Security Questions to Ask Any Legal Software Vendor in India
A practical checklist of the security questions every Indian law firm, advocate, or in-house legal team should ask before signing up with any legal software vendor.
Buyer’s Guide · Vendor Security
Legal software vendors ask for some of the most sensitive material a firm holds: pleadings, client instructions, privileged correspondence, and case strategy. Before you hand that over, you need straight answers on where the data lives, who can see it, and what happens if something goes wrong. This checklist sets out the security questions to put to any legal software vendor in India, in plain language, so you can compare answers instead of taking a sales pitch on faith.
- Ask before you sign: where data is stored, who can access it, and what happens in a breach, all in writing.
- The newest must-ask question: does the vendor use your documents to train its AI models?
- Get it in the contract: a verbal promise on a sales call is not enforceable; the SLA and contract are.
- On AI training, Claw states plainly: it does not use customer case documents to train AI models.
01Why vendor security is a real risk in Indian legaltech
Legal work runs on confidential material. Case files, client instructions, settlement terms, board minutes uploaded for a dispute, all of it is sensitive, and much of it is privileged. When you move that work onto a software platform, you are trusting a third party with it, often without a way to check what actually happens to the data once it is uploaded.
The stakes are higher than a normal SaaS purchase
If a CRM or accounting tool has a security lapse, it is a business problem. If a legal software vendor mishandles case data, it can mean a breach of client confidentiality, a professional conduct issue, and in some cases a breach that has to be disclosed. Lawyers and in-house teams carry a duty of confidentiality that does not pause because the file sits in someone else’s cloud.
The DPDP Act changes the baseline
India’s Digital Personal Data Protection Act, 2023 sets out how personal data must be processed, with rules notified in 2025. Any vendor that stores client or case data containing personal information is a data processor under this framework, and your firm, as the data fiduciary in many cases, carries responsibility for choosing a vendor that can meet those obligations. That makes vendor security due diligence a compliance question, not just an IT question.
AI adds a new question that did not exist before
Many legal software vendors now build AI features into search, drafting, or document review. That raises a question buyers did not used to have to ask: does the vendor use the documents you upload to train its AI models? If the answer is yes, or is unclear, your confidential material could end up shaping outputs seen by other users. This is now one of the first questions serious buyers ask.
Part of a bigger buying decision
Security is one part of choosing legal software. For the full buying checklist, covering coverage, cost, support, and more, see 15 questions to ask before buying legal software in India.
02What a good answer looks like
Before the checklist itself, it helps to know what separates a good answer from a vague one. Four things matter across every question below.
- Specific, not generic: a vendor that says “we take security seriously” has told you nothing. A good answer names where data is stored, who can access it, and what happens in a breach.
- In writing: a sales call answer is not a commitment. Ask for the answer in the contract, the SLA, or a data processing addendum.
- Verifiable: the vendor should be able to point to a policy, a page, or a document, not just a verbal assurance.
- Consistent across vendors: ask every vendor you evaluate the same questions, in the same order, so you can actually compare the answers.
A vendor that cannot answer where your data lives and who can see it has not answered the most basic question in the checklist.
03The checklist: security questions to ask
Ask these questions of every legal software vendor you shortlist, whether it is an AI legal chatbot, a litigation tracking tool, or an all-in-one platform. Group them by category so nothing gets missed.
Data storage and residency
- Where is our data physically stored, and does it ever leave India? Some vendors host on servers within India; others use global cloud regions. Neither is automatically wrong, but you should know which applies, since it affects your DPDP obligations.
- How long is our data retained after we stop using the service, and who deletes it? A vendor should have a clear deletion timeline, not an open-ended “we keep it.”
Access control and authentication
- Who inside the vendor’s team can see our documents, and why? Support staff and engineers often need some access to troubleshoot. Ask how that access is limited and logged.
- What authentication options does the platform support for our own users? Look for basics like enforced strong passwords and, ideally, multi-factor authentication, so a single stolen password cannot expose your whole matter list.
AI and data use
- Does the vendor use our documents, or documents like ours, to train its AI models? This is the question buyers most often forget to ask, and it matters most for any tool with AI search, drafting, or chat features. Get this answer in writing, not just verbally.
- If the vendor uses AI, does it show the source behind an AI-generated answer or citation? An AI answer you cannot trace back to a real judgment or clause is a risk in itself, separate from data security.
Compliance and breach response
- How does the vendor comply with the DPDP Act, 2023? Ask specifically, not generally: what is their process for consent, data minimisation, and responding to a data principal’s request.
- What is the vendor’s process if there is a data breach, and will they notify us? A vendor should be able to describe a breach response process, including a commitment to notify you within a defined time.
Data portability and vendor lock-in
- Can we export our data if we switch vendors, and in what format? A vendor that makes it hard to leave with your own case data is a red flag, regardless of how good the security story sounds otherwise.
- What happens to our data if the vendor is acquired or shuts down? This is uncomfortable to ask but worth asking, especially with newer or smaller vendors.
