How your files are handled
before you send anything
We are asking for your real files. Here is what happens to them.
Brand assets and license agreements are not test data. These are the answers your legal and security teams will ask for, on the page rather than in week three.
| Before anything moves | Mutual NDA and a signed DPA. No files are read until both are in place. |
| Where it lives | On infrastructure we control, hosted in EU and USA, isolated per tenant. No asset crosses into another customer’s record. |
| Training | Never used to train models — ours or anyone else’s. |
| Access | Scoped access with OAuth. Licensee/partner logins see only what their license permits, and counsel-private notes stay off that view. |
| Provenance | Every transaction is logged — human or agent — with the rule it applied and the date. Retention windows and legal hold are supported. |
| Certification | ISO 27001 targeted for Q1 2027. Control set and sub-processor list on request; sub-processors change only with notice. |
| If you leave | Full export in an open format, and hard deletion on request. A record you cannot remove is a record you should not trust. |
A pilot folder is handled the same way as a production record. There is no lesser tier of care for the thing you send first.