Security
How client data is stored, who can reach it, what the AI assistant does and does not do with it, and what happens if your firm leaves. Written to be handed to a client who asks.
- Effective
- July 29, 2026
- Last updated
- July 29, 2026
1. Two separate systems
This website and the Legal AI Center platform are separate. The website holds marketing content and a contact form; it holds no client data, no matter records, and no documents. Everything below describes the platform, except where it says otherwise.
2. Encryption
- In transit: all connections use TLS 1.2 or higher. Older protocols are refused.
- At rest: documents, matter records, and backups are encrypted with AES-256.
- Encryption keys are managed by our cloud provider's key management service, separately from the data they protect.
3. Access control and separation between firms
- Each firm's data is logically isolated. A query issued in one firm's account cannot reach another firm's documents.
- Within a firm, access is scoped matter by matter. An administrator at your firm decides who can open which matters.
- Accounts are individual. Shared logins are not supported, so the audit trail always points at a person.
- Multi-factor authentication is available and can be required firm-wide.
- Our own staff do not browse customer data. Access for support is granted only on request from your firm, is limited to what the request needs, expires automatically, and is logged.
4. What the AI assistant does with your data
This is the part most firms ask about, so it is set out in detail.
- Your data is never used to train models. Not ours, not a third party's. There is no setting that changes this and no tier of service where it is different.
- The assistant answers only from documents in your own account. It is a retrieval system: it locates passages in your files and composes an answer from them.
- Every answer cites the document and location it came from, so an attorney can open the source and verify it before relying on it.
- Where the answer is not in the file, the assistant is built to say so rather than fill the gap.
- Where a third-party model provider is used to generate the language of an answer, it is under a contract that prohibits training on the content and prohibits retention beyond the immediate request.
- Every query is recorded in the audit log described below.
The assistant is a research aid. It does not exercise professional judgment, and the attorney using it remains responsible for the work.
5. Audit logging
The platform records who signed in, what they opened, what they asked the assistant, and what changed on a matter, with a timestamp against each event. Administrators at your firm can review and export the log for their own account. Logs are retained for 12 months.
6. Infrastructure
The platform runs on established cloud infrastructure in United States regions. Customer data stays in the United States unless your firm has agreed otherwise in writing. Production systems are network-isolated, and administrative access requires multi-factor authentication.
7. Backups and continuity
- Encrypted backups are taken daily and retained for 30 days.
- Restores are tested periodically rather than assumed to work.
- Backups are held in a separate location from the primary systems.
8. People
- Everyone with access to production systems is subject to a written confidentiality agreement.
- Access is granted on a least-privilege basis and reviewed when someone changes role.
- Access is revoked on the day someone leaves.
- Staff receive security and confidentiality training appropriate to handling legal data.
9. Keeping the software patched
Dependencies are monitored for known vulnerabilities and patched on a risk-based schedule, with critical issues prioritised ahead of other work. Changes are reviewed before they reach production.
10. If something goes wrong
We maintain a written incident response procedure. If a security incident affects your firm's data we will notify your firm's designated contact without undue delay, and in any event within 72 hours of confirming it. The notice will describe what happened, what data was involved, what we have done, and what we recommend you do. We will support your firm in meeting its own notification obligations to its clients and to any regulator or bar authority.
11. Your data on exit
- Your firm's data belongs to your firm. We claim no ownership of it.
- You can export your matters and documents in a standard, readable format at any time during your subscription, without asking us and without a fee.
- If you leave, you keep export access for 30 days after the subscription ends.
- After that, we delete your data from production systems within 30 days and from backups as those backups age out, within 60 days.
- We will confirm the deletion in writing if you ask.
12. Reporting a vulnerability
If you believe you have found a security problem, email security@legalaicenter.com with enough detail to reproduce it. We will acknowledge within two business days and keep you updated until it is resolved.
Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and do not access, modify, or delete data belonging to anyone else while investigating. We will not pursue legal action against researchers who follow this process in good faith.
13. Security reviews and due diligence
Firms carrying out their own diligence, or answering a client's questions about their vendors, can request our current security documentation, our list of subprocessors, and a completed security questionnaire. Write to security@legalaicenter.com.