Security

Security at Pundora

By Abhijeet, founder, Pundora · Published 3 October 2026

A client's papers are the most confidential thing an advocate holds. This page says, item by item, what Pundora does with them, what it does not do, and what has not yet been audited by anyone outside.

Where the files live

Servers
India, Mumbai region. The database, the file store and the application run there.
One chamber, one workspace
Every row of every table carries the chamber it belongs to, and the database itself refuses a query from one chamber for another's data. This wall is tested on every change to the code before it can be deployed.
Files at rest
Every uploaded file is encrypted with a key that belongs to that workspace before it is written to storage; the key is itself wrapped by a master key the application holds. The stored object is ciphertext.
Backups
Encrypted and held separately from the live system. A restore has been rehearsed and timed.
Scanned pages and photographs
Read on a machine Pundora runs itself in Mumbai, reachable only by the application, with no route to the public internet from the reader. No cloud reading service sees a page.

Who can touch them

Sign-in
Google sign-in only. Pundora holds no passwords. One person belongs to one chamber.
The AI provider
When an AI feature runs, the relevant text is sent to Anthropic to produce the result. Anthropic does not train on content sent through its API and, under its standard terms, deletes inputs and outputs within 30 days. Pundora has applied for the provider's zero-data-retention terms; until they are approved for Pundora's account the 30-day standard applies, and the privacy policy changes on the day it changes. Features that need no AI, which is most of them, never send anything.
Licensed sources
A citation, or search terms built from named legal parts, may be sent to Indian Kanoon under licence. An advocate's documents, words and typed party names have no path there.
WhatsApp
Pundora talks to Meta's WhatsApp Business Platform directly, with no intermediary provider. The number is registered with India as its storage region. Every photograph or document an advocate sends is fetched once, encrypted into the workspace, and a deletion request is sent to Meta the same minute, with Meta's answer recorded in the workspace's audit trail. Nothing is ever sent back out over WhatsApp as a document. The channel is not end-to-end encrypted, because no business channel on WhatsApp is; Pundora says so.
Pundora's own people
Nobody at Pundora reads a chamber's documents in the course of running the service. Operational work uses records about requests and errors, not their content.

What the code refuses

What is in place around the edges

What is not yet done

If something goes wrong

Indian law requires certain incidents to be reported to CERT-In within six hours; Pundora's runbook is written to that clock. Affected chambers are told what happened, what was touched, and what was done, in plain words.

Questions advocates ask

Is my data stored in India?

Yes: the database, the file store and the application run in the Mumbai region. Two things leave India, both named in the privacy policy: text sent to the AI provider when an AI feature runs, and WhatsApp messages passing through Meta's systems with India as the storage region.

Is Pundora end-to-end encrypted?

Files are encrypted before they are stored, with a key that belongs to the workspace, and every connection is encrypted in transit. The WhatsApp channel is not end-to-end encrypted, because a business number on WhatsApp works through Meta's hosting; Pundora says this plainly rather than implying otherwise.

Is my chamber's data used to train AI?

No. The AI provider does not train on content sent through its API, and Pundora trains no model on anything. A chamber's own drafts shape only that chamber's workspace, and only in form, never in facts.

Is Pundora ISO 27001 or SOC 2 certified?

Not yet. No audit has been done, and no badge will appear until one has.

How do I report a security problem?

Write to contact@pundora.in, or follow /.well-known/security.txt. A person reads it.

Sources

  1. Privacy policy: the same commitments as a contract
  2. Anthropic's privacy centre: how long organisation data sent through the API is stored (read 3 October 2026)
  3. Meta: WhatsApp Business Platform data processing terms
  4. CERT-In directions of 28 April 2022 (the six-hour reporting rule)

Every fact on this page carries its source. If one is wrong, write to contact@pundora.in and it will be corrected and dated.