All controls monitoredLast updated October 2026Hosted in the United StatesAppend-only audit on every action
Legal by Rose
Controls

Security & privacy controls

Grouped by category. Open any control for what it means in practice. A gold marker means the control is in progress or available on request.

01

Infrastructure Security

6 controls
INF-01Tenant isolationEnforced+

Every row carries a firm identifier, and Postgres row-level security enforces separation at the data layer — not just in application code. Cross-firm access is structurally impossible except through explicit, consented co-counsel sharing.

INF-02Encryption at rest & in transitEnforced+

AES-256 at rest and TLS 1.2+ in transit across the platform, with cloud-native key management. Bring-your-own-key is available on Enterprise.

INF-03US-based cloud infrastructureEnforced+

Data is hosted in the United States on SOC 2-attested infrastructure providers. Regions and providers are disclosed under Subprocessors.

INF-04Continuous monitoring & loggingEnforced+

Platform and security events are logged centrally for detection, alerting and forensics, separate from the per-firm application audit trail.

INF-05Backups & disaster recoveryEnforced+

Automated, encrypted backups with point-in-time recovery, and a documented recovery plan with defined objectives.

INF-06Vulnerability management & penetration testingAnnual+

Dependency and infrastructure scanning in the pipeline, plus annual third-party penetration testing. The latest summary is available under NDA.

02

Access Control & Authentication

5 controls
ACC-01Role-based access control (RBAC)Enforced+

Access follows defined firm roles. Permissions are least-privilege by default and administered by each firm’s own admins.

ACC-02Matter-level scope & ethical wallsEnforced+

Access narrows to the specific matters a user is on, and ethical walls are enforced before retrieval — including before the AI reads anything.

ACC-03Multi-factor authentication — authenticator & SMSAvailable+

Users can enroll an authenticator app (TOTP) and a mobile number for SMS text codes — both at once if they choose. MFA is mandatory for admin and finance roles.

ACC-04SSO / SAML / SCIMEnterprise+

Single sign-on and directory-driven provisioning and de-provisioning for firms that standardize on an identity provider.

ACC-05Audited platform-support accessEnforced+

Authorized support access is role-restricted, used only to operate and support the platform, and written to an append-only audit trail.

03

Product Security

5 controls
PRD-01Separation-of-duties money gateEnforced+

The AI chat agent has no write or money tools. To create a task, note or prebill it proposes an action a human approves — it never executes. Money and irreversible actions are always human-gated.

PRD-02Privilege-filtered AI retrievalEnforced+

Retrieval is intersected with the user’s accessible matters, minus ethical walls, before anything reaches the model. The AI cannot cite across firms or matters.

PRD-03Tamper-evident audit trailEnforced+

A hash-chained, append-only record of every prompt, document accessed, output and action — exposed in a per-firm AI Audit View.

PRD-04Secrets management & key isolationEnforced+

Credentials are stored in managed secret stores. Rose Legal AI runs on a dedicated, workspace-scoped key with isolated usage and spend.

PRD-05Secure software development lifecycleOngoing+

Code review, automated checks and staged deploys. Change management is being formalized under SOC 2 and ISO 27001.

04

Data & Privacy

4 controls
DAT-01You own your data — full exportabilityEnforced+

Your documents and work product stay yours. Full export is available on request, on the way in and the way out — no lock-in.

DAT-02No training, zero retention on client dataEnforced+

Client data is never used to train models. Enterprise model-vendor terms prohibit retention and training; the system learns per firm from your own outcomes, never a shared model.

DAT-03Data retention & deletionEnforced+

Customer data is retained and deleted per the customer agreement, subject to legal-hold requirements. Deletion requests are honored on documented timelines.

DAT-04Bring Your Own Key (BYOK)Enterprise · in development+

Customer-managed encryption keys via your own cloud KMS, so you can rotate or revoke access to sensitive fields. In development for the Enterprise tier; design available for review.

05

Organizational Security

5 controls
ORG-01Security policies, reviewed annuallyEnforced+

A documented information-security policy set, reviewed at least annually and on material change.

ORG-02Background checks & security trainingOngoing+

Personnel undergo background screening where lawful and complete security-awareness training; confidentiality obligations apply to all staff.

ORG-03Vendor & subprocessor risk managementEnforced+

Subprocessors are reviewed before onboarding and bound by confidentiality and data-protection terms. The current registry is published under Subprocessors.

ORG-04Incident response & breach notificationEnforced+

A documented incident-response plan with defined roles and breach-notification timelines consistent with applicable law and the customer agreement.

ORG-05Business continuityEnforced+

Continuity planning so the platform and your data remain available and recoverable through disruption.

06

AI Governance

3 controls
AIG-01Human-in-the-loop approvalEnforced+

Auto-act when certain, verify in place when unsure, route to a human when there is no match — never an irreversible action without sign-off.

AIG-02Citations & confidence on every outputEnforced+

Authority citations and quotes come only from the compare-to-authority tool; document facts carry a verbatim quote and source. No fabricated citations.

AIG-03Model-agnostic orchestrationEnforced+

A proprietary orchestration layer spans model providers, so a single vendor’s policy change never changes your security posture. Aligned to ABA Formal Opinion 512.

Questions from your security team?

We share our SOC 2 report, subprocessor registry, BAA and DPA under NDA, and will walk your team through the controls.

Start a security review