Security · Privacy · DPDP Act 2023

Data privacy and security for law firms in India. Your matters are privileged.

A lawyer's files are not ordinary data, so Lawgger is built like they aren't. Everything below is how your chamber's work is held — in plain words, on the record.

The short answer

Lawgger encrypts everything in transit with TLS 1.2 or higher and at rest with AES-256. Each chamber's matters sit in a private data container. Every action is written to a hash-chained, tamper-evident audit trail. Controls are aligned to ISO/IEC 27001 — not certified. Built for the DPDP Act, 2023. Your work is never used as AI training data.

your briefReply to legal notice — State v. Rathore, hearing 14 Aug…
on the wire•••• •••• •••• ••••
Six standing promises

Client confidentiality on legal software — what we do, and what we never do

Encrypted, both ways

Everything travels over encrypted connections (TLS 1.2+) and rests encrypted (AES-256). Your files are never readable in transit or in storage.

Private data containers

Each chamber's matters, documents and clients live in their own sealed container. No sharing between chambers, no pooling — your vault is yours alone, us included.

Tamper-evident audit trail

Every action is logged and the log is hash-chained — blockchain-style integrity, so a record can't be quietly altered after the fact.

DPDP Act, 2023 ready

Built around the Digital Personal Data Protection Act, 2023: purpose-limited collection, consent, the right to erasure, and a named grievance contact.

ISO/IEC 27001-aligned controls

Our security controls follow the ISO/IEC 27001 framework — access control, least privilege, incident response and regular review. Aligned to it; we do not hold the certificate and do not say we do.

Never training data

Your matters, drafts and documents are never used to train AI models — ours or anyone else's. Your work stays your work.

The other trust question

Is AI legal research reliable?

It depends entirely on one thing: whether the tool is reading judgments, or writing from memory. That single difference decides whether an answer is checkable in ten seconds or a liability you carry into court.

Why general assistants invent citations

A general-purpose assistant is a very good guesser at what a sentence should look like. Asked for authority on a point of Indian law, it produces something that has the shape of a citation — a plausible party name, a plausible year, a plausible volume. Sometimes it is real. Sometimes it is not, and there is nothing in the answer to tell you which. Courts in several jurisdictions have now dealt with counsel who filed on the strength of a case that never existed. We wrote about the mechanics of this in AI hallucination in legal research, and about the wider question in using ChatGPT for legal work in India.

How Lawgger answers differently

Lawgger answers only from judgments it actually holds — 2.07 crore-plus Indian judgments in full text, covering the Supreme Court and all 25 High Courts. Every proposition in an answer is pin-cited to the page it came from, and the page opens. If the judgments on file do not support a proposition, the answer says so rather than filling the gap. You are never asked to trust a summary; you are handed the paragraph. See how this works on the legal research page.

Good law, checked before you rely on it

A real citation is not automatically a safe one. An authority can be real, correctly cited, and overruled. Every authority Lawgger surfaces is checked and marked — still good law, or not — and good-law checking is explained in full on its own page. Authority Check goes one step further: paste a brief you have already written, and get back a Table of Authorities with a verdict against each entry, so a two-hour verification pass takes minutes.

The advocate still signs

None of this makes the software responsible for what is filed. Lawgger produces working material for a qualified advocate to read, verify and sign, and the terms of service say so plainly. The point of pin-cites and good-law flags is not to remove your judgment from the process — it is to make exercising that judgment fast enough to be worth doing on every authority, every time.

2.07 crore+judgments, full text 25 High Courtsplus the Supreme Court Every claimpin-cited to the page Every authoritychecked for good law
DPDP Act, 2023

What the DPDP Act asks of a chamber

A chamber that holds client names, phone numbers, medical records, bank statements and identity documents is handling personal data. Under the Digital Personal Data Protection Act, 2023, that makes the chamber a Data Fiduciary — with duties of its own, separate from privilege.

