India data residency
Documents and derived embeddings stay in Indian regions, with enterprise plans able to pin a named region.
Trust centre
Advocates, CAs and HR leaders carry the confidentiality obligation personally. Here is exactly how VedaCore protects what you cannot afford to lose.
Documents and derived embeddings stay in Indian regions, with enterprise plans able to pin a named region.
A logically isolated tenant with row-level access rules, no shared indexes, no cross-contamination.
Partner, associate and staff roles, matter-level access lists, SSO on request.
Every read, draft, edit, approval and export logged with user, timestamp and source document.
Your documents never train foundation models, prompts and outputs are never retained by model vendors.
Set retention windows per workspace, purge a matter on demand, get verifiable deletion confirmation.
Certification status
VedaCore does not hold a completed SOC 2 or ISO 27001 certificate yet, and we will not display a badge we have not earned. This is the current state of each programme, maintained by the VedaCore team.
External audit targeted for 2026.
Controls mapped and monitored internally.
DPA, sub-processor list and data subject request process already available.
Controls
TLS 1.2+ on every connection
AES-256 on storage and backups
Quarterly, least-privilege by default
Point-in-time recovery, encrypted
Managed vault, no keys in application code
Disclosed list, DPA available on request
Client privilege, POSH case files and tax records sit in the same workspace as your daily work. So access is scoped per matter, exports are logged, and every AI output keeps a named human reviewer on record.
A 30-minute walkthrough on your own documents. No setup, no obligation — book a slot and bring the file that has been sitting on your desk too long.