Access
No anonymous door
Single-use, hashed invitation tokens. No public signup. Argon2id password hashing, opaque server-side sessions, and CSRF protection on every state change.
Security
That is the whole promise of the room. Everything below is how we keep it, and Rule 1.6(c) asks you for reasonable efforts, not guarantees.
In plain terms
One more, because lawyers ask it early: a firm administrator can see that a matter exists. They cannot read what is inside it unless someone put them on it.
Controls
For the person at your firm whose job is to ask. Every item below exists in the product today. Nothing here is roadmap.
Access
Single-use, hashed invitation tokens. No public signup. Argon2id password hashing, opaque server-side sessions, and CSRF protection on every state change.
Isolation
Multi-tenant authorization checked on every request: identity, firm, matter, role. Even firm admins get no matter content by default.
Data
AES-256-GCM encryption at rest for AI payloads and attorney private notes. Uploaded documents are released only to the people on that matter. Logs never contain message content.
The record
Material actions by your team and by the AI are recorded with an actor and a timestamp. Exports label AI-generated versus attorney-reviewed content, so the provenance of every line is clear.
Straight answers
The legal AI market is full of privilege promises. Here is where we stand instead, on the record.
What we do claim: the workflow is designed around the factors courts have actually examined, and every control listed on this page exists in the product today.
Our security review documentation and its remediation record are available to pilot firms during onboarding.