Built to hold your clients’ data
What’s on by default
Firm isolation
No matter who signs in, they only ever see your workspace’s data. Every database query is automatically scoped to your firm at the database layer — a bug can’t leak another firm’s data into yours.
Encryption at rest & in transit
Data is encrypted at rest using AES-256. All traffic runs over TLS 1.3. Sensitive fields — PANs, DSC metadata, bank account numbers — use rotating encryption keys.
Two-factor authentication
Optional 2FA for every user, with trusted-device management. Partners and managers can require 2FA firm-wide.
Request signing
Every action that changes data requires a signed token. Stops common session-hijack attacks dead.
Audit trail on every action
Every read, write, export, and login is logged with user, timestamp, IP, and device. Downloadable by partners at any time — useful for professional-liability defence.
Abuse protection
Automatic rate limits on every API endpoint and login path. Prevents brute-force attacks and scraping.
Session control
See every active session for every user in your firm. Revoke any session — on any device — remotely.
Cross-firm detection
If anything ever attempts to access another firm’s data, we detect it, block it, and alert you.
Scoped API keys
Every API key is scoped to your workspace, tracks its own usage, and can be expired or revoked instantly.
Your data stays in India
Primary region: ap-south-1 (Mumbai)
All client data lives on Indian servers via Supabase’s Mumbai region. Never replicated to a region outside India.
Backups kept in India
Backup snapshots are retained on Indian infrastructure. Current cadence is monthly; we’re moving to daily in 2026.
Cross-border transfer
The only time data leaves India is through clearly-scoped, user-initiated features — sending a message to WhatsApp, triggering an AI query, or generating an email. See the sub-processor list below for exactly what moves where, and when.
We don’t hold your DSCs
DSCs sign legally-binding documents. We treat them that way.
Practicore never stores physical DSC tokens or private keys. The DSC module is a custody and usage register — you record which DSC belongs to which client, who checked it out, when it was used, for which document. The actual signing happens on the user’s own hardware, at the moment of signing. A breach of our systems could never let anyone sign on your client’s behalf.
AI never runs in the background
Your client data is never sent to an AI provider automatically.
AI features in Practicore — Vidhi AI chat, notice analyser, draft generation, OCR, meeting transcription — are all user-initiated. You explicitly choose which document, notice, or question goes to the model. Only that specific input is sent. Nothing else in your workspace is visible to the AI provider.
We use OpenAI and Anthropic via their APIs, which under their standard API terms do not use API inputs to train their models. Meeting audio for transcription is sent to Deepgram only when you start a meeting with transcription enabled.
Who else touches your data
Below is the current list of third-party services that handle customer data as part of operating Practicore, what each one sees, where they operate, and when the data reaches them. We’ll notify you before adding a new sub-processor that handles client data.
| Service | Purpose | Data seen | Region | When |
|---|---|---|---|---|
| Supabase | Primary database, file storage, authentication | All workspace data | ap-south-1 (Mumbai, India) | Always |
| Upstash | Redis rate-limiting | API request metadata (no client data) | Global edge | Always |
| Resend | Transactional email delivery | Recipient email address, message content | US | On email send |
| UploadThing | Temporary file upload handling | Files in transit during upload | US | On file upload |
| Razorpay | Subscription & invoice payments | Payer/payee name, amount, GSTIN | India | On payment |
| WhatsApp Business (Meta) | Client messaging when you enable it | Phone numbers, message content | Global | On message send |
| OpenAI / Anthropic | AI features — notice analysis, Vidhi AI, drafting | Only the specific input you explicitly submit | US | User-initiated only |
| Azure Document Intelligence | OCR on documents you explicitly submit | Document images you choose to process | Microsoft Azure | User-initiated only |
| Deepgram | Meeting transcription | Audio from meetings you explicitly start with transcription on | US | User-initiated only |
| 100ms | Video conferencing for board meetings | Audio / video streams during meetings | India | User-initiated only |
| Sentry | Error monitoring | Stack traces, user IDs (no PII) | US | On error |
Your data, on your terms
While your account is active
Workspace data is kept for as long as your account is active. CAs are required by the Income Tax Act to retain client records for eight years — we don’t force any earlier deletion.
After account closure
When you close your account, all client data is permanently deleted within 30 days. During that window you can export everything or reinstate your account.
Portability
Export your clients, invoices, payments, tasks, and documents to Excel, CSV, or PDF at any time — no support ticket required.
Right to erasure
On written request, we’ll permanently delete specific data you identify and confirm in writing. This is additional to the automatic 30-day post-closure deletion.
Aligned with the DPDP Act, 2023
What we’ve built for it
- Purpose limitation. Personal data is processed only to operate your Practicore workspace — nothing else.
- Data minimisation. We don’t ask for data we don’t need.
- Data residency. Primary data and backups in India (see Data residency above).
- Data principal rights. Access, correction, portability, and erasure are all self-serve from your workspace settings, or on written request.
- Retention. Workspace data kept while your account is active; deleted within 30 days of closure.
- Breach notification. We commit to notifying impacted customers and the Data Protection Board of India within 72 hours of becoming aware of a reportable security incident, as required by the Act.
- Sub-processor transparency. Full list above. You’ll be notified before any new sub-processor is added that handles client data.
What we’re still building
- Formal Data Protection Officer appointment.
- Written incident-response runbook.
- ISO 27001 certification (in progress).
- Moving to daily backups (from monthly).
This is not a legal document. For formal data-protection queries or grievance redressal, email contact@practicore.in with “Data Protection” in the subject line. We respond within two working days.
If something goes wrong
We’re being honest about where we are.
A formal, written incident-response runbook is in progress. Until that’s published, here’s what we commit to today: if we identify a security incident that affects your workspace, we will notify you and the Data Protection Board of India within 72 hours of becoming aware, aligned with the DPDP Act.
Found a vulnerability? Email contact@practicore.in with “Security Disclosure” in the subject. We acknowledge within one working day.
Where we stand
ISO 27001 — in progress
We’re in the process of obtaining ISO 27001 certification and building out the information security management system that goes with it. We’ll update this page when certification lands. We don’t claim certifications we don’t hold.
Security questions before you sign?
We’re happy to answer vendor-assessment questionnaires, security questions from your IT team, or anything else. Write to contact@practicore.in.
Ready to run your practice on one platform?
Start a 14-day trial or review the product pages on your own.