Security

Secure your most sensitive documents with enterprise-level security.

Every contract, agreement and compliance record indexed, searchable and retrievable in one repository. Security is not an add-on — it is the foundation of Legatio.

Certified.

Independently audited and issued. Each certificate is published here in full rather than described.

ISO 9001 certificate issued to Trayambic LLP
CertifiedISO 9001Our commitment to delivering reliable, consistent and continuously improving products and services.

View the certificate (PDF, opens in a new tab)

ISO 27001 certificate issued to Trayambic LLP
CertifiedISO 27001The globally recognised framework for protecting sensitive information, through rigorous security controls, risk management and continuous improvement.

View the certificate (PDF, opens in a new tab)

ISO 27701 certificate issued to Trayambic LLP
CertifiedISO 27701Strengthens privacy and data protection, and supports accountability with partners, clients and regulators through evidence-based privacy management.

View the certificate (PDF, opens in a new tab)

Startup India certificate issued to Trayambic LLP
CertifiedStartup IndiaLegatio is recognised by the Government of India as a validated startup.

View the certificate (PDF, opens in a new tab)

Aligned.

Regulatory frameworks Legatio is built to meet. These are statements of compliance posture rather than third-party certifications, and are described that way deliberately.

AlignedDPDP Act, 2023A privacy-first posture built to India's Digital Personal Data Protection Act — building trust, reducing financial and reputational exposure, and mirroring international data protection standards.
AlignedGDPRAligned to the General Data Protection Regulation, which protects the privacy rights of individuals by giving them control over their own information.
AlignedHIPAAAligned to HIPAA's safeguards for Protected Health Information, covering the confidentiality, integrity and availability of patient data.

Software security.

Four controls that apply to every document on the platform, on every plan.

01

Role-based employee access

Legatio follows role-based access control and least-privilege principles. Access is restricted to each user's responsibilities: root administrators have full platform access, while operating administrators are limited to template upload and customisation and cannot reach stored documents. Every document, signing, upload and download action is recorded in an audit log.

02

Tenant and environment isolation

Each corporate client's data is kept logically separate. Business users reach only the templates, packages, documents and records assigned to their organisation, and recipients reach only the documents sent to them, after authentication. Production, testing and development environments stay isolated so non-production work never touches live customer data.

03

Secure document storage and data protection

Signed documents are held in a protected vault, reached through user permissions, authenticated sessions, secure document links and OTP verification for recipients. The platform keeps a document activity history covering access events, signing actions, downloads, timestamps, device and browser information, and IP address. Document data is encrypted in transit and at rest, with retention periods set by administrators against your own compliance obligations.

04

Secure infrastructure, integrations and network controls

Legatio runs on hardened, regularly patched production infrastructure with restricted administrative access and secure network controls. External integrations — Aadhaar OCR and eSign, DSC signing, SMS and email delivery, eMSign — use authenticated APIs and protected webhook endpoints, and integration events are validated, logged and processed to preserve document integrity and a complete audit trail.

Third-party sub-processors.

Named rather than described. Each is bound by a Data Processing Agreement compliant with the DPDP Act, 2023, the IT Act, 2000 and the CERT-In Directions, and processes data only on Legatio's documented instructions.

Sub-processorFunctionLocation
DigioAadhaar eSign, eKYC and DSC-based signingIndia
Amazon Web ServicesPlatform infrastructure and encrypted vault hostingIndia — Mumbai region
Jio TrueConnectSMS and OTP gatewayIndia
AWS Simple Email ServiceTransactional email deliveryIndia
PCI-DSS payment gatewaysPayment processing — no card data is stored by LegatioIndia

A copy of any data processing agreement is available on request. No customer data is transferred, processed or stored outside India.

Security questions we get asked.

Can Legatio read our documents?

No Legatio employee has standing access to the contents of your documents. Documents are encrypted in transit and at rest and held in a segregated vault; access is role-based and least-privilege, requires an approved support or troubleshooting purpose, and every access event is written to the audit trail you can read. Root administrator access is restricted, logged and reviewed.

Do you train AI models on our contracts?

No, and this is a contractual commitment rather than a preference. Legatio does not use document content, user content or personal data for the training, fine-tuning or benchmarking of any artificial intelligence, machine learning or large language model. Nor is your data sold, rented or commercially transferred to anyone.

What happens if an employee leaves our organisation?

Administrators can revoke access immediately, without affecting the ownership or availability of company documents. All files, workflows and audit history remain under your organisation's control.

Why should enterprises trust Legatio with business-critical documents?

Legatio is designed for organisations where documentation is business-critical. ISO 27001 and ISO 9001 certification, enterprise-grade security controls, auditability, role-based access management and legally recognised digital signing workflows together cover the complete document lifecycle.

Can someone modify a signed document?

No. Once a document has been digitally signed, any modification changes its integrity and is detectable. Legatio keeps version history and audit records, so you always know what changed, when, and by whom.

Can Legatio employees view our confidential documents?

No. Your documents remain your organisation's property. Legatio follows strict internal access controls, and customer data is not accessed without explicit authorisation for an approved support or troubleshooting purpose.

How does Legatio help during audits and compliance reviews?

Legatio centralises your documents, maintains version control, records every activity through audit logs and provides secure storage. That significantly reduces the time spent locating records and preparing for an internal or external audit.

Send it to your infosec team.

Security review documentation, data processing terms and the certificates above are available for your review.

Talk to our security team