Security
Built for privileged work
Patent matters are confidential by definition. Here is where your data runs, who can reach it, and what the AI does and does not see.
Read the data processing agreementConfidentiality
Never used for training
AI requests carry only the context needed for the task. Our third-party AI providers do not use them to train models.
Provider deletes within 30 days
The AI provider deletes requests after 30 days at the latest. Nothing sent to the model becomes part of a permanent store outside our infrastructure.
Customer data isolation
Each firm's data is separated at the database layer, reducing the risk of cross-customer exposure. One firm's data cannot reach another, even under an application bug.
Data control
Stored and served in the EU
Application, databases, and file storage run in Amsterdam on EU-jurisdiction infrastructure. Only AI requests leave, processed by our provider under a data processing agreement.
Data export
Matter data can be exported at any time for internal recordkeeping, review, and compliance. Your files are yours to take.
Deleted means deleted
Deleting a matter, or your whole account, removes its data from the live system immediately. Every backup and log copy is purged within 30 days. Only the access record stays, and it never held the content.
Protection
Encrypted in transit and at rest
All traffic is encrypted with TLS. Databases and file storage are encrypted at rest.
Every access is on record
Every read or change of matter content is written to an append-only log that the application cannot edit or delete: who, when, which matter, and whether it was allowed. Never the content itself. Access records for your matters are available on request and are kept as long as legal obligations require.
Security-reviewed before it ships
Every code change gets an automated security review before merge, and the whole codebase is re-reviewed weekly across rotating security lenses.
Documentation
For your security review
The data processing agreement and subprocessor list are published in full, with every subprocessor change dated.
Frequently asked questions
Who can see our matter data?
Your firm's signed-in users. Tenant isolation is enforced by the database itself, so no other customer can reach your rows, even through an application bug.
Is our data used to train AI models?
No. Requests to the AI provider are used to answer the request and nothing else. They are never used for model training.
What does the AI provider receive?
Only the context needed for the task at hand, sent per request. It is not a copy of your matter, and with the assistant off nothing is sent at all.
Where is our data processed?
The application, databases, and file storage run in Amsterdam on EU-jurisdiction infrastructure. AI requests are processed by our AI provider under a data processing agreement with standard contractual clauses.
Can we use the platform without any AI?
Yes. The workspace, editors, versioning, and search all work with the assistant off. AI is a layer on top, not a requirement.
What documentation can our security team review?
The data processing agreement and the subprocessor list are published in full. A signed copy of the agreement is available on request.