Third parties and contractual protection
- Which third-party services or subprocessors does the vendor use, for example cloud hosting or payment processing? Your data’s security is only as strong as the weakest link in that chain.
- What does the contract actually say about security, liability, and confidentiality? This is the answer that matters most, because it is the one you can enforce. Get everything above written into the agreement, not left as a verbal promise.
04Why each category of question matters
| Question category | Why it matters | What a strong answer includes | A red flag to watch for |
|---|---|---|---|
| Data storage and residency | Affects your DPDP obligations and your control over the data | Named storage location, clear retention and deletion timeline | Vague answer, or “we will check and get back to you” |
| Access control | Limits how much damage one compromised account or employee can do | Documented internal access limits, MFA support for your users | No mention of who inside the vendor can see your files |
| AI and data use | Determines whether your confidential documents shape AI outputs seen by others | A plain written statement that customer documents are not used to train AI models | Evasive answer, or “we use data to improve the product” with no detail |
| Compliance and breach response | Determines your legal exposure if something goes wrong | A named breach process with a notification commitment | No breach process, or compliance answered only in marketing language |
| Data portability | Determines whether you are trapped with the vendor even if the relationship sours | Clear export format and process, stated in the contract | Export possible only in a locked or unusable format |
| Third parties and contract terms | Your security is only as strong as the weakest link, and only enforceable if it is in writing | Named subprocessors, security terms written into the SLA | Security promises made only verbally, not in the contract |
05How to use this checklist when evaluating vendors
Do not run this checklist informally in a sales call. Send it in writing, to every vendor you shortlist, and ask for written answers before you sign. A vendor that is confident in its security posture will not mind putting it in writing; a vendor that hesitates has told you something too.
A few practical steps make this easier. Loop in whoever handles compliance or IT at your firm, even if that is a part-time role, since some of these answers need a technical read. Ask the same questions of every vendor, including AI-based tools like NyayGuru and VIDUR AI, so the answers are comparable. Get the answers written into the contract or a data processing addendum, not left as a verbal promise from a sales call. And treat the AI training question as a must-answer item, since it is newer and easy for a vendor to gloss over.
Security is one part of the buying decision. For the wider set of questions to ask, including on coverage, pricing, and support, see the full 15 questions before buying legal software in India guide.
06Where Claw fits
Claw is an all-in-one legaltech platform for Indian advocates, law firms, and corporate legal teams, combining AI-based case search, an AI legal assistant (Legal GPT), case management, and compliance automation across all Indian courts and tribunals.
On the specific point that this checklist puts first among the newer questions, Claw states plainly that it does not use customer case documents to train AI models. That is a direct, written answer to question 5 above, and it is the kind of answer this checklist is designed to draw out of any vendor you evaluate, including Claw itself. Ask every AI-based legal tool you shortlist, including NyayGuru and VIDUR AI, the same question in writing, and compare the answers side by side rather than taking any vendor’s word for it on a call.
For a deeper look at how Claw handles data privacy specifically, see Claw security and data privacy.
07Sources and further reading
References used for this checklist:
- Digital Personal Data Protection Act, 2023 and Rules (Ministry of Electronics and IT): meity.gov.in/data-protection
- eCourts (official portal, source of truth for case data): ecourts.gov.in
- National Judicial Data Grid (NJDG): njdg.ecourts.gov.in
- Claw: clawlaw.in
- NyayGuru: nyayguru.com
- VIDUR AI: vidur.in
This checklist is general guidance, not legal advice. Confirm specific security and compliance claims directly with each vendor before you sign.
08Frequently asked questions
What is the most important security question to ask a legal software vendor in India?
There is no single most important question, but three come first: where is the data stored, who inside the vendor can access it, and does the vendor use your documents to train AI models. Get all three answered in writing before you sign.
Does the DPDP Act apply to legal software vendors?
Yes, in general. Any vendor that processes personal data on your behalf, including client or case data containing personal information, sits within the Digital Personal Data Protection Act, 2023 framework, with rules notified in 2025. Your firm carries responsibility too, so vendor due diligence is part of your own compliance.
Why does it matter if a vendor uses documents to train AI models?
If a vendor trains its AI on customer documents, your confidential case material could shape outputs that other users see. This is a newer risk that did not exist before AI features became common in legal software, so it is worth asking directly and getting the answer in writing.
Should I ask the same security questions to every vendor I evaluate?
Yes. Asking the same checklist of every shortlisted vendor, including AI-based tools, is the only way to compare the answers fairly. A vendor that answers clearly and in writing has told you more than one that answers vaguely on a call.
Does Claw train AI models on customer case documents?
No. Claw states plainly that it does not use customer case documents to train AI models. This is one of the direct answers this checklist is designed to draw out of any legal software vendor, and it is worth confirming the same in writing from every vendor you evaluate.
What should be in the contract, not just the sales pitch?
Data storage location, retention and deletion timelines, breach notification commitments, data export terms, and named subprocessors should all be written into the contract or a data processing addendum. If a vendor will not put its security answers in writing, treat that as a red flag on its own.