Your documents are the whole business.
Pay applications, change orders, contracts — the paper we process is financially sensitive by definition. Here is, concretely, how it’s protected.
Encryption
- All traffic is encrypted in transit with TLS.
- Project files are encrypted at rest (AES-256) in cloud object storage.
- Application data is encrypted at rest in our managed database.
Access control & tenant isolation
- Every firm's data is isolated — users only ever see their own firm's projects and documents.
- Role-based permissions gate administrative actions.
- Sensitive operations require step-up re-authentication, not just an active session.
- Sessions are protected against cross-site request forgery, and authentication endpoints are rate-limited.
Auditability
- Administrative and security-relevant actions are recorded in a tamper-evident audit log.
- Legal documents (Terms, Privacy) are versioned, so we can show exactly what text a user agreed to, and when.
AI & your data
- Document understanding is powered by leading third-party AI models, accessed via API.
- Your documents are not used to train AI models — ours or anyone else's. This commitment is written into our Privacy Policy, covering both first- and third-party models.
- AI answers cite their sources: page-level references back to your own documents, so every claim is checkable.
Subprocessors
We rely on a small set of vetted subprocessors for AI document processing (under our no-training commitment), encrypted hosting, and storage. Analytics are limited to our public website and consent-based in the EEA/UK/CH — never inside the product.
Our current, complete subprocessor list is provided with our Data Processing Addendum on request.
A Data Processing Addendum is available on request, and security questions or vulnerability reports are welcome at [email protected].