The guarantees

01

We never train on your data

Your matters, documents, and queries are never used to train any model. Your work is yours; it stays that way, by policy and by contract.

02

Encrypted everywhere

All data is encrypted in transit (TLS) and at rest, with strict access controls on every request.

03

Firm-level isolation

PostgreSQL row-level security isolates every firm's matters and documents at the database. Role-based access (owner, admin, attorney, paralegal) and per-matter visibility are enforced on every request.

04

Verified, not hallucinated

Every answer is grounded in the law, each citation resolves to its official source, an independent model checks that each claim is supported, and the system abstains when the corpus is not enough.

Standards we hold ourselves to

Independent security audit

Four-surface security review complete, with no critical or high findings outstanding.

ISO 27001 hosting

Runs on ISO 27001-certified cloud infrastructure.

Encryption at rest & in transit

AES-256 at rest, TLS 1.2+ in transit.

PCI DSS payments

Card data is handled only by PCI DSS Level 1 processors and never stored on our servers.

Firm-level tenant isolation

Row-level security isolates every firm's data, verified by an automated suite on every release.

Data residency & DPA

Regional hosting and a Data Processing Agreement on request.

Security is a program, not a checkbox. An independent four-surface security review is complete with no critical or high findings outstanding, tenant isolation is enforced by row-level security and verified by an automated suite on every release, and our Data Processing Agreement is published at /dpa. We pursue formal certification on the schedule your firm's procurement requires. If you need specific documentation now, contact us.

Talk to us about security
MXLEX · Security & Trust