In practical terms the Act asks a chamber to know what it holds and why, to collect only what a stated purpose needs, to keep it no longer than that purpose requires, to erase it when asked unless a law says otherwise, to name someone who answers grievances, and to report a breach. None of that is onerous for a chamber that keeps its files in one system. It is very hard for a chamber whose client data lives across a personal phone, a shared drive, three email accounts and a clerk's notebook.

Lawgger is built so the software side of those duties is already handled: collection is purpose-limited, consent is recorded, erasure is a request you can make in writing and have honoured, and a grievance contact is published rather than buried. Every access to a file is written to the audit trail, which is what turns "we think nobody else saw it" into something you can actually show. The full detail is in the privacy policy.

One caution, stated plainly. This is a description of how the software behaves. It is not legal advice about your obligations under the Act, and Lawgger is not a law firm. Your compliance position is yours to determine.

For the profession

Bar Council rules and legal software: built to respect the Bar

Lawgger is a technology platform for advocates — not a law firm, and never a substitute for one.

  • No solicitation, no advertising of legal services. Consistent with the Bar Council of India's rules, Lawgger does not practise, advertise or solicit legal work. Advocates do; we equip them. We publish no testimonials, no user counts and no client names — who we are is on the record instead.
  • No legal advice. Lawgger produces research and drafts for a qualified advocate to review and sign. The advocate's judgment is always the final word.
  • Only original judgments from real cases. Every authority cited is a real, verifiable judgment — opened at its page, from the official court record. Nothing invented, ever.
  • Payments handled by a PCI-DSS compliant processor. Card and UPI details go to the payment processor, never to us. What you pay is published on the pricing page.

On the record

DPIIT-recognised startup
Registered in Jammu & Kashmir, India
CIN U62011JK2025PTC017648
Seeded by JKEDI · Startup J&K
Showcased at Bengaluru Tech Summit 2025
Digital Personal Data Protection Act, 2023 — Lawgger is built for DPDP compliance DPIIT recognition mark — Lawgger is a DPIIT-recognised startup Startup India logo
Questions, answered

Is client data safe on legal software? And five other fair questions

Everything travels over encrypted connections using TLS 1.2 or higher and rests encrypted with AES-256. Each chamber's matters, documents and clients sit in their own sealed container with no pooling between chambers. Every action is written to a hash-chained audit trail, so a record cannot be quietly altered afterwards.

No. Your matters, drafts and documents are never used as AI training data — not by Lawgger and not by anyone else. This is a standing rule rather than a setting you have to find and switch off. Your work stays your work, inside your chamber's own container.

No, and it does not claim to be. Lawgger's security controls are aligned to the ISO/IEC 27001 framework — access control, least privilege, incident response and regular review — without holding the certificate. That distinction matters when you are answering a client's procurement questionnaire, so it is stated plainly rather than blurred.

A chamber holding client personal data is a Data Fiduciary, with duties around notice, purpose limitation, retention, erasure and breach reporting. Lawgger is built for that: purpose-limited collection, consent, a right to erasure and a named grievance contact. This is a description of the software, not legal advice on your obligations.

It depends entirely on whether the tool reads judgments or writes from memory. General assistants produce case names that look correct and do not exist. Lawgger answers only from judgments on file, pin-cites every claim to the page, and shows whether each authority is still good law — so verification takes seconds.

No. Lawgger never publishes a user's name, their matters or their outcomes, and it publishes no testimonials or user counts. Bar Council of India rules restrict how an advocate may be advertised, so the software is advertised and the advocate is not. Your practice stays off this website entirely.

Your rights, in one place

Read the fine print. It's short on purpose.

Questions, or a data request? Write to anubhav@lawgger.com — a human replies.

Try it on your own matter

Confidential by default. Checkable by design.

Fourteen days free, no card. Run it on your own matters and see how the pin-cites hold up.

Start free with Lawgger