Cybersecurity researcher Nisarga Adhikary claimed on September 8 that he accessed Adalat AI’s entire infrastructure, including its database, storage, credentials, and private source code, revealing critical security vulnerabilities. Adalat AI is a startup promoted by the Ministry of Electronics and Information Technology (MeitY) and has been involved in government-backed technology initiatives, according to medianama.com.
Adhikary initially alleged that sensitive court data was processed on production servers located in Japan but later clarified that the data he accessed was publicly available research data, as confirmed by Adalat AI’s founders. However, he maintained that the company’s deployment, DevOps, production infrastructure, and source code were compromised. His findings included full infrastructure compromise, access to live credentials, Kubernetes cluster-admin rights, and exposure of over 90 internal private source-code repositories, as detailed in an email he sent to the Adalat AI team.
The disclosure raises concerns about the security standards of startups supported by MeitY, especially those handling sensitive judicial data. Adhikary criticized the quality of these startups and questioned their claims regarding data sovereignty. The incident highlights the risks associated with government-backed technology projects that may lack robust cybersecurity measures, potentially exposing critical data and infrastructure to unauthorized access.
Adalat AI’s security vulnerabilities were publicly revealed on September 8, 2026, following Adhikary’s detailed disclosure and social media posts. The startup’s founders have acknowledged the nature of the data accessed but dispute the claim of sensitive data exposure beyond publicly available information, according to medianama.com.