Security & Compliance

Security that meets the attorney-client privilege standard.

Security that meets the attorney-client privilege standard.

Security that meets the attorney-client privilege standard.

Built on enterprise infrastructure with law firm confidentiality requirements at the core.

Built on enterprise infrastructure with law firm confidentiality requirements at the core.

Built on enterprise infrastructure with law firm confidentiality requirements at the core.

Our commitment

“Good enough” security isn’t good enough.

“Good enough” security isn’t good enough.

“Good enough” security isn’t good enough.

In legal practice, “good enough” security isn’t good enough. Sovereign Legal was architected with the same security standards used for classified government systems—because attorney-client privilege demands nothing less.

Zero-retention AI processing

Dedicated firm storage vaults

Audit-ready access controls

Infrastructure security

Infrastructure security

AWS Bedrock Foundation

Sovereign Legal runs entirely on AWS Bedrock, Amazon’s enterprise AI platform used by Fortune 500 companies and government agencies.

Sovereign Legal runs entirely on AWS Bedrock, Amazon’s enterprise AI platform used by Fortune 500 companies and government agencies.

No training on your data • SOC 2 Type II compliant infrastructure • 99.9% uptime SLA • DDoS protection

No training on your data • SOC 2 Type II compliant infrastructure • 99.9% uptime SLA • DDoS protection

Your data never leaves AWS’s secure environment.

Multi-Tenant Isolation

Each law firm gets dedicated AWS S3 storage buckets. Your documents are not stored in a shared database—they live in your firm’s isolated vault.

Each law firm gets dedicated AWS S3 storage buckets. Your documents are not stored in a shared database—they live in your firm’s isolated vault.

True data separation • Easier regulatory compliance • Export control without vendor lock-in

True data separation • Easier regulatory compliance • Export control without vendor lock-in

Visual metaphor

Each firm owns its own safe deposit box, not a drawer in a shared filing cabinet.

Encryption

Protected at rest, in transit, and during processing.

At rest: all documents encrypted using AES-256 bank-grade standards. In transit: TLS 1.3 encryption for all data transfers. At processing: end-to-end encryption during AI analysis, with documents decrypted only in secure memory and never written to disk unencrypted.

At rest: all documents encrypted using AES-256 bank-grade standards. In transit: TLS 1.3 encryption for all data transfers. At processing: end-to-end encryption during AI analysis, with documents decrypted only in secure memory and never written to disk unencrypted.

Access control

Roles, sessions, and controls built for firms.

Firm Administrators manage users, admin console, and billing. Standard Users query documents and run comparisons. Audit-Only Users view logs without document access. Session controls include automatic logout, optional IP restrictions, and multi-factor authentication coming Q3 2026.

Firm Administrators manage users, admin console, and billing. Standard Users query documents and run comparisons. Audit-Only Users view logs without document access. Session controls include automatic logout, optional IP restrictions, and multi-factor authentication coming Q3 2026.

PII sanitization

Automatic redaction before vector storage.

Before documents enter the vector database, Sovereign Legal can detect and sanitize Social Security Numbers, credit cards, bank accounts, email addresses, and phone numbers. Turn it on for sensitive matters, leave it off for standard contracts.

Before documents enter the vector database, Sovereign Legal can detect and sanitize Social Security Numbers, credit cards, bank accounts, email addresses, and phone numbers. Turn it on for sensitive matters, leave it off for standard contracts.

Privilege protection

Controls aligned to privileged legal work.

Your queries and documents are never used to train AI models. Matter-based filtering keeps Matter A physically separated from Matter B. Every access is logged for privilege logs, security audits, and malpractice defense.

Your queries and documents are never used to train AI models. Matter-based filtering keeps Matter A physically separated from Matter B. Every access is logged for privilege logs, security audits, and malpractice defense.

Compliance readiness, without hand-waving.

Compliance readiness, without hand-waving.

Business Associate Agreement

Available upon request

For firms handling HIPAA-covered health information. AWS Bedrock infrastructure is HIPAA-eligible, and we can execute a BAA for your use case.

Business Associate Agreement

Available upon request

For firms handling HIPAA-covered health information. AWS Bedrock infrastructure is HIPAA-eligible, and we can execute a BAA for your use case.

GDPR Compliance

Residency, deletion, export

US regions by default, permanent matter deletion, and full dataset export whenever your firm needs it.

GDPR Compliance

Residency, deletion, export

US regions by default, permanent matter deletion, and full dataset export whenever your firm needs it.

SOX / Financial Compliance

Audit logs for auditors

Immutable logging, access control documentation, and logs designed to support Sarbanes-Oxley requirements.

SOX / Financial Compliance

Audit logs for auditors

Immutable logging, access control documentation, and logs designed to support Sarbanes-Oxley requirements.

Data Retention & Deletion

Your data, your control

Soft delete archives matters, hard delete permanently purges documents and vectors, and export before deletion gives your firm a full S3 download.

Data Retention & Deletion

Your data, your control

Soft delete archives matters, hard delete permanently purges documents and vectors, and export before deletion gives your firm a full S3 download.

Disaster Recovery

Backups and continuity

Daily snapshots, 30-day historical versions, optional cross-region replication, and 99.9% uptime across multiple availability zones.

Disaster Recovery

Backups and continuity

Daily snapshots, 30-day historical versions, optional cross-region replication, and 99.9% uptime across multiple availability zones.

Vulnerability Management

Continuous monitoring

Annual penetration testing, weekly vulnerability scanning, and critical security patch deployment within 48 hours of CVEs.

Vulnerability Management

Continuous monitoring

Annual penetration testing, weekly vulnerability scanning, and critical security patch deployment within 48 hours of CVEs.

Transparency

What we can and cannot see

Admins can see aggregate usage and error logs. We cannot see document contents, query text, results, client names, or matter names without explicit permission.

Transparency

What we can and cannot see

Admins can see aggregate usage and error logs. We cannot see document contents, query text, results, client names, or matter names without explicit permission.

Third-party subprocessors

AWS handles Bedrock, S3, and CloudWatch infrastructure. Weaviate Cloud hosts the vector database. Supabase powers authentication. No other third parties have access to your data.

Security documentation

Need architecture diagrams?

Request our Security White Paper through the demo form for your IT team or compliance officer.

Request our Security White Paper through the demo form for your IT team or compliance officer.

See our security controls in action.

See our security controls in action.

See our security controls in action.

Bring your IT team to the demo. We welcome technical questions.