Trust Center Open a Request

Controls

38 controls across 6 areas. Each is monitored continuously; a failing control opens a tracked issue.

Infrastructure security

  • Production database is not publicly reachable

    The database listens only on private interfaces; no port is exposed to the internet.

    Monitored
  • Encryption at rest

    Database volumes, the document store and backups are encrypted with AES-256.

    Monitored
  • Encryption in transit

    Every connection uses TLS 1.2 or later, and HSTS is enforced.

    Monitored
  • Edge protection

    Traffic passes through a web application firewall with rate limiting and bot filtering.

    Monitored
  • Intrusion detection

    Hosts and the edge are monitored for anomalous traffic and access, with alerts to on-call.

    Monitored
  • Hardened hosts

    Servers run a minimal image, accept key-based SSH only, and receive security patches automatically.

    Monitored
  • Backups with point-in-time recovery

    Encrypted backups are continuous and restored in scheduled drills.

    Monitored

Organisational security

  • Multi-factor authentication

    Staff sign in to production and every business system through SSO with hardware-backed MFA.

    Monitored
  • Background checks

    Everyone with production access is background-checked before they start.

    Monitored
  • Confidentiality agreements

    Staff and contractors sign confidentiality agreements before any access is granted.

    Monitored
  • Security awareness training

    Training at onboarding and annually, including phishing and data-handling.

    Monitored
  • Acceptable use policy

    Every member of staff acknowledges it at onboarding and on every revision.

    Monitored
  • Managed devices

    Company devices enforce full-disk encryption, screen lock and automatic updates.

    Monitored
  • Access reviews

    Production and vendor access is reviewed quarterly and removed within a day of departure.

    Monitored

Product security

  • Workspace isolation

    Every query is scoped to your workspace, and every route declares who may call it.

    Monitored
  • Passwordless and SSO sign-in

    Sign-in by one-time email code or Google and Microsoft SSO; no passwords to leak.

    Monitored
  • Role-based access

    Private and shared cases, with per-case membership decided by your administrators.

    Monitored
  • Tamper-evident audit trail

    Reads, changes and decisions are recorded with who, what and when; entries are never deleted.

    Monitored
  • Legal hold

    A case under legal hold cannot be altered or deleted until the hold is released.

    Monitored
  • Secure development lifecycle

    Peer-reviewed changes, dependency scanning and automated tests gate every release.

    Monitored
  • Annual penetration testing

    An independent firm tests the application and infrastructure every year and after major changes.

    Monitored

Data and privacy

  • Data minimisation

    Cases stores what you give it to build your case, and nothing else.

    Monitored
  • Deletion on request

    Deleting a case removes it from the product immediately and from backups within 35 days.

    Monitored
  • Data residency

    Documents are stored in the European Union.

    Monitored
  • Data Processing Addendum

    A DPA with Standard Contractual Clauses is available to every customer.

    Monitored
  • Subprocessor oversight

    Every subprocessor is reviewed before use and annually, and you are notified before a new one is added.

    Monitored
  • Privacy by design

    Data protection impact assessments are run for new processing.

    Monitored

AI governance

  • No training on customer data

    Contracts with every model provider prohibit training on your documents or outputs.

    Monitored
  • Zero data retention

    Model providers do not retain prompts or completions beyond processing the request.

    Monitored
  • Grounded outputs

    Every finding links to the passage it came from, so a person can verify it.

    Monitored
  • Human supervision

    Consequential proposals wait in the Decision Inbox for a person to approve or reject.

    Monitored
  • Model change control

    Model and prompt changes are evaluated against reference cases before release.

    Monitored

Internal security procedures

  • Continuous control monitoring

    Controls are monitored continuously, and a failing control opens a tracked issue.

    Monitored
  • Incident response plan

    A tested plan with defined roles, and notification within 72 hours of a confirmed breach.

    Monitored
  • Risk assessment

    Risks are assessed annually and when the business or the platform changes materially.

    Monitored
  • Vendor management

    Vendors are assessed for security before onboarding and reviewed annually.

    Monitored
  • Change management

    Production changes are reviewed, tested and deployed through an audited pipeline.

    Monitored
  • Business continuity

    Recovery objectives are defined and verified by restore drills.

    Monitored

No controls match that filter.

Request documents

Choose the documents your review needs and tell us who you are. We reply within one business day.

Documents

Questions? [email protected]