Controls

What is in the product today.

Every item below describes a control that exists and has been through independent security review. Nothing here is roadmap.

Access

Single-use, hashed invitation tokens. No public signup. Argon2id password hashing, opaque server-side sessions, and CSRF protection on every state change.

Isolation

Deny-by-default, multi-tenant authorization. Every request is checked against identity, firm, matter, and role. Even firm admins get no matter content by default.

Data

AES-256-GCM encryption at rest for AI payloads and attorney private notes. Document downloads gated on malware scanning. Logs never contain message content.

The record

An append-only audit log of material user and AI actions. Exports that label AI-generated versus attorney-reviewed content, so the provenance of every line is clear.

Straight answers

What we do not claim.

The legal AI market is full of privilege promises. Here is where we stand instead.

  • We never claim that using CounselRoom makes a communication privileged. Privilege depends on jurisdiction, facts, and how your firm runs the representation.
  • We never claim that AI output cannot be subpoenaed or discovered.
  • We never claim protection in every jurisdiction. The law here is new and still moving.
  • We do not yet publish AI vendor retention terms. The pilot's provider agreement, including data retention and training terms, is finalized and disclosed during pilot onboarding.

What we do claim: the workflow is designed around the factors courts have actually examined, and every control listed on this page exists in the product today.

Ask us the hard questions.

Security review documentation is available to pilot firms during onboarding.