Built for firms where client confidentiality is non-negotiable.
Security posture.
Client confidentiality is the foundation this product is built on, and we treat it as an engineering requirement, not a policy statement. Your data lives in the United Kingdom, encrypted in transit and at rest, and it does not leave UK infrastructure at any point in the pipeline. The AI layer runs at zero data retention: no prompt and no output is ever written to storage, and nothing your firm provides is used to train any model. Documents are read in memory, extracted, and never kept as files.
Every firm is isolated at the database itself, not by application code. Row-level security means one firm's records are invisible to another even in the presence of a software defect, and the regulated actions, signing an assessment, clearing or escalating a suspicious-activity consideration, are locked to your named compliance officers and enforced on the server. Every material action is written to an append-only audit log, so there is always a complete answer to who did what, and when. Access is protected by two-factor authentication and argon2id credential hashing, and every session, request and upload passes rate-limiting, cross-site request forgery protection and a web application firewall.
You see the evidence before you commit anything. A signed data processing agreement, our data protection impact assessment and our AI-use disclosure go to your compliance officer as the standard opening of every engagement, and the platform is independently penetration-tested before any firm's matters are processed. Your records are retained on your schedule and erased when you leave. Every claim on this page can be evidenced in writing, on request, to your data protection officer or your insurer.