All controls monitoredLast updated October 2026Hosted in the United StatesAppend-only audit on every action
Legal by Rose
Subprocessors

Who can access your data

The third parties that help us run the platform. Open any entry to see exactly what data they can access, why, and how we protect it.

Supabase USPrimary database, authentication & document storage+
What data
Essentially all firm data at rest: matters, cases, documents, time & billing, trust ledgers, and user accounts/PII.
Why
It is the platform’s primary datastore, authentication provider and document storage.
How we protect it
AES-256 at rest, TLS in transit, row-level security tenant isolation, writes only through audited server routes, SOC 2 infrastructure.
Vercel USApplication hosting & serverless API+
What data
Data in transit only — page and API requests, request metadata and IP. No firm records are stored on Vercel.
Why
It runs the application and its serverless API at the edge.
How we protect it
TLS everywhere, no customer data persisted at rest, SOC 2 infrastructure.
Anthropic USRose Legal AI model provider+
What data
Only the specific content needed for a given AI request — the matter text or document being analyzed, plus the prompt.
Why
It powers Rose Legal AI’s drafting, analysis and review.
How we protect it
Zero-retention, no-training terms; a workspace-scoped key; TLS; and permission-filtered so only the asking user’s accessible content is ever sent.
Resend USTransactional email delivery+
What data
Email addresses and the contents of transactional emails — invitations, confirmations, password resets and invoice notices.
Why
It sends account and billing email on the platform’s behalf.
How we protect it
TLS, a scoped API key, and transactional use only — never marketing.
Amazon Web Services USUnderlying cloud infrastructure+
What data
Underlying compute and storage for our providers — no direct application-level access to firm data.
Why
It is the infrastructure our platform providers run on (a sub-processor).
How we protect it
Inherited SOC 2 / ISO controls and encryption at rest.

Planned: a payment processor (e.g. Stripe) will be added here when online payments go live. Our DNS/registrar touches no customer data and is not listed as a data subprocessor. We notify account administrators of material changes to this list.

Questions from your security team?

We share our SOC 2 report, subprocessor registry, BAA and DPA under NDA, and will walk your team through the controls.

Start a security review