Controls
38 controls across 6 areas. Each is monitored continuously; a failing control opens a tracked issue.
Infrastructure security
- Production database is not publicly reachableMonitored
The database listens only on private interfaces; no port is exposed to the internet.
- Encryption at restMonitored
Database volumes, the document store and backups are encrypted with AES-256.
- Encryption in transitMonitored
Every connection uses TLS 1.2 or later, and HSTS is enforced.
- Edge protectionMonitored
Traffic passes through a web application firewall with rate limiting and bot filtering.
- Intrusion detectionMonitored
Hosts and the edge are monitored for anomalous traffic and access, with alerts to on-call.
- Hardened hostsMonitored
Servers run a minimal image, accept key-based SSH only, and receive security patches automatically.
- Backups with point-in-time recoveryMonitored
Encrypted backups are continuous and restored in scheduled drills.
Organisational security
- Multi-factor authenticationMonitored
Staff sign in to production and every business system through SSO with hardware-backed MFA.
- Background checksMonitored
Everyone with production access is background-checked before they start.
- Confidentiality agreementsMonitored
Staff and contractors sign confidentiality agreements before any access is granted.
- Security awareness trainingMonitored
Training at onboarding and annually, including phishing and data-handling.
- Acceptable use policyMonitored
Every member of staff acknowledges it at onboarding and on every revision.
- Managed devicesMonitored
Company devices enforce full-disk encryption, screen lock and automatic updates.
- Access reviewsMonitored
Production and vendor access is reviewed quarterly and removed within a day of departure.
Product security
- Workspace isolationMonitored
Every query is scoped to your workspace, and every route declares who may call it.
- Passwordless and SSO sign-inMonitored
Sign-in by one-time email code or Google and Microsoft SSO; no passwords to leak.
- Role-based accessMonitored
Private and shared cases, with per-case membership decided by your administrators.
- Tamper-evident audit trailMonitored
Reads, changes and decisions are recorded with who, what and when; entries are never deleted.
- Legal holdMonitored
A case under legal hold cannot be altered or deleted until the hold is released.
- Secure development lifecycleMonitored
Peer-reviewed changes, dependency scanning and automated tests gate every release.
- Annual penetration testingMonitored
An independent firm tests the application and infrastructure every year and after major changes.
Data and privacy
- Data minimisationMonitored
Cases stores what you give it to build your case, and nothing else.
- Deletion on requestMonitored
Deleting a case removes it from the product immediately and from backups within 35 days.
- Data residencyMonitored
Documents are stored in the European Union.
- Data Processing AddendumMonitored
A DPA with Standard Contractual Clauses is available to every customer.
- Subprocessor oversightMonitored
Every subprocessor is reviewed before use and annually, and you are notified before a new one is added.
- Privacy by designMonitored
Data protection impact assessments are run for new processing.
AI governance
- No training on customer dataMonitored
Contracts with every model provider prohibit training on your documents or outputs.
- Zero data retentionMonitored
Model providers do not retain prompts or completions beyond processing the request.
- Grounded outputsMonitored
Every finding links to the passage it came from, so a person can verify it.
- Human supervisionMonitored
Consequential proposals wait in the Decision Inbox for a person to approve or reject.
- Model change controlMonitored
Model and prompt changes are evaluated against reference cases before release.
Internal security procedures
- Continuous control monitoringMonitored
Controls are monitored continuously, and a failing control opens a tracked issue.
- Incident response planMonitored
A tested plan with defined roles, and notification within 72 hours of a confirmed breach.
- Risk assessmentMonitored
Risks are assessed annually and when the business or the platform changes materially.
- Vendor managementMonitored
Vendors are assessed for security before onboarding and reviewed annually.
- Change managementMonitored
Production changes are reviewed, tested and deployed through an audited pipeline.
- Business continuityMonitored
Recovery objectives are defined and verified by restore drills.
No controls match that filter.