Skip to main content
Security

Your data, protected

Security is not a feature — it is how we build. Every document, message, and analysis is encrypted at rest and in transit.

GDPR compliant
SOC 2 Ready
Encrypted at rest & in transit

AES-256 encryption at rest and in transit

All user-generated content — documents, analyses, chat messages, clauses — is encrypted with AES-256 before it hits disk, under versioned keys with rotation support. TLS 1.2+ protects data in transit. Only non-content metadata, such as file names and timestamps, remains searchable in plaintext.

GDPR compliant, hosted in the EU

Attorly runs in Railway's EU-West region and your case data lives in our EU database; uploaded files are stored encrypted on Cloudflare R2. Where a processor operates from the US — Cloudflare and the AI model providers among them — transfers rely on Standard Contractual Clauses or the EU-US Data Privacy Framework, documented per processor in our subprocessor register. We provide data processing agreements, honor right-to-erasure requests, and support full data portability.

SOC 2 Type II readiness

Infrastructure and processes designed to meet SOC 2 Type II criteria. Continuous monitoring, access controls, and change management — with third-party audit on the roadmap.

SSO with SAML 2.0

Centralize access management with enterprise single sign-on. SAML 2.0 integration with your identity provider — Okta, Azure AD, Google Workspace, and others.

Complete audit trail

Every action is logged: who did what, when, on which document. Immutable records for compliance reviews, internal investigations, and regulatory reporting.

Where your data lives

Attorly runs on EU servers in Railway's EU-West region, and your case data lives in our EU database. Uploaded files are encrypted on our servers before they are stored on Cloudflare R2, which does not guarantee they stay in the EU. AI analysis is processed by US-based model providers under EU standard contractual clauses — see the AI providers section below. Enterprise customers can bring their own storage bucket and encryption keys to keep files in a region of their choice.

How AI providers handle your data

Attorly uses frontier AI models for analysis, drafting, and research. This is exactly what leaves our infrastructure, and on which terms: requests are routed through our EU-hosted gateway (or directly to the same providers if it is unreachable), providers receive only the text needed for that request, and provider-side retention is limited to short-term abuse monitoring under the API terms linked below.

ProviderPurposeLocationData terms
GetPlatform AI GatewayRequest routing and usage metering — our own service, the first hop for AI requests; if it is unreachable, requests go directly to the same providersEU (Netherlands)View data terms
Anthropic (Claude)Primary model for legal analysis, drafting, and researchUnited StatesView data terms
OpenAIFallback model and document embeddingsUnited StatesView data terms
Google (Gemini API)Legal-corpus embeddings and fallback modelGlobal (Google Cloud)View data terms
Mistral AIDocument OCR; optional EU-only analysis with your own key or self-hosted deploymentEU (France)View data terms
Voyage AILegal-tuned embeddings — opt-in, bring-your-own-key onlyUnited StatesView data terms

Never used for training

Your content is never used to train AI models — not by us, and not by our providers. Every provider is used under API terms that exclude training on customer data.

Only what the request needs

Providers receive the prompt and the document excerpts required for that specific request — never your document store. Your documents stay encrypted in our own storage, not with AI providers.

Your keys, your models

Bring your own model key, or run analysis on a self-hosted EU-only deployment. Enterprise plans also support bring-your-own encryption keys (BYOK).

Full transparency

Every third party that touches your data is listed in our public subprocessor register, with its location, transfer mechanism, and data processing agreement.

How long we keep your data

These are the periods in our data processing agreement. A daily job deletes audit logs after two years and discarded playbook imports after 30 days; documents and analyses are deleted when you delete them or your account, within the periods below.

DataKept for
Account dataWhile the account is active
DocumentsUntil you delete them, or 30 days after account deletion
Analyses90 days after the document is deleted
Audit logsTwo years
Discarded playbook imports30 days after the last change

Security questionnaires

Send your security questionnaire or vendor assessment to security@attorly.ai. Attorly is not SOC 2 or ISO 27001 certified; our answers say so and describe the controls in place.

Email security@attorly.ai

Security built for legal work

Read our security documentation or talk to our team about your requirements.

Start your trial