1.Our approach
Advocates trust us with confidential client and case information. We design the Platform so that each firm’s data stays private, every sensitive action is checked on the server, and important actions leave an audit trail.
We describe here only measures that are actually in place. We do not claim certifications we do not hold. Security also depends on how an account is used, so the last section lists what advocates should do.
2.Each firm’s data is kept separate
- All firms share one Platform, but every record belongs to exactly one firm. The server adds that firm to every database query automatically — the browser can never choose which firm’s data it sees.
- Opening another firm’s client, case, appointment, document or file, even with a correct link or ID, returns “not found”.
- Personal templates and saved Legal Library items are private to the user who created them, even inside the same firm.
- Automated tests try to read, change and delete another firm’s data before every release, and a database check verifies that no record points to another firm.
3.Sign-in and access control
- Passwords are stored only as bcrypt hashes. Nobody at MECGURA can see your password.
- Repeated failed sign-ins are slowed and temporarily blocked, per account and per network address.
- Sessions expire after 8 hours. Changing or resetting your password signs out every other session.
- Password-reset links are single-use and expire after 30 minutes. Only a hash of the link is stored.
- New accounts created by MECGURA must change their temporary password at first sign-in.
- Roles are enforced on the server: advocate (owner), staff, and MECGURA Super Admin. Owner-only actions, such as deleting records, are refused for staff.
- Paid modules are checked on the server for every page, action and file download — not only hidden in the menu.
4.Support access by MECGURA
If you ask for help, an authorised MECGURA Super Admin can open your dashboard in a “view as advocate” session. The session lasts at most one hour, a banner is shown for its whole duration, and its start and end — and every action taken during it — are recorded in the audit log.
5.Encryption and web protections
- The Platform is served only over HTTPS, with HTTP Strict Transport Security (HSTS) in production.
- Sign-in cookies are HTTP-only and marked Secure in production.
- Google Calendar access tokens are encrypted at rest with AES-256-GCM.
- Each page has a strict Content Security Policy (with a fresh random value per request), and pages cannot be embedded in other sites (clickjacking protection).
- Forms and actions check where a request came from, and public forms have rate limits and spam traps.
- User content is displayed as text, never run as code. Legal document templates are stored as plain text, not HTML.
6.Legal documents and share links
- Only final documents can be shared. Each link uses a 256-bit random token; we store only its hash, so the link cannot be recovered from our database.
- Every link expires. You can add a password (stored as a bcrypt hash and never included in the message sent to the client) and revoke the link at any time.
- Every view, download and wrong password attempt is logged and shown to you. Links are hidden from search engines and never cached.
- Documents are generated on our own servers. No document text is sent to an outside document service.
- Every save creates a new version, so earlier text is never silently overwritten.
7.Uploads and outside connections
- Uploaded images are re-processed on the server before they are stored. PDF uploads are checked to be real PDF files and have size limits.
- When the Platform fetches legal updates from external feeds, it blocks requests to internal or private network addresses.
- API keys and passwords for email, WhatsApp and Google are kept in server settings, never in the website code or the browser.
8.Audit logs
Important actions are recorded with time, user and network address. These include sign-ins, profile and case changes, document creation, finalisation, download, sharing and deletion, subscription changes, and every Super Admin change. Advocates can see the history on their clients, cases and documents.
9.Hosting, backups and incidents
- The database is not exposed to the internet. The Platform connects to it from the application server only.
- We take regular database backups and keep them for a limited period so data can be restored after a failure.
- Errors are logged on the server without showing technical details to users.
- If a security incident affects your data, we will contain it, inform you without undue delay, and notify the authorities and affected people as required by Indian law. See our Privacy Policy.
10.What you can do
- Use a long, unique password for your MECGURA account and do not share it. Give each staff member their own login.
- Sign out on shared or court computers.
- Remove staff access as soon as someone leaves your office.
- Share documents with the shortest expiry that works, add a password for sensitive documents, and revoke links you no longer need.
- Contact us immediately if you notice anything unusual in your account.
11.Reporting a vulnerability
If you believe you have found a security problem, please email support@mecgura.tech with the details and steps to reproduce it. Please do not access, change or delete other people’s data, and give us reasonable time to fix the issue before telling anyone else.
We will acknowledge your report, keep you informed, and will not take legal action against good-faith research that follows these rules.