Security

Built for privileged work

Patent matters are confidential by definition. Here is where your data runs, who can reach it, and what the AI does and does not see.

Read the data processing agreement

Confidentiality

Never used for training

AI requests carry only the context needed for the task. Our third-party AI providers do not use them to train models.

Provider deletes within 30 days

The AI provider deletes requests after 30 days at the latest. Nothing sent to the model becomes part of a permanent store outside our infrastructure.

Customer data isolation

Each firm's data is separated at the database layer, reducing the risk of cross-customer exposure. One firm's data cannot reach another, even under an application bug.

Data control

Stored and served in the EU

Application, databases, and file storage run in Amsterdam on EU-jurisdiction infrastructure. Only AI requests leave, processed by our provider under a data processing agreement.

Data export

Matter data can be exported at any time for internal recordkeeping, review, and compliance. Your files are yours to take.

Deleted means deleted

Deleting a matter, or your whole account, removes its data from the live system immediately. Every backup and log copy is purged within 30 days. Only the access record stays, and it never held the content.

Protection

Encrypted in transit and at rest

All traffic is encrypted with TLS. Databases and file storage are encrypted at rest.

Every access is on record

Every read or change of matter content is written to an append-only log that the application cannot edit or delete: who, when, which matter, and whether it was allowed. Never the content itself. Access records for your matters are available on request and are kept as long as legal obligations require.

Security-reviewed before it ships

Every code change gets an automated security review before merge, and the whole codebase is re-reviewed weekly across rotating security lenses.

Documentation

For your security review

The data processing agreement and subprocessor list are published in full, with every subprocessor change dated.

Frequently asked questions

Who can see our matter data?

Your firm's signed-in users. Tenant isolation is enforced by the database itself, so no other customer can reach your rows, even through an application bug.

Is our data used to train AI models?

No. Requests to the AI provider are used to answer the request and nothing else. They are never used for model training.

What does the AI provider receive?

Only the context needed for the task at hand, sent per request. It is not a copy of your matter, and with the assistant off nothing is sent at all.

Where is our data processed?

The application, databases, and file storage run in Amsterdam on EU-jurisdiction infrastructure. AI requests are processed by our AI provider under a data processing agreement with standard contractual clauses.

Can we use the platform without any AI?

Yes. The workspace, editors, versioning, and search all work with the assistant off. AI is a layer on top, not a requirement.

What documentation can our security team review?

The data processing agreement and the subprocessor list are published in full. A signed copy of the agreement is available on request.