Encrypted vault
LiveAES-256 at rest, TLS 1.3 in transit, AWS Mumbai region by default.
- ✓AES-256 at rest, TLS 1.3 in transit
- ✓Per-org KMS-backed encryption keys
- ✓Default AWS Mumbai (ap-south-1) region
- ✓Region pinning for enterprise contracts
What it is.
Every document you store on LexVio is encrypted at rest with AES-256 using per-organisation keys. Transport is TLS 1.3. Storage region defaults to AWS Mumbai (ap-south-1), with the option to pin to a different region for enterprise contracts.
Your data never leaves India under the default configuration. Sub-processors that must be reached (model inference, error monitoring) operate under the contractual safeguards in our DPA.
Three steps.
End to end.
Drag a file into your vault. Encrypted before it hits storage.
Each organisation gets its own KMS-backed key. Key rotation is automatic.
India residency by default, with a region-pin option for enterprise plans.
What you get.
- ✓AES-256 at rest, TLS 1.3 in transit
- ✓Per-org KMS-backed encryption keys
- ✓Default AWS Mumbai (ap-south-1) region
- ✓Region pinning for enterprise contracts
- ✓Quarterly backup tests + 90-day backup retention
Quick answers.
Primary in AWS ap-south-1 (Mumbai). Encrypted backups replicated to a secondary AWS India region. Sub-processor outbound is per the DPA.
More in Vault & Document Management.
Per-document share links with expiry, password, and watermarking.
Every edit is versioned. Diff any two versions side-by-side.
Role-based access (admin / member / guest) with per-folder overrides.
Upload thousands of documents in one go with automatic parsing and indexing.