Firms trust Nyaytech with privileged case data. Here's how we protect it.
Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256, across the platform — including uploaded documents and matter records. Encryption keys are managed through our cloud provider's key management service, with access restricted to production systems.
Firms manage their own role-based permissions for partners, associates, and support staff. Client portal users only ever see the matters and documents your firm shares with them. Enterprise plans support SSO and firm-wide audit logs.
Each firm's matters, documents, and client data are logically isolated from every other firm on the platform.
Nyaytech staff do not access the content of a firm's matters or documents except where necessary to provide requested support, investigate a security issue, or comply with a legal obligation — and such access is logged. See our Privacy Policy for more.
Firm data is backed up daily and retained for 30 days to guard against loss, with restoration procedures tested periodically as part of our operational practice.
We follow secure development practices, keep dependencies and infrastructure patched, and review changes before they reach production.
In the event of a security incident affecting your firm's data, we will notify affected firms without undue delay and in any case within 72 hours of becoming aware of it, and take prompt action to contain and remediate the issue. See our Privacy Policy for more on breach notification.
If you believe you've found a security vulnerability in Nyaytech, please report it to security@nyaytech.com. We ask that you give us a reasonable opportunity to investigate and address it before any public disclosure. We will not pursue legal action against researchers who report vulnerabilities in good faith, avoid privacy violations and data destruction, and comply with this policy.