Grouped by category. Open any control for what it means in practice. A gold marker means the control is in progress or available on request.
Every row carries a firm identifier, and Postgres row-level security enforces separation at the data layer — not just in application code. Cross-firm access is structurally impossible except through explicit, consented co-counsel sharing.
AES-256 at rest and TLS 1.2+ in transit across the platform, with cloud-native key management. Bring-your-own-key is available on Enterprise.
Data is hosted in the United States on SOC 2-attested infrastructure providers. Regions and providers are disclosed under Subprocessors.
Platform and security events are logged centrally for detection, alerting and forensics, separate from the per-firm application audit trail.
Automated, encrypted backups with point-in-time recovery, and a documented recovery plan with defined objectives.
Dependency and infrastructure scanning in the pipeline, plus annual third-party penetration testing. The latest summary is available under NDA.
Access follows defined firm roles. Permissions are least-privilege by default and administered by each firm’s own admins.
Access narrows to the specific matters a user is on, and ethical walls are enforced before retrieval — including before the AI reads anything.
Users can enroll an authenticator app (TOTP) and a mobile number for SMS text codes — both at once if they choose. MFA is mandatory for admin and finance roles.
Single sign-on and directory-driven provisioning and de-provisioning for firms that standardize on an identity provider.
Authorized support access is role-restricted, used only to operate and support the platform, and written to an append-only audit trail.
The AI chat agent has no write or money tools. To create a task, note or prebill it proposes an action a human approves — it never executes. Money and irreversible actions are always human-gated.
Retrieval is intersected with the user’s accessible matters, minus ethical walls, before anything reaches the model. The AI cannot cite across firms or matters.
A hash-chained, append-only record of every prompt, document accessed, output and action — exposed in a per-firm AI Audit View.
Credentials are stored in managed secret stores. Rose Legal AI runs on a dedicated, workspace-scoped key with isolated usage and spend.
Code review, automated checks and staged deploys. Change management is being formalized under SOC 2 and ISO 27001.
Your documents and work product stay yours. Full export is available on request, on the way in and the way out — no lock-in.
Client data is never used to train models. Enterprise model-vendor terms prohibit retention and training; the system learns per firm from your own outcomes, never a shared model.
Customer data is retained and deleted per the customer agreement, subject to legal-hold requirements. Deletion requests are honored on documented timelines.
Customer-managed encryption keys via your own cloud KMS, so you can rotate or revoke access to sensitive fields. In development for the Enterprise tier; design available for review.
A documented information-security policy set, reviewed at least annually and on material change.
Personnel undergo background screening where lawful and complete security-awareness training; confidentiality obligations apply to all staff.
Subprocessors are reviewed before onboarding and bound by confidentiality and data-protection terms. The current registry is published under Subprocessors.
A documented incident-response plan with defined roles and breach-notification timelines consistent with applicable law and the customer agreement.
Continuity planning so the platform and your data remain available and recoverable through disruption.
Auto-act when certain, verify in place when unsure, route to a human when there is no match — never an irreversible action without sign-off.
Authority citations and quotes come only from the compare-to-authority tool; document facts carry a verbatim quote and source. No fabricated citations.
A proprietary orchestration layer spans model providers, so a single vendor’s policy change never changes your security posture. Aligned to ABA Formal Opinion 512.
We share our SOC 2 report, subprocessor registry, BAA and DPA under NDA, and will walk your team through the controls.