Your data, protected
Security is not a feature — it is how we build. Every document, message, and analysis is encrypted at rest and in transit.
AES-256 encryption at rest and in transit
All user-generated content — documents, analyses, chat messages, clauses — is encrypted with AES-256 before it hits disk, under versioned keys with rotation support. TLS 1.2+ protects data in transit. Only non-content metadata, such as file names and timestamps, remains searchable in plaintext.
GDPR compliant, EU data storage
Your data is stored in the EU — our infrastructure runs in Railway's EU-West region. Where a processor operates from the US, transfers rely on Standard Contractual Clauses or the EU-US Data Privacy Framework, documented per processor in our subprocessor register. We provide data processing agreements, honor right-to-erasure requests, and support full data portability.
SOC 2 Type II readiness
Infrastructure and processes designed to meet SOC 2 Type II criteria. Continuous monitoring, access controls, and change management — with third-party audit on the roadmap.
SSO with SAML 2.0
Centralize access management with enterprise single sign-on. SAML 2.0 integration with your identity provider — Okta, Azure AD, Google Workspace, and others.
Complete audit trail
Every action is logged: who did what, when, on which document. Immutable records for compliance reviews, internal investigations, and regulatory reporting.
Data residency options
Choose where your data lives. EU data residency by default, with additional regions available for enterprise customers on request.
How AI providers handle your data
Attorly uses frontier AI models for analysis, drafting, and research. This is exactly what leaves our infrastructure, and on which terms: requests are routed through our EU-hosted gateway, providers receive only the text needed for that request, and provider-side retention is limited to short-term abuse monitoring under the API terms linked below.
| Provider | Purpose | Location | Data terms |
|---|---|---|---|
| GetPlatform AI Gateway | Request routing and usage metering — our own service, the first hop for every AI request | EU (Norway) | View data terms |
| Anthropic (Claude) | Primary model for legal analysis, drafting, and research | United States | View data terms |
| OpenAI | Fallback model and document embeddings | United States | View data terms |
| Google (Gemini API) | Legal-corpus embeddings and fallback model | Global (Google Cloud) | View data terms |
| Mistral AI | Document OCR; optional EU-only analysis with your own key or self-hosted deployment | EU (France) | View data terms |
| Voyage AI | Legal-tuned embeddings — opt-in, bring-your-own-key only | United States | View data terms |
Never used for training
Your content is never used to train AI models — not by us, and not by our providers. Every provider is used under API terms that exclude training on customer data.
Only what the request needs
Providers receive the prompt and the document excerpts required for that specific request — never your document store. Your documents are stored encrypted in our EU infrastructure, not with AI providers.
Your keys, your models
Bring your own model key, or run analysis on a self-hosted EU-only deployment. Enterprise plans also support bring-your-own encryption keys (BYOK).
Full transparency
Every third party that touches your data is listed in our public subprocessor register, with its location, transfer mechanism, and data processing agreement.
Security built for legal work
Read our security documentation or talk to our team about your requirements.
Start your trial