Trust should be
open to inspection.

Understand the boundaries around data, AI processing and human decisions. These are product-design facts—not a security certification.

Discuss your requirements

Connected systems. Defined access.

Tenant, workspace and matter permissions govern which records a person can access. Hosting and model-processing routes are separate questions, made explicit for each deployment.

Close-up illustration of separate groups of network interfaces and petrol-coloured cables.
Conceptual infrastructure image, not NyayaDesk’s actual hosting.

Know who can see—and do—what.

Permissions govern retrieval and actions. The platform’s administrator is not automatically entitled to read private case records.

NyayaDeskMatter access

Different responsibilities.
The right access.

Counsel
Strategy and legal approval
Record owner
Assigned factual questions
Coordinator
Tasks and operational oversight
Access boundary

A role alone does not open every matter. Tenant, workspace and matter grants determine access.

Fictional example · curated product view

AI processing happens outside India

Every AI model call — drafting, checking, extraction, research and answers — goes through OpenRouter to the model provider that serves it, outside India. OpenRouter documents in-region routing for the United States and the European Union only. Every request requires zero data retention: the provider may not keep the data or train on it, and the provider that served each call is recorded.

Your workspace's data is stored in India. The search embeddings are made by a model inside the deployment and do not go to OpenRouter.

This deployment sends AI model calls to OpenRouter (openrouter.ai) with zero data retention requested on every call.

Where your data sits

Each organisation is placed on one of three hosting tiers when its workspace is set up. The same code, the same database schema and the same row-level security apply in every tier.

Shared database

For organisations

A database in India shared with other organisations, where every row carries its workspace and PostgreSQL row-level security keeps each workspace to its own rows.

Dedicated database

For state governments

A database of the workspace's own, in the state's data centre.

Dedicated deployment

For organisations that host it themselves

A deployment of its own, in the organisation's data centre or on its premises.

Who else processes your data

Reviewed 14 September 2026
Third parties that process data for NyayaDesk, what they receive, where and for how long.
SubprocessorWhat forWhat it receivesWhereRetention
OpenRouterRoutes every AI model call (drafting, checking, extraction, research and answers) to the model provider that serves it.The case text, questions and structured instructions an AI task needs, for that task only.Outside India. OpenRouter documents in-region routing for the United States and the European Union only.Zero data retention on every request: the provider must not keep or train on the data (provider.zdr true, provider.data_collection deny). The provider that served each call is recorded on the AI run.
The model provider OpenRouter routes each call toRuns the model for one call. Each AI role has a primary model and ordered fallbacks from different model families.The same call OpenRouter forwards, under the same zero-retention requirement.Outside India, wherever that provider processes the call.Only providers with zero-retention endpoints are used; the serving provider is recorded per call.
Hosting provider
Configured per deployment
Runs the application, its databases, object storage and workflow services.Everything a workspace stores.India. The deployment chart refuses a region outside India; a state government's workspace is hosted in that state's data centre.As each workspace's retention settings and offboarding decide.
S3-compatible object storage
Configured per deployment
Holds uploaded documents, page images, OCR layers and exports, under each workspace's own prefix or bucket.Documents and files.In the workspace's hosting location, in India.As the workspace's retention settings and offboarding decide.
E-mail delivery (an SMTP relay, or Brevo)
Configured per deployment
Sends sign-in codes, notification e-mails a person has chosen to receive, access-reset notices, and tells NyayaDesk's platform operators that a Talk to us request arrived.The recipient's address, a subject and a short notice or code; never a password.The relay the deployment configures. A deployment that chooses Brevo's transactional e-mail API sends through Brevo, outside India.As the relay's operator keeps mail logs.

Which hosting provider, object store and e-mail relay a deployment uses is decided when it is set up; this page cannot name them for every deployment.

