Access
Single-use, hashed invitation tokens. No public signup. Argon2id password hashing, opaque server-side sessions, and CSRF protection on every state change.
Security
Security cannot create privilege on its own. It can make your workflow easy to defend when someone asks how it worked.
Controls
Every item below describes a control that exists and has been through independent security review. Nothing here is roadmap.
Single-use, hashed invitation tokens. No public signup. Argon2id password hashing, opaque server-side sessions, and CSRF protection on every state change.
Deny-by-default, multi-tenant authorization. Every request is checked against identity, firm, matter, and role. Even firm admins get no matter content by default.
AES-256-GCM encryption at rest for AI payloads and attorney private notes. Document downloads gated on malware scanning. Logs never contain message content.
An append-only audit log of material user and AI actions. Exports that label AI-generated versus attorney-reviewed content, so the provenance of every line is clear.
Straight answers
The legal AI market is full of privilege promises. Here is where we stand instead.
What we do claim: the workflow is designed around the factors courts have actually examined, and every control listed on this page exists in the product today.
Security review documentation is available to pilot firms during onboarding.