Short answer
Your documents and analyses are stored in the EU (Railway’s EU-West region), encrypted at rest and in transit. AI requests go through an EU-hosted gateway, and providers receive only the text a request needs, never your document store. Documents are kept until you delete them, audit logs for two years.
Where the data lives
- Application, database and file storage: EU (Railway EU-West).
- Encryption: AES-256 at rest for documents and user content, TLS in transit. Attorly is not end-to-end encrypted; the service can read content to analyse it.
- Enterprise can bring its own encryption keys (AWS KMS or Azure Key Vault).
- Transfers to processors in the United States rely on Standard Contractual Clauses or the EU-US Data Privacy Framework, as listed on the subprocessors page.
Which AI providers see what
| Provider | Purpose | Location |
|---|---|---|
| Attorly gateway | Routing and usage metering, first hop for every AI request | EU (Norway) |
| Anthropic | Primary model for analysis, drafting and research | United States |
| OpenAI | Fallback model and document embeddings | United States |
| Legal-corpus embeddings and fallback model | Global (Google Cloud) | |
| Mistral | Document OCR; optional EU-only analysis with your own key or a self-hosted deployment | EU (France) |
Every provider is used under API terms that exclude training on customer data.
Retention periods
| Data | Kept for |
|---|---|
| Account data | While the account is active |
| Documents | Until you delete them, or 30 days after account deletion |
| Analyses | 90 days after the document is deleted |
| Audit logs and admin audit logs | Two years |
| Discarded or failed Playbook Studio imports | 30 days after the last change |
| Payment records | Per Stripe’s retention policy |
The periods are the same as in the data processing agreement. A daily job deletes audit logs after two years and discarded Playbook Studio imports after 30 days; documents and analyses are deleted when you delete them or your account.
Frequently asked questions
- Can I keep all AI processing inside the EU?
- Yes, with your own Mistral key or a self-hosted Mistral deployment (Pro and Enterprise). The default models run with providers in the United States under the terms above.
- Is my content used to train AI models?
- No. Neither Attorly nor its AI providers train on your content.
- Can I get a security questionnaire answered?
- Yes. Email security@attorly.ai with your questionnaire. Attorly is not SOC 2 or ISO 27001 certified; controls are aligned to both, and the answers will say so.