Skip to content

Security and privacy

Your cases aren't our data.

The simplest way to protect case files is to never receive them. The toolboxes do their work on the attorney's computer, and Indictra never has a copy.

What leaves the computer

What leaves the computer, and what never does.

Case files

Read and kept on the attorney's computer, in a case library folder. Defender's Toolbox encrypts case records at rest with a key protected by Windows, and won't put the library in a cloud-synced or network folder.

Updates and the subscription check

Each toolbox contacts its own update server to download signed updates and to renew a short signed lease that says the license is active. That request carries the license id and, for licenses limited to a number of computers, a hashed device id that names no person. Never case data.

AI, if you turn it on

Bryce Bot uses Claude on Amazon Bedrock in your own AWS account: AWS GovCloud for a DA's office, the firm's own account for defense counsel. Requests go from the app to your account, never through Indictra, and only when the attorney asks.

Telemetry

None. No analytics, crash reports or usage counters are sent from the apps. Client names are kept out of logs and notifications.

Built in

Protections in the apps themselves.

  • Signed Windows installers and updates; an update that isn't signed by us isn't installed.
  • The app window blocks requests to anywhere but the app itself and, when connected, your own AI account.
  • Documents in a case are treated as evidence. Text inside a file is never followed as an instruction, by the app or by Bryce Bot.
  • Prosecutor's Toolbox and Defender's Toolbox use separate license keys, update servers and storage. Neither can reach the other.
  • Defender's Toolbox backups are encrypted with a passphrase only you know. We can't open them or recover the passphrase.
  • If a subscription ends, saved cases still open and print. Only new work stops.

What we do keep

Licenses, not cases.

To license the toolboxes we keep a record of each customer office or firm (its name, contacts and agreement dates), the licenses we issue, and whether each subscription is on. Our update servers keep the list of devices a limited license is used on, as hashed ids. Changes to any of that are written to an audit log.

Found a security problem? Email support@indictra.com with "Security" in the subject. We'll answer you directly.

Questions from your IT or security team?

We're happy to go through the network traffic, installers and AI setup with them.