- SOC 2
- Vendor Security
- Data Privacy
- AI Procurement
Security Built for Privilege: OurFirm.ai Receives SOC 2 Type 2 Attestation

Security is more than a promise. Controls must prove it.
OurFirm.ai has received its SOC 2 Type 2 attestation from an independent examination of our security controls, covering May 1, 2026 through July 31, 2026. The examination tested both the design and the operating effectiveness of those controls throughout that period, not at a single point in time. For firms evaluating AI for litigation, that distinction is the point.
When a platform handles client matters, work product, case strategy, and other highly sensitive information, security cannot be an afterthought or a promise made only during procurement.
Security built around the work
OurFirm.ai's security program is designed around the realities of litigation, with controls that include:
- AES-256 encryption at rest, TLS 1.2+ in transit, tenant-isolated matter data
- U.S.-based data processing on AWS
- No-training, zero-retention terms across all model access
- Continuous control monitoring and automated threat detection
- Formal access, vendor-risk, and incident-response controls
These controls sit alongside OurFirm.ai's ISO/IEC 27001:2022 information security and ISO/IEC 27701:2019 privacy certifications. The full set of certifications, policies, and documents is collected in the Trust Center.
What does this mean for firms?
SOC 2 Type 2 doesn't replace a firm's own due diligence. It gives security, IT, and firm leadership one more piece of independent evidence to bring to that process.
Where the data goes. Who can access it. Whether it's retained or used to train a model. Those are the questions worth asking any AI vendor.
OurFirm.ai was built to make those questions answerable.
Security built for privilege.
Request our SOC 2 Type 2 report. Available to firms conducting security and due diligence review.
Request the reportFrequently asked questions
What is the difference between SOC 2 Type 1 and SOC 2 Type 2?
Does SOC 2 Type 2 mean a law firm can skip its own security review?
Which security controls does OurFirm.ai operate?
How does a firm request OurFirm.ai's SOC 2 Type 2 report?
Keep reading
The Questions Your AI Vendor Should Answer in Writing
Attorney Judith Soto draws on her experience supporting FedRAMP-authorized products and enterprise security reviews to explain what every law firm should ask before buying legal AI.
From the Bench10 min readVerify or Get Sanctioned: What the Case Law Actually Requires
Courts aren't punishing attorneys for using AI. They're punishing attorneys for signing filings they never verified. Here's the doctrine emerging from three years of sanctions opinions.
From the Bench5 min readI Read the Heppner Opinion Twice. Here's What Actually Changes for Trial Lawyers.
Three lawyers warned me the Heppner ruling means AI destroys privilege. I read the opinion twice. That is not the holding, and the real lesson matters more.