Skip to content
Aditya Puram, Gwalior, MP 474005 info@curioinfotech.com
+91 9202362121 Mon–Sat: 9:30 AM – 6:30 PM
Case Study

Legal Practice — Secure Document System

A role-based, encrypted document management system for a Gwalior law firm with six advocates — replacing scattered email attachments, USB drives and physical files with a single auditable repository that secured 10,000+ documents and brought the firm into DPDP Act compliance in six weeks.

Client Gwalior law firm, 6 advocates (anonymized)
Industry Legal & Professional Services
Location Gwalior, Madhya Pradesh
Duration 6 weeks
Services Software DevelopmentInformation SecurityCloud Deployment
6
Advocates onboarded
6 wk
Delivery
10K+
Documents secured
100%
Audit trail

The Challenge

The firm's documents lived everywhere and nowhere. Case files were split between physical cabinets in the Gwalior office, attachments buried in advocate email threads, scanned PDFs on office desktops, and — increasingly — USB drives that advocates carried between court and home. There was no version control, so the "latest" draft of any agreement was whichever copy someone happened to open. Important clauses had been overwritten more than once.

Access was effectively uncontrolled. Any advocate or clerk with a shared login could read any document, including matters they weren't assigned to — a confidentiality concern the senior partners had flagged but never resolved. There was no audit trail of who viewed, downloaded or edited what, and no remote-access path that didn't involve emailing a file to oneself. During the kind of disruption the pandemic had demonstrated, the firm had no way to keep working securely from home.

The senior partners also saw a regulatory wave coming. India's Digital Personal Data Protection (DPDP) Act, 2023 was reshaping how every professional services firm had to handle client data — with explicit obligations around access control, consent, breach notification and auditability. The firm's current setup, frankly, could not satisfy any of those obligations. They needed a single secure repository with role-based access, full audit logging and encrypted storage — and they needed it without disrupting court deadlines.

"We had no idea where the latest version of anything was. Half our documents were on someone's pen drive, the other half in an inbox, and we had no way to know who had read what. For a law firm, that's not just inefficient — it's a liability." — M____, Senior Partner

Our Solution

Curio opened with a one-week requirements and workflow-mapping sprint — sitting with each of the six advocates and two support staff to understand how a case file actually moved through the firm, from intake to filing to archival. The output was a role-and-permission matrix that mapped every document type (pleadings, evidence, agreements, client KYC, correspondence) to who should be able to view, edit, download or share it — and an explicit policy for matter-level confidentiality.

We built the document management system on Next.js with a Node.js API and PostgreSQL with column-level encryption for sensitive metadata, with documents themselves stored in AWS S3 encrypted through AWS KMS. Authentication is OTP-based — no passwords to lose or reuse — and every action (view, edit, download, share, delete) is written to an immutable audit log that the senior partners can query at any time. Role-based access control (RBAC) enforces matter-level confidentiality: an advocate only sees the matters assigned to them, and the senior partners see everything.

Because most legal documents arrive as scans, we built OCR-backed full-text search — so an advocate can type "section 138" or a party name and surface every relevant page across 10,000+ documents in seconds, instead of physically leafing through files. Version control keeps every draft, with a one-click diff. The system is hosted on AWS ap-south-1 for low latency from the Gwalior office, with daily encrypted backups and a documented restore runbook. Security hardening included TLS 1.3, rate-limiting, MFA for partner accounts, and a pre-launch external penetration test — with every control mapped explicitly to the firm's DPDP Act obligations.

  1. Requirements & Workflow Mapping
    One-week exercise with all 6 advocates + 2 staff — matter-flow mapping, document-type taxonomy and a role-and-permission matrix.
  2. DMS Design
    Role-based access control (RBAC), matter-level confidentiality model, audit-log schema and OCR search architecture.
  3. Development
    Next.js + Node.js build, PostgreSQL column-level encryption, AWS S3 + KMS, OTP auth, version control, full-text OCR search.
  4. Security Hardening & DPDP Compliance
    TLS 1.3, rate-limiting, partner MFA, external penetration test, DPDP Act control mapping, encrypted daily backups.
  5. Training & Go-Live
    Document migration from email + USB + physical scans, partner + advocate + staff training, go-live alongside active court deadlines.
Next.js Node.js PostgreSQL (Column-Level Encryption) AWS S3 + KMS Role-Based Access Control (RBAC) OTP Authentication Full Audit Logging Version Control + OCR Search

Results & Impact

10K+
Documents migrated & secured
100%
Audit trail on every view & edit
Sec
Retrieval time (from hours)
0
Data incidents since go-live

The firm migrated and secured more than 10,000 documents during the cutover — pleadings, evidence, agreements, client KYC and correspondence pulled out of email threads, USB drives and physical scans into a single auditable repository. Every view, edit, download and share is now logged against a named user, giving the senior partners 100% audit-trail visibility and a defensible posture under the DPDP Act. The firm has had zero data incidents since go-live.

Retrieval time — previously hours per case file, sometimes overnight if a clerk had to dig a physical folder out of storage — dropped to seconds, with OCR-backed search surfacing any clause, party or section reference across the entire corpus instantly. All six advocates and two support staff were trained and onboarded within the six-week window, with no disruption to active court deadlines. The senior partners now have matter-level confidentiality enforcement they can demonstrate to clients, and the firm can work securely from anywhere.

"Curio built us something I didn't think was possible in six weeks — a single secure repository with real access control and a full audit trail. We can find any document in seconds, we know who has read what, and for the first time we can look a client in the eye and say their files are properly protected. That matters in this profession." — M____, Senior Partner

Services Used

Next Case Study
Gwalior Hospital — Patient Portal →
How Curio built a secure patient portal for a 120-bed Gwalior hospital — cutting appointment wait times 60% and onboarding 15,000+ patients in 90 days.
Your Project Next

Want Results Like This?

Whether you're a law firm, a hospital, a manufacturer or a service business — we scope clearly, deliver transparently and report on the metrics that matter. Book a no-obligation consultation with our Gwalior team.