In plain terms

Three things, and you can stop reading.

  • There is no anonymous door. Your firm decides who is in the room, one invitation at a time. Nobody browses their way in.
  • A lawyer is on every matter. Not an option you switch on. The responsible attorney is there before your client ever types anything.
  • You can show who saw what. If anyone ever asks how the work was handled, the answer is a record, not a recollection.

One more, because lawyers ask it early: a firm administrator can see that a matter exists. They cannot read what is inside it unless someone put them on it.

Who can reach matter content Four nested boundaries. From the outside in: the public, who reach nothing. Your firm, whose administrators see that a matter exists but not what is in it. The matter team, being the responsible attorney, staff, and the invited client. And at the centre, the matter content itself. THE PUBLIC YOUR FIRM THE MATTER TEAM Responsible attorney · staff · invited client Matter content Conversation, facts, documents, notes Firm admins see that it exists. They do not see what is in it.

Controls

How that is built.

For the person at your firm whose job is to ask. Every item below exists in the product today. Nothing here is roadmap.

Access

No anonymous door

Single-use, hashed invitation tokens. No public signup. Argon2id password hashing, opaque server-side sessions, and CSRF protection on every state change.

Isolation

Deny by default

Multi-tenant authorization checked on every request: identity, firm, matter, role. Even firm admins get no matter content by default.

Data

Encrypted where it counts

AES-256-GCM encryption at rest for AI payloads and attorney private notes. Uploaded documents are released only to the people on that matter. Logs never contain message content.

The record

A record of who did what

Material actions by your team and by the AI are recorded with an actor and a timestamp. Exports label AI-generated versus attorney-reviewed content, so the provenance of every line is clear.

Straight answers

What we do not claim.

The legal AI market is full of privilege promises. Here is where we stand instead, on the record.

Representationscounselroom.ai · 2026
  1. We never claim that using CounselRoom makes a communication privileged. Privilege depends on jurisdiction, facts, and how your firm runs the representation.
  2. We never claim that AI output cannot be subpoenaed or discovered.
  3. We never claim protection in every jurisdiction. The law here is new and still moving.
  4. We do not yet publish AI vendor retention terms. The pilot's provider agreement, including data retention and training terms, is finalized and disclosed during pilot onboarding.

What we do claim: the workflow is designed around the factors courts have actually examined, and every control listed on this page exists in the product today.

Ask us the hard questions.

Our security review documentation and its remediation record are available to pilot firms during onboarding.