Data stays in India
Case records, personal data and documents are stored in India, in Microsoft Azure’s Central India region. Stored documents are kept in more than one data centre in that region, with earlier versions and deleted files recoverable for 30 days.
The public website is delivered through a content network for speed. Case data is not stored there.
Each firm’s data is kept apart
The platform is built so that more than one firm could use it. Every record carries the firm it belongs to, and the database itself refuses to return another firm’s records to the application, whatever the query. Inside a firm, client users see only their own organisation’s cases, and branch users only their branches’ cases.
Personal data is encrypted
- Phone numbers and email addresses are encrypted (AES-256-GCM) before they are stored, and found again through keyed fingerprints, not plain text.
- One-time codes, PINs, passwords and sign-in links are never written to logs. Logs show only masked phone numbers and email addresses.
- All traffic to the site and the portal is encrypted in transit (HTTPS).
- Document downloads use short-lived links: a respondent’s link lasts 2 minutes.
Who can see what
- Every staff, client and arbitrator account uses two-step verification. See Accounts and sign-in.
- Each role sees only what it needs. Respondents see only their own case, and only documents released to them.
- Sensitive actions (an interim decision, a withdrawal, signing an award) ask for a fresh second step.
- Important changes, such as making a notice template live or a client’s authority grant, need a second person to approve.
A record that cannot be quietly changed
Every change to a case is written to an audit log in the same step as the change itself, so one cannot happen without the other. The application cannot edit or delete audit entries.
Each entry carries a hash of the one before it, forming a chain: changing or removing any past entry breaks every link after it. Once a day the latest link is copied to separate write-once storage, so the chain can be checked against it later. Administrators can verify the chain from the admin screens.
Receipts and proof-of-service documents carry SHA-256 fingerprints of the files they describe, so a copy can be matched to the record.
Outside services
Messages, email, post, video and e-signing use outside providers, each behind its own connection that can be switched off on its own. Staff can pause any channel, or stop all outgoing messages at once; each pause is recorded with a reason. Every message has a unique key, so a retry never sends the same notice twice.
Where the platform uses AI, it drafts and suggests only. Personal details are masked before text reaches a model, a person reviews every suggestion, and AI never sends a legal notice or decides anything.
How long data is kept
Retention periods are set per type of document under legal advice, counted from when the record was made or when the case closed. When a period ends, the record is deleted and a note of the deletion is kept. A legal hold stops deletion, and so does a missing retention rule, so nothing is deleted by accident.
You can ask to see, correct or erase your personal data, or nominate someone. Requests are answered within 30 days. See the Privacy Policy and the grievance page.
Report a security concern
If you think you have found a security problem, or that someone is misusing this platform’s name, write to support@abirnyayasetu.com with the details. Please do not test against real case data. We will reply and keep you informed.