Encryption
Verify protection in transit and at rest, key handling, and every storage and processing path.
See what is available in this preview and the controls that must be implemented and verified before real client use.
Verify protection in transit and at rest, key handling, and every storage and processing path.
Keep originals outside public URLs, with private object storage and time-limited authorized downloads.
Connect account registration, sign-in, recovery, multifactor authentication, and session controls.
Enforce organization and matter permissions on the server for every read, change, and download.
Retain durable events for access, changes, approvals, exports, and permission changes.
Verify that each organization and matter can retrieve only authorized records and AI context.
Review provider processing, training, retention, deletion, and subprocessors before making privacy claims.
Enforce scoped invitations, revocation, role changes, and document-level access as appropriate.
Define recovery objectives, configure backups, test restoration, and apply retention controls.
Verify file scanning, dependency management, monitoring, incident response, and independent testing.
The fictional /demo workspace keeps records in page memory. The separate /workspace pilot stores matter records and originals on the hosting platform with server-side ownership checks. Pilot records remain until a managed deletion process is implemented; self-service deletion is not yet available. Exported files remain on your device. The access-request form prepares a local draft and sends nothing. Hosting and browser services may process technical request information under their own terms. AI processing, when enabled and requested, sends selected documents to OpenAI with response storage disabled; provider retention terms still apply. Production retention policies, deletion, malware scanning, recovery testing and security review remain unfinished.
No SOC 2, HIPAA, FINRA, SEC, or other certification or regulatory compliance status is claimed. Specific encryption standards, security protections, and provider privacy settings must be implemented and verified before they are described as operational.