Security & compliance

Built for regulated teams

ContractRisk.io protects your contracts with enterprise-grade security controls, region-aware compliance, and transparent operations.

AES-256 at restGDPR ยท DPDP ยท UAESSO / SAML + MFANo AI training on your data
๐Ÿ”’

Data Protection

๐Ÿ”’

Encryption in transit

TLS 1.2+ enforced for all ingress with HSTS and modern ciphers.

๐Ÿ”’

Encryption at rest

Managed keys with AES-256; backups encrypted and region-bound.

๐Ÿ”’

No AI training on your data

Your contracts never train shared models. Isolation by design.

๐Ÿ“œ

Compliance

๐Ÿ“œ

GDPR (EU)

DPA and SCCs available; EU data residency on request.

๐Ÿ“œ

DPDP (India)

Data localization support with India-based storage and access controls.

๐Ÿ“œ

UAE data residency

Awareness and optional UAE-region storage with mirrored backups.

โ˜๏ธ

Infrastructure

โ˜๏ธ

Cloud hosting

Hardened VPC, private subnets, WAF, and continuous patching.

โ˜๏ธ

Region-specific storage

EU, India, and UAE storage options; customer pinning supported.

๐Ÿ›ก๏ธ

Operational Security

๐Ÿ›ก๏ธ

Access controls

SSO/SAML, MFA, and least-privilege principles across environments.

๐Ÿ›ก๏ธ

Audit logs

Immutable logs for access, uploads, and policy changes.

๐Ÿ›ก๏ธ

Role-based access

Granular roles for admins, reviewers, and external counsel.

Talk to security

Need a DPA, SOC controls, or pen-test report?

Our security team will respond within one business day.