• SOC 2
  • Vendor Security
  • Data Privacy
  • AI Procurement

Security Built for Privilege: OurFirm.ai Receives SOC 2 Type 2 Attestation

Andrew Mancilla, Esq.2 min read
A security reviewer reading closely across two monitors of logs
On this page

Security is more than a promise. Controls must prove it.

OurFirm.ai has received its SOC 2 Type 2 attestation from an independent examination of our security controls, covering May 1, 2026 through July 31, 2026. The examination tested both the design and the operating effectiveness of those controls throughout that period, not at a single point in time. For firms evaluating AI for litigation, that distinction is the point.

When a platform handles client matters, work product, case strategy, and other highly sensitive information, security cannot be an afterthought or a promise made only during procurement.

Security built around the work

OurFirm.ai's security program is designed around the realities of litigation, with controls that include:

  • AES-256 encryption at rest, TLS 1.2+ in transit, tenant-isolated matter data
  • U.S.-based data processing on AWS
  • No-training, zero-retention terms across all model access
  • Continuous control monitoring and automated threat detection
  • Formal access, vendor-risk, and incident-response controls

These controls sit alongside OurFirm.ai's ISO/IEC 27001:2022 information security and ISO/IEC 27701:2019 privacy certifications. The full set of certifications, policies, and documents is collected in the Trust Center.

What does this mean for firms?

SOC 2 Type 2 doesn't replace a firm's own due diligence. It gives security, IT, and firm leadership one more piece of independent evidence to bring to that process.

Where the data goes. Who can access it. Whether it's retained or used to train a model. Those are the questions worth asking any AI vendor.

OurFirm.ai was built to make those questions answerable.

Security built for privilege.

Request our SOC 2 Type 2 report. Available to firms conducting security and due diligence review.

Request the report

Frequently asked questions

What is the difference between SOC 2 Type 1 and SOC 2 Type 2?
A Type 1 report covers whether a service organization's controls are suitably designed at a single point in time. A Type 2 report covers whether those controls were designed suitably and operated effectively throughout an observation period, typically several months or longer. OurFirm.ai has completed both examinations, and either report is available under NDA.
Does SOC 2 Type 2 mean a law firm can skip its own security review?
No. SOC 2 Type 2 does not replace a firm's own due diligence. It gives security, IT, and firm leadership one more piece of independent evidence to bring to that process: an examination performed by an independent auditor, covering a defined period, against a published set of criteria.
Which security controls does OurFirm.ai operate?
AES-256 encryption at rest, TLS 1.2+ in transit, tenant-isolated matter data, U.S.-based data processing on AWS, no-training and zero-retention terms across all model access, continuous control monitoring and automated threat detection, and formal access, vendor-risk, and incident-response controls. These sit alongside ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications.
How does a firm request OurFirm.ai's SOC 2 Type 2 report?
Through the OurFirm.ai Trust Center. The report is available under NDA to firms conducting security and due diligence review, alongside the SOC 2 Type 1 report, ISO certificates, penetration test summary, and subprocessor list.

Keep reading

Put it to work on your next matter.

Book a DemoMore from the blog