What runs inside the deployment

  • Embeddings for searchA local embedding model inside the deployment turns text into search vectors; this is the one AI step that does not go through OpenRouter.
  • OCRScanned pages are rendered to images inside the document worker and read by a model through OpenRouter, zero retention (D-29).
  • Malware scanningEvery upload is scanned by ClamAV inside the deployment before anything reads it; a scanner that is down never counts as clean.
  • Databases, search, workflows and cachePostgreSQL (with full-text search and pgvector), Temporal and Valkey run inside the deployment.

Security controls

  • Every workspace's data is separatedEvery workspace-owned table carries the workspace and is protected by PostgreSQL row-level security that the application's own database role cannot bypass, in every hosting tier, including inside a dedicated database. Search, storage, caches, workflows and AI tools are scoped to the workspace as well.
  • Every act that matters legally is auditedWrites that matter legally create audit events the application cannot edit or delete, sealed into hourly hash-chain checkpoints.
  • EncryptionTLS in transit. Documents, databases and backups are encrypted at rest with the keys the deployment configures.
  • A second factor for privileged accessWorkspace administrators, platform operators and break-glass sessions need a sign-in with a second factor on every request.
  • No standing access to your dataOperating the platform does not show anyone a workspace's matters. Support access is a break-glass session: requested with a reason, approved by a second person, time-limited, read-only and audited.
  • AI prepares; people approveNo AI output is approved or filed automatically. A Government Pleader's approval is what makes a draft final, and every AI run records its model, sources and checks.
  • Word files leave NyayaDeskA counter draft downloaded for Word, or opened through NyayaDesk for Word, is a copy on the person's own computer and in the organisation's own Office and storage; NyayaDesk does not control it there. The file carries sentence ids and text hashes, not sources. An edited file returns only as a new draft version whose approval resets, and the Word add-in's sign-in lasts at most 30 minutes and cannot approve, execute or file.

Retention in this deployment

Matter records and documents
The periods each workspace's administrator sets
Audit entries, at least
180 days
Audit checkpoints held write-once
180 days
After a workspace is offboarded, deletion no earlier than
30 days after its export is verified, unless the platform sets another period
The platform's own audit log
Not yet decided
AI spend cap for a workspace that sets none
US$25 a month

Certifications

NyayaDesk holds no security or privacy certification today. We do not claim SOC 2, ISO/IEC 27001 or any government empanelment.

Questions about security or data handling: talk to us.

Access precedes retrieval.

Matter, document and knowledge access follow the user’s tenant, workspace and permissions. Search applies scope before retrieving private records, rather than retrieving everything and hiding it afterwards.

  • Tenant isolation and matter-level grants
  • Public authorities separate from private case data
  • Platform administration is not blanket legal-data access

Decisions leave a trail.

Draft versions and approvals carry a content hash. Model runs retain their review record. Administrative changes, exports and privileged access are audited.

  • Version-bound approvals
  • Time-limited, approved break-glass access
  • Export provenance and audit events

Retention is not one universal number.

Tenant retention policies, document classes and legal holds affect what can be retained or deleted. Zero-retention model routing does not mean your own case record or application audit trail is not stored.

Confirm storage location, backup arrangements, retention, subprocessors and incident responsibilities for your actual deployment before onboarding.

Authentication follows your workspace.

Organisation single sign-on uses OpenID Connect and a verified email domain. Existing membership is required. A federated sign-in does not create a new workspace or grant a person access to a matter.

SAML, SCIM and government-provider integrations should not be assumed available.

Claims we do not make.

No certification, guaranteed accuracy, guaranteed outcome or production SLA is claimed on this website. Model agreement is not legal correctness, and source coverage is not a probability of winning.

See evaluation status and limitations

Bring your requirements.
Inspect the details.

Explore NyayaDesk for your organisation’s records, people and review process.

Talk to us

Does all NyayaDesk AI processing remain in India?

No. The current inference route uses OpenRouter with zero-retention settings and may process data outside India. Embeddings follow a separate self-hosted route. Confirm hosting, subprocessors and processing boundaries for the actual deployment.

Discuss your requirements