All controls monitoredLast updated October 2026Hosted in the United StatesAppend-only audit on every action
Legal by Rose
FAQ

Questions security teams ask

The questions managing partners, security teams and malpractice carriers raise most often.

Where does my data go when AI processes it?+

Retrieval is intersected with the matters you can access and your ethical walls before any model sees a word. Nothing is retrieved across firms, matters or walls, and only the specific content needed for a request is sent — under zero-retention, no-training terms.

Is the AI trained on our client data?+

Never. Enterprise model-vendor terms prohibit retention and training. The system learns per firm from your own outcomes and edits, and never trains shared models.

Who can see what inside the platform?+

RBAC, matter-level scope and ethical walls, with SSO / SAML / SCIM available, and MFA — authenticator app and/or SMS — mandatory for admin and finance roles.

How do you handle privileged information?+

Row-level security puts a firm identifier on every row. Cross-firm access is structurally impossible except through explicit, consented co-counsel sharing that you control.

Can we audit what the AI did?+

Every prompt, document accessed, output and action is hash-chained and exposed in a per-firm AI Audit View. Every substantive output carries citations and a confidence level.

What if something goes wrong?+

A documented incident-response plan with breach-notification timelines, annual third-party penetration testing, and a published subprocessor registry.

Questions from your security team?

We share our SOC 2 report, subprocessor registry, BAA and DPA under NDA, and will walk your team through the controls.

Start a security review