← All features
Vault & Document Management

Encrypted vault

Live

AES-256 at rest, TLS 1.3 in transit, AWS Mumbai region by default.

What you get
  • AES-256 at rest, TLS 1.3 in transit
  • Documents stored in AWS Mumbai (ap-south-1)
  • Region pinning on self-hosted and private-cloud deployments
  • 90-day backup retention
Overview

What it is.

Every document you store on LexVio is encrypted at rest with AES-256. Transport is TLS 1.3. Storage is in the AWS Mumbai (ap-south-1) region. Self-hosted and private-cloud deployments can pin storage to a region of your choosing.

Your documents are stored in India. Model inference and error monitoring are performed by sub-processors that process content outside India under the contractual safeguards in our DPA — the current list is published there.

How it works

Three steps.
End to end.

01
1. Upload

Drag a file into your vault. Encrypted before it hits storage.

02
2. Encrypted at rest

Objects are encrypted before they land in storage, in the AWS Mumbai region.

03
3. Compliant by default

India residency by default, with a region-pin option for enterprise plans.

Capabilities

What you get.

  • AES-256 at rest, TLS 1.3 in transit
  • Documents stored in AWS Mumbai (ap-south-1)
  • Region pinning on self-hosted and private-cloud deployments
  • 90-day backup retention
FAQ

Quick answers.

Where exactly does my data live?

Primary in AWS ap-south-1 (Mumbai). Encrypted backups replicated to a secondary AWS India region. Sub-processor outbound is per the DPA.

Related

More in Vault & Document Management.

Shared document links
Live

Per-document share links with expiry, password, and watermarking.

Version history
Live

Every edit is versioned. Diff any two versions side-by-side.

Folder permissions
Live

Role-based access (admin / member / guest) with per-folder overrides.

Bulk upload + ZIP ingest
Live

Upload thousands of documents in one go with automatic parsing and indexing.

Want to try Encrypted vault?
Get started in 60 seconds.

Sign up →All features