Security

Your matter data is
your matter data.

Tenant isolation, customer-managed encryption, immutable audit trail, no training on your data. Built to pass procurement, designed to pass an audit.

Compliance posture

Built for procurement.

SOC 2

Type II in progress · Type I complete · report on request.

ISO 42001

AI management system, mapped and audited.

HIPAA

BAA available at Enterprise.

EU AI Act

Conformity assessment ready for high-risk classification.

Data handling

Five rules we will not break.

No training on your data

Your matter content is never used to train base or specialist models. Opt-in fine-tuning is strictly contractual and isolated.

Tenant isolation

Per-tenant KMS keys. Schema-per-tenant on Enterprise. Network-level segregation. BYOK on request.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Field-level encryption for PII.

Identity & access

SSO/SAML/SCIM via Okta, Microsoft Entra, Google Workspace. RBAC with per-action permissions.

Immutable audit log

Every agent action, tool call, document touched, model invoked. Append-only. Exportable to SIEM.

Pen-tested · bug bounty

Annual third-party penetration test. Continuous bounty via HackerOne.

Sub-processors.

VendorPurposeRegion
Amazon Web ServicesPrimary infrastructureus-east-1 · eu-west-1
AnthropicFoundation model inference (no-train)US
OpenAI EnterpriseFoundation model inference (no-train)US
WorkOSSSO / SCIMUS
StripeBillingUS

Full DPA, SCCs, and the complete sub-processor list available at security@litigo.app.