Security

Confidential by architecture.

Indian Big Law data discipline doesn't bend for AI vendors. Docket is built to firm-grade trust standards from the data layer up. Below: what that means in practice.

Data residency

All client data hosted in India. AWS Mumbai region (ap-south-1) for our managed deployment, with the option of dedicated single-tenant infrastructure for firms with sovereign-data requirements. No cross-border data transfer for matter content. No training on your data, ever — your firm's documents, queries, and outputs are excluded from any model training set, including third-party LLM providers we use under inference-only agreements.

Matter-level isolation

Every matter is isolated at the database layer with row-level security. No data leakage between matters: not between firms, not between teams at the same firm, not between partners within the same team if matter walls require it. Access controls map to your firm's existing conflict-check architecture.

Audit logs

Every interaction logged: prompt, output, user, timestamp, matter context, source citations referenced. Logs are exportable in standard formats for your firm's risk team and your client's audit requirements. Available to your firm's designated reviewer in real time.

Compliance

Standards we hold ourselves to.

SOC 2 Type IIIn progress · targeted Q3 2026
ISO 27001In progress · targeted Q4 2026
DPDP Act 2023Compliant by design: data residency, consent, processor obligations

Security review request.

We're happy to walk your firm's IT or risk team through our architecture in detail. Procurement documents, security questionnaires, and architecture diagrams available under NDA.

Request a security review