Security & Compliance
Last reviewed: Aug 2025We know your clients’ trust depends on the confidentiality and integrity of their information. Attorney Assist AI is built with security as a first principle.
Encryption
- In transit: All traffic is secured via TLS 1.2+
- At rest: Data is encrypted with AES-256 using managed keys
Tenant Isolation
Each firm has its own isolated workspace, storage buckets, and vector indexes. Your data is never mixed with another tenant’s.
Access Controls
- Role-based access (admin, attorney, staff)
- Audit logs on all sensitive actions
- Least-privilege by default
Retention
- Drafts and temporary files: 90 days
- Audit logs: 365 days (configurable)
- Data can be exported or deleted at any time upon request
Compliance Roadmap
- SOC 2 Type II (in progress)
- HIPAA / BAA available for covered entities
- GDPR & CCPA aligned data practices
No Training on Your Data
We do not use your private data to train AI models by default. Training is opt-in only.