This page states what this codebase actually does today, not what a certification would let us claim. Where something is a real gap, it says so — an omission would be worse than the gap itself.
Every matter, document, client and draft is scoped by PostgreSQL row-level security, enforced at the database itself for every request — not a filter inside application code a single bug could bypass.
An advocate's session can only ever read rows carrying their own advocate id. This holds structurally, the same way for every table, not as a per-feature check someone has to remember to add.
Client documents, drafts and case records are never used to train or fine-tune any model, ours or a third party's.
An action a system administrator takes on your account — including an attempt that was refused — is written to an append-only log: one that a direct database command cannot alter or delete after the fact, enforced by the database itself, not merely by the absence of an edit button.
Every one of these tables carries a database trigger that rejects any UPDATE or DELETE outright — proven directly against the database in this codebase's own test suite, not assumed from the absence of a route. A record, once written, cannot be quietly edited or removed later, by anyone.
Every owner-level action on an account (a profile edit, a suspension, an export, an erasure); every attempt to reach an admin-only or owner-only area of the system, allowed or refused; and every time an AI request is stopped before it reaches a model or your case data, with the reason it was stopped.
Nobody outside Aadhrix's own operators. They exist to hold Aadhrix accountable for its own privileged actions, not as a feature an advocate queries about their own account.
90 days, then automatically removed.
Kept for as long as the account exists — hearings, documents, drafts and fee entries are working case data, not a log. Removed only on account erasure.
Which source backed which sentence of an answer or draft is kept permanently and cannot be edited — the same accountability principle as the admin logs above, applied to Aadhrix's own AI output rather than to human action.
Export, correction and erasure of your account are all real today. Erasure — “Relinquish My Account,” in your account settings — is a genuine, irreversible deletion, not a deactivation, confirmed by re-entering your password before it runs. A data export still goes through hello@aadhrix.com rather than a self-service button — the one real gap left in this section worth naming rather than smoothing over.
Two things this page will not pretend are already solved:
There is no automated intrusion-detection system or a tested breach-notification runbook in place today.
Aadhrix does not hold SOC 2, ISO 27001, or any other independently audited certification. Nothing on this site claims otherwise.
Aadhrix checks every “Section N of the X Act” in a draft or an answer against the Acts it holds. We measure that check the same way each time: 249 real citations generated from the indexed Acts themselves (each must resolve to exactly its own section) and 166 deliberately non-existent section numbers of the same Acts (none may resolve), across 83 Acts, with a fixed random seed so the run is reproducible.
249 of 249 real citations resolved to exactly the right Act and section. 0 were reported as ambiguous (the same words name two indexed Acts) and 0 were not resolved at all.
0 real citations were matched to the wrong provision. 0 of the 166 non-existent sections were wrongly “found” — a 0% false-positive rate.
Whether a cited passage actually supports the sentence citing it needs a model call and is not exercised while AI is unavailable in this deployment. The cases are generated from the corpus, so short forms, typos and Acts outside the corpus are not represented. Run of 2026-09-24.
The same run also measures the other ways a pleading cites law. Two sections of one Act in a single “Sections A and B” sentence: 83 of 83 resolved both (100%). Orders and Rules of the Code of Civil Procedure's First Schedule: 40 of 40 real rules resolved (100%), and 0 of 15 non-existent rule numbers were wrongly found. Articles of the Limitation Act's Schedule: 40 of 40 resolved (100%), 0 of 10 non-existent Articles wrongly found.
India's Digital Personal Data Protection Rules, 2025 were notified in a staggered, three-phase commencement set by the Ministry of Electronics and IT: administrative provisions took effect 14 November 2025, the Consent Manager registration framework becomes operative 14 November 2026, and the substantive data-protection obligations — consent, breach notification, data-principal rights — become effective 14 May 2027. Today, Aadhrix is in that first phase: none of the Act's substantive obligations are yet legally in force. The practices on this page are followed as good practice ahead of that date, not because a deadline requires them yet.
This page is an engineering description, not legal advice. It describes what this codebase does today, verified directly against its own source. Nothing here should be relied on as a compliance opinion.