Home/Security

Security and privacy

Confidentiality of the files is a property of the environment, not a clause in a contract

We separate two questions: where the case files physically reside, and which data goes to the model providers. Both are configurable, both are visible in the interface, and both can be tightened towards greater strictness.

On-premises server

The files are with you

They go nowhere except the model provider you choose. We physically cannot see the contents of your cases.

Our server

Isolation of organisations

Each firm has its own space: its own cases, users, keys and limits. One organisation's keys are inaccessible to another, even to us.

Project

Nothing goes outside

Only local models and local recognition are used. Quality is lower — the files never leave the machine. Assembled as an integration project in your perimeter.

The communication channel

The relay: we carry it, but we do not read it

If a lawyer works outside the office, the connection goes through our nodes — but as an encrypted stream that we do not decrypt. Otherwise the promise "files never leave your office" would be untrue at the very moment the lawyer steps out of it.

  • The certificate is issued by your server; the key never leaves the firm's machine
  • The relay does not compute or store content: its costs are nodes and traffic
  • In the office the connection goes directly over the local network and does not reach us at all
  • Bulk import of volumes is performed by the firm's server, not the relay

Model keys

  • Entered in the admin panel and encrypted in the database
  • After saving they are not shown in full — only the last characters
  • A check button: 'the key works, the limit is such and such'
  • A log entry recording who changed what and when

A key from a personal subscription is fine for development but not for a product: personal rate limits and silent degradation at the worst possible moment.

Data governance

What goes outside is configured by data type and by provider

The firm can allow fact extraction on one service while sending the full text of the case nowhere except the chosen one. At the extreme, there is a mode in which nothing goes outside at all.

What goes where
ActionWhat is sentTo whomHow to restrict it
Analysis and debatesThe case fragments needed for the answerThe selected models for the rolesLocal models for the roles
Fact extractionVolume pagesA cheap model, or locallyLocal extraction
RecognitionOnly disputed pages, a fraction of a percentArbiterA local arbiter
EmbeddingsFragment textsThe embeddings providerLocal embeddings
External sourcesThe search queryA legal database, a registryDisabling the connector

Double local recognition also saves money: the neural network sees a fraction of a percent of the pages, not the entire case.

Control

Who sees what, and who did what

Roles instead of "access to everything"

Administrator, partner, lawyer, assistant, client. The client sees only their own case: submit documents, the status, approval of a draft.

Audit log of significant actions

Approving a document, confirming a deadline, rejecting a fact, linking a chat, querying an external source — all with who and when.

Spend and limits

Limits per organisation, per lawyer and per case; a warning and a hard stop; the estimate is shown before an expensive operation is run, not after.

Backups

A nightly copy of the database and files, retained for N days, with verifiable restoration. An update does not touch case files.

Boundaries

What we do not do — deliberately

  • We do not connect personal data 'lookup' services
  • We do not scrape commercial legal databases — only official connections
  • We do not send to court and do not file documents automatically
  • We do not mask model degradation by silently truncating the result

Formalising the relationship

We work under a contract describing data processing, a list of sub-processors (model providers) and the procedure for deleting files. For corporate clients there is a separate document pack and a service level agreement. We send the exact list of documents and annexes together with the quote.

No unfounded certificates. We do not write "compliant with everything" — in the documents we list exactly what we do and what we do not do, so that your security department can verify rather than take our word.

Need a review of your confidentiality requirements?

Send us your internal policy or a question from your security department — we will answer substantively and, if needed, build an environment to match it.