Your Data Is Sacred.
We Treat It That Way.
Enterprise-grade security designed for attorney-client privilege. Built from the ground up to meet the most demanding security requirements in the legal industry.
Defense in Depth
Multiple independent layers of security protect your firm's data at every level — from encryption to access control to audit logging.
Data is encrypted in transit with TLS and at rest via AWS KMS at the storage layer — databases (RDS) and document storage (S3). Selected sensitive fields use additional application-level AES-256 encryption.
Intrusion detection, vulnerability scanning, and security patching on AWS infrastructure. Architecture designed to meet enterprise trust service criteria — security, availability, processing integrity, and confidentiality.
AI features powered by Claude through AWS Bedrock under our Business Associate Agreement (BAA). Your data is never used for model training, improvement, or any other purpose. Data stays within US AWS regions.
Security practices designed to meet Massachusetts Standards for the Protection of Personal Information. Including access controls, encryption, breach notification procedures, and regular security assessments.
Key actions — logins, AI calls, and permission and data changes — are recorded in tamper-evident audit logs capturing actor, timestamp, and IP address.
Request an export or full deletion of your firm's data by contacting us; deletion is completed within 90 days of a verified request, subject to legal-hold obligations. You can also delete individual AI conversations from within the platform.