CourtMesh API Security
    Skip to main content

    API Security

    We would rather tell you what is missing than let a claim stand unchallenged until your own due diligence finds it.

    Security posture

    Where we stand today

    Not yet in place

    • SOC 2 Type II attestation
    • ISO 27001 certification
    • A published uptime, latency or freshness SLA

    Neither certification has a target date scoped yet.

    In place today

    • India hosting, with data residency in India
    • TLS in transit; API keys hashed and shown once, never stored in the clear
    • Per account audit log, plus a request id on every response for support to trace
    • Organisation level IP allowlisting, opt in through support
    • A live right to be forgotten pipeline: our case removal and de-indexing process running in production

    A data processing agreement is available on request, and we will complete a CAIQ or SIG style vendor questionnaire and sign a security addendum with incident response terms as part of an Enterprise conversation.

    Retention

    What we keep, and for how long

    Request records
    Retained 90 days by default, then purged.
    Billing transactions
    api_key_transactions rows are purged on a time to live index rather than kept indefinitely.
    Audit hits
    Per account API call records backing GET /audit and GET /usage are retained for billing, so your own usage history stays available to you.

    Breach process

    What happens if something goes wrong

    We notify affected customers within 72 hours of confirming a breach that affects their data or their account. That clock starts at confirmation, not at first suspicion, because an unconfirmed alert is not yet something we can respond to responsibly. What we send at that point: what is known so far, what we have already done, and what you should do on your side. A fuller report follows once the investigation is complete.

    Subprocessors

    Who else touches this data

    CourtMesh API subprocessors
    SubprocessorPurposeRegion
    AWSHosting, storage and computeap-south-1 (Mumbai)
    OpenAIAI analysis and adjudication, under a zero retention API usage agreementAPI, not self hosted
    RazorpayPayment processing for credit purchases and subscriptionsIndia

    Support

    Where to reach us

    support@courtmesh.ai for every plan, including security questions and incident reports. Enterprise customers get a named contact in addition to this address.

    No SLA is published today, stated plainly rather than implied by silence. See Request ids and support in the API documentation for what to include when you write to us about a specific call.