We know what a GC's procurement checklist looks like before they'll
put a client matter anywhere near a new platform. Here's where we
stand today, and where we're headed.
Encryption
All data encrypted in transit (TLS 1.2+) and at rest (AES-256), with client data isolated per tenant — no shared database rows across firms.
Access control & audit trail
Role-based permissions, SSO/SAML for enterprise IT, and a full audit trail — every action is attributable and logged, core to the Platform module.
Data residency
Cloud-hosted on major infrastructure providers, EU region by default, with US or other regions available for clients whose own regulatory or LP requirements call for it.
AI & client data
Client data is never used to train shared or foundation models. Firms can disable Intelligence features entirely without losing access to the rest of the platform.
Certifications
SOC 2 Type I targeted at GA, Type II within 12 months of launch. GDPR-aligned by design, with a Data Processing Agreement available to every client.
Data ownership & export
Client data always remains the client's. Self-serve export in standard formats at any time, full deletion within 30 days of offboarding.