Legal
Security & Data Residence
Last updated: 30 July 2026
Lawyers hold privileged material. This page states plainly where your data sits, who can reach it, and what happens to it when it passes through AI. If anything here is unclear, write to security@legalkairos.app.
1. Isolation between accounts
Every document, matter, client record, note and invoice is bound to the account that created it and is enforced at the database layer with row-level security — not just in the interface. One user's uploads can never appear in another user's search, matter list or AI context, including inside the same firm unless access is explicitly granted. Requests without a valid session are rejected before any query runs.
2. Encryption
All traffic is served over TLS 1.2+. Files and database contents are encrypted at rest with AES-256 by the managed infrastructure provider. Passwords are stored only as salted hashes; we never see them.
3. Data residence
Application data and uploaded files are held in a managed Postgres database and object storage operated by our cloud infrastructure provider. AI processing is performed by third-party model providers reached over encrypted connections; prompts may be processed outside India. If your engagement requires India-only processing, contact us before uploading privileged material — we will confirm in writing what can and cannot be met.
4. How AI handles your matter
- Your documents and prompts are sent to the model only to answer the request you made.
- We do not use your content to train models, and we do not sell or share it.
- AI output is a first draft. It carries a confidence indicator and must be verified by the advocate.
- You can delete any document or matter; deletion removes it from search and AI context immediately.
5. Access control and authentication
- Role-based access: admin, partner, lawyer, paralegal, staff and scoped client-portal access.
- Optional two-factor authentication (TOTP) on any account.
- Account lockout with progressive backoff after repeated failed sign-ins.
- Automatic sign-out after 30 minutes of inactivity.
- Every privileged action is written to an append-only audit log.
6. Uploads
Files are validated on the server by inspecting the actual bytes, not the file name — unsupported or disguised formats are rejected. Uploads are screened for known malicious patterns (macro-bearing documents, active content in PDFs, known signatures) before any text extraction or OCR is attempted.
7. Retention and deletion
Your content is retained while your account is active. On deletion of an item it is removed from the live system; residual copies in encrypted backups age out within 30 days. On account closure, data is deleted within 30 days except where a statutory or tax record must be kept.
8. Backups and continuity
The database is backed up daily with point-in-time recovery. Object storage is redundantly stored. Backups are encrypted and access to them is restricted to on-call engineering.
9. Reporting a vulnerability
Report security issues to security@legalkairos.app. We acknowledge within one working day and will not pursue action against good-faith research that avoids privacy violations, data destruction and service disruption.
10. Breach notification
If a breach affects your data, we will notify affected account owners without undue delay with what we know, what is affected, and what we are doing — and will report to the relevant authority where the law requires it.
11. Your responsibilities
Use a unique password, enable two-factor authentication, keep client-portal invitations limited to the intended recipient, and remember that professional obligations of confidentiality and independent verification of AI output remain with you as the advocate.