Security
Security at Pundora
A client's papers are the most confidential thing an advocate holds. This page says, item by item, what Pundora does with them, what it does not do, and what has not yet been audited by anyone outside.
Where the files live
- Servers
- India, Mumbai region. The database, the file store and the application run there.
- One chamber, one workspace
- Every row of every table carries the chamber it belongs to, and the database itself refuses a query from one chamber for another's data. This wall is tested on every change to the code before it can be deployed.
- Files at rest
- Every uploaded file is encrypted with a key that belongs to that workspace before it is written to storage; the key is itself wrapped by a master key the application holds. The stored object is ciphertext.
- Backups
- Encrypted and held separately from the live system. A restore has been rehearsed and timed.
- Scanned pages and photographs
- Read on a machine Pundora runs itself in Mumbai, reachable only by the application, with no route to the public internet from the reader. No cloud reading service sees a page.
Who can touch them
- Sign-in
- Google sign-in only. Pundora holds no passwords. One person belongs to one chamber.
- The AI provider
- When an AI feature runs, the relevant text is sent to Anthropic to produce the result. Anthropic does not train on content sent through its API and, under its standard terms, deletes inputs and outputs within 30 days. Pundora has applied for the provider's zero-data-retention terms; until they are approved for Pundora's account the 30-day standard applies, and the privacy policy changes on the day it changes. Features that need no AI, which is most of them, never send anything.
- Licensed sources
- A citation, or search terms built from named legal parts, may be sent to Indian Kanoon under licence. An advocate's documents, words and typed party names have no path there.
- Pundora talks to Meta's WhatsApp Business Platform directly, with no intermediary provider. The number is registered with India as its storage region. Every photograph or document an advocate sends is fetched once, encrypted into the workspace, and a deletion request is sent to Meta the same minute, with Meta's answer recorded in the workspace's audit trail. Nothing is ever sent back out over WhatsApp as a document. The channel is not end-to-end encrypted, because no business channel on WhatsApp is; Pundora says so.
- Pundora's own people
- Nobody at Pundora reads a chamber's documents in the course of running the service. Operational work uses records about requests and errors, not their content.
What the code refuses
- Any AI model whose terms require longer retention than the standard: the gateway refuses the request, and the build fails if such a model is named in the code.
- Batch and file-upload routes to the AI provider, which fall outside zero-retention terms: blocked in code.
- A scanned page bigger than about A2, an upload over 100 MB, a picture over 50 million pixels: refused at the door, because each was once a way to exhaust a machine.
- Text inside an uploaded document that tries to instruct the AI: detected and reported, never obeyed. Eight such documents are kept as a permanent test.
What is in place around the edges
- Security headers on every page of both hosts; the sign-in page is not indexed; the public site loads no third party at all.
- A reading allowance per chamber per day, so one runaway job cannot spend another chamber's share.
- An append-only audit trail in each workspace: who uploaded, confirmed, exported or deleted what, and when.
- Secrets live only on the machines that need them; the shared secret between the application and the page reader is rotated and never logged.
- A security contact at /.well-known/security.txt. A report to contact@pundora.in is read by a person.
What is not yet done
- No certification. No ISO 27001 or SOC 2 audit has been carried out. Pundora will not display a badge it has not earned.
- Zero-retention terms with the AI provider: applied for, not yet in force (above).
- Error monitoring with content removed is being set up; until it is live the privacy policy does not name it.
- No bug-bounty programme. Reports are welcome at the address above and will be answered.
- Independent penetration testing has not been commissioned. The product is tested adversarially by its own builders, and those tests are kept as permanent suites; that is not the same thing.
If something goes wrong
Indian law requires certain incidents to be reported to CERT-In within six hours; Pundora's runbook is written to that clock. Affected chambers are told what happened, what was touched, and what was done, in plain words.
Questions advocates ask
Is my data stored in India?
Yes: the database, the file store and the application run in the Mumbai region. Two things leave India, both named in the privacy policy: text sent to the AI provider when an AI feature runs, and WhatsApp messages passing through Meta's systems with India as the storage region.
Is Pundora end-to-end encrypted?
Files are encrypted before they are stored, with a key that belongs to the workspace, and every connection is encrypted in transit. The WhatsApp channel is not end-to-end encrypted, because a business number on WhatsApp works through Meta's hosting; Pundora says this plainly rather than implying otherwise.
Is my chamber's data used to train AI?
No. The AI provider does not train on content sent through its API, and Pundora trains no model on anything. A chamber's own drafts shape only that chamber's workspace, and only in form, never in facts.
Is Pundora ISO 27001 or SOC 2 certified?
Not yet. No audit has been done, and no badge will appear until one has.
How do I report a security problem?
Write to contact@pundora.in, or follow /.well-known/security.txt. A person reads it.