exactly how we protect them — including what is not done yet.

Last updated:

We would rather tell you precisely what is in place than make large promises. Everything in the first two tables is implemented today; the last table lists what we have not done.

Who can see a case

ProtectionHow it works
Chambers are walled offEvery cases, clients, fees, notes and documents request is checked against your active chamber. A user in another chamber cannot open your data even with its ID. Automated tests check this isolation on every release.
Sharing is explicit and revocableNothing leaves your chamber unless you create a share link for one case. The recipient must sign in and accept; access is view-only or edit as you choose; you can restrict a link to one mobile number or email and revoke it any time.
RolesOwner, associate and clerk roles; only the chamber owner can add members.
Documents are privateUploaded files are kept outside the public web folder. They can only be downloaded by a signed-in user who has access to that case — there are no public file URLs.

Accounts and sign-in

ProtectionHow it works
Verified mobile numberSign-up and OTP sign-in use a 6-digit code sent to your phone. Codes are stored only as hashes, expire after 10 minutes, allow 5 wrong attempts, and can be re-requested only after 30 seconds.
PasswordsStored only as salted one-way (bcrypt) hashes — we cannot read your password. Minimum 8 characters.
Brute-force and SMS-bombing limitsRate limits on OTP and sign-in endpoints at both the web server and the application, per number and per IP. Forgot-password gives the same answer whether or not an account exists, so it cannot be used to find who has one.
Sign-in tokensSigned, short-lived access tokens (24 hours); switching chambers issues a new token scoped to that chamber.
AlertsYou are notified on WhatsApp (and by email if verified) of every sign-in, and when your password is changed, so account misuse is noticed quickly.
Email only after verificationWe never send mail to an address you have not proved is yours with a code.

Infrastructure

ProtectionHow it works
Encryption in transitAll traffic between your device and our servers uses HTTPS (TLS). Plain HTTP is redirected.
Isolated runtimeThe application runs under its own operating-system user and PHP process pool, with its own database and a database user that can access only that database. The database accepts local connections only.
SecretsAPI keys and passwords live in server environment files that are not in the code repository and not readable by other users.
BackupsNightly database and document backups, kept 14 days.
PaymentsWhen online payments launch, card and UPI details go straight to the payment gateway; we never see or store them.
Third partiesOnly message delivery partners (SMS / WhatsApp / email) receive the minimum needed — the recipient and the message — and never the contents of your cases. See the Privacy Policy.
Privacy by designThe Android app asks only for internet access; no contacts, location, SMS, camera or microphone. No advertising or tracking SDKs.

What we have not done yet

If something goes wrong

What you can do