Security and data
Last updated:
A law firm asks where its data goes before it asks about features. This page answers the procurement questions with the facts we actually have. No badges. Architecture.
1. Hosting
The application and its data run on infrastructure located in the European Union. Data is encrypted in transit and at rest.
Turkish law does not require legal data to be held in Türkiye. We choose to host in the EU, which brings the data under the protection of the GDPR regime and a legal framework that can be audited.
2. Model inference and training
Model inference runs in an EU region.
Client content is not used to train third-party models. That is a commitment in our contracts with our providers.
Content passes through anonymisation before it leaves the boundary for inference.
3. The matter boundary
Access to your firm’s own documents is scoped to the matter they belong to. One client’s documents do not surface while a lawyer works on another.
This is not a filter, it is the default. The separation professional confidentiality requires is made into behaviour nobody has to remember.
Tenant separation is applied server side; no parameter sent by the client can change that boundary.
4. Deletion and retention
Delete a document and the original, its extracted text and its index entries go with it. If the deletion chain cannot complete, the operation fails and stops rather than half-deleting.
You can export your data before closing your account. After closing, the data is deleted.
5. Accounts and access
Access is managed by role under a firm account. Invitations and seat count are controlled by the firm administrator.
Email verification is required at signup.
6. Certification status
We hold no security certification: no SOC 2, no ISO 27001, nothing comparable.
We write that plainly. Implying a credential we do not have is the first thing an auditor in a procurement process notices, and it damages trust more than silence does. Everything listed above is true today and can be verified.
7. Data processing agreement
For personal data your firm is the controller and we are the processor, acting on your instructions.
A data processing agreement is available on request. Write to info@frontier.legal.