The questions managing partners, security teams and malpractice carriers raise most often.
Retrieval is intersected with the matters you can access and your ethical walls before any model sees a word. Nothing is retrieved across firms, matters or walls, and only the specific content needed for a request is sent — under zero-retention, no-training terms.
Never. Enterprise model-vendor terms prohibit retention and training. The system learns per firm from your own outcomes and edits, and never trains shared models.
RBAC, matter-level scope and ethical walls, with SSO / SAML / SCIM available, and MFA — authenticator app and/or SMS — mandatory for admin and finance roles.
Row-level security puts a firm identifier on every row. Cross-firm access is structurally impossible except through explicit, consented co-counsel sharing that you control.
Every prompt, document accessed, output and action is hash-chained and exposed in a per-firm AI Audit View. Every substantive output carries citations and a confidence level.
A documented incident-response plan with breach-notification timelines, annual third-party penetration testing, and a published subprocessor registry.
We share our SOC 2 report, subprocessor registry, BAA and DPA under NDA, and will walk your team through the controls.