Security
Your case files stay yours.
Your firm's documents are isolated at the database level, not just behind a login. Files are encrypted in transit and at rest. Nothing from your firm is used to train any model, ever, and nothing is shared across firms. You can delete a case and its underlying documents at any time.
Medical records are handled under the same confidentiality obligations you carry under RPC 1.6.
Security policy
Firm-level isolation
{{SECURITY_POLICY_BODY.isolation}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Encryption in transit and at rest
{{SECURITY_POLICY_BODY.encryption}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Model training and data use
{{SECURITY_POLICY_BODY.training}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Retention and deletion
{{SECURITY_POLICY_BODY.retention}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Access and authentication
{{SECURITY_POLICY_BODY.access}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Subprocessors
{{SECURITY_POLICY_BODY.subprocessors}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Incident response
{{SECURITY_POLICY_BODY.incidents}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
Questions about any of this
{{SECURITY_POLICY_BODY.questions}}Real policy language. Do not invent it. No SOC 2, HIPAA, or ISO claims unless supplied.
If your firm has a security questionnaire, send it. I would rather answer it in writing than have you guess.