Security

How your records are protected

Written plainly, so it can be handed to a client or used to answer a firm's technology questionnaire.

Only the attorney who uploaded a record can open it

Each uploaded file is stored in a private area tied to the attorney who uploaded it. Another attorney at the same firm cannot open it. A firm administrator cannot open it. A signed-out visitor cannot open it. The same rule covers the text pulled out of the file, the case it belongs to, the transcript and every flag.

There are no public links

Files are never published to a web address. Nothing can be reached by guessing a link, and search engines cannot index a record.

Encrypted in transit and at rest

Everything sent between the app and our servers travels over an encrypted connection, and files and database records are encrypted where they are stored.

The AI does not learn from your records

Uploaded records and deposition testimony are used only to produce the answer on your screen for that one request. No model is trained, tuned or updated on your material, nothing is retained to improve the software, and nothing from one case carries into another. Each case starts empty.

Where your text goes while the AI is working

Transcription and analysis run on outside model providers (Google and OpenAI models, reached through Lovable's AI gateway). Only the excerpts relevant to the question being analyzed are sent — never an attorney's whole library — over an encrypted connection, for that single request. Under those providers' business terms the text is not used to train their models. That is their contractual commitment, and it is worth naming plainly rather than implying the app can enforce it.

Accounts are by invitation only

Nobody can create an account on their own. An administrator invites a specific email address; anyone else is turned away at the sign-in screen. Removing or deactivating a person cuts off their access on their next page load, even if they are still signed in.

Every touch of a record is logged

Uploading, opening or deleting a record writes a permanent line: who did it, which record, which case, and when. Firm administrators can review the log. Nobody — including administrators — can edit or erase an entry from inside the app.

Automatic sign-out

If a laptop is left untouched for 30 minutes the app signs the user out and returns to the sign-in screen, with a warning shortly beforehand so nobody is dropped mid-deposition.

Sign-in protections

Passwords that appear in known public breaches are rejected, and a signed-in user must confirm their current password before changing it. Password reset links are single-use and expire quickly.

Deleted means deleted

Deleted cases and sessions stay recoverable for one week, then the files themselves are removed from storage — not just the entry in the list.

This page describes the protections built into the software. It is not legal advice, and it does not replace your own obligations around client confidentiality, consent to recording, and supervision of the work product.