Security — Nyaytech
LEGAL

Security

Firms trust Nyaytech with privileged case data. Here's how we protect it.

Encryption

Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256, across the platform — including uploaded documents and matter records. Encryption keys are managed through our cloud provider's key management service, with access restricted to production systems.

Access controls

Firms manage their own role-based permissions for partners, associates, and support staff. Client portal users only ever see the matters and documents your firm shares with them. Enterprise plans support SSO and firm-wide audit logs.

Data isolation

Each firm's matters, documents, and client data are logically isolated from every other firm on the platform.

Internal access

Nyaytech staff do not access the content of a firm's matters or documents except where necessary to provide requested support, investigate a security issue, or comply with a legal obligation — and such access is logged. See our Privacy Policy for more.

Backups and continuity

Firm data is backed up daily and retained for 30 days to guard against loss, with restoration procedures tested periodically as part of our operational practice.

Application security

We follow secure development practices, keep dependencies and infrastructure patched, and review changes before they reach production.

Incident response

In the event of a security incident affecting your firm's data, we will notify affected firms without undue delay and in any case within 72 hours of becoming aware of it, and take prompt action to contain and remediate the issue. See our Privacy Policy for more on breach notification.

Responsible disclosure

If you believe you've found a security vulnerability in Nyaytech, please report it to security@nyaytech.com. We ask that you give us a reasonable opportunity to investigate and address it before any public disclosure. We will not pursue legal action against researchers who report vulnerabilities in good faith, avoid privacy violations and data destruction, and comply with this policy.