In transit and at rest
TLS 1.3 protects data in transit. AES-256 protects data at rest. No exceptions for AI traffic.
Trust Center
Encryption, attorney-client privilege, and per-firm isolation, built into the platform and documented for your security team.
Book a DemoAES-256 at rest · Per-firm isolation · No training on client data
Overview
OurFirm.ai is an AI litigation workspace built for record-grounded work. Encryption, attorney-client privilege, and per-firm data isolation are architectural commitments, not features bolted on afterward. Every claim here maps to a control we operate or a document we can share under NDA, and where a certification is still in progress, we say so.
Certifications & Attestations
Where an audit or certification is complete, the certificate or report is available to your security team under NDA. Where a program is still underway, we say so, never before.
Platform Security
The controls that protect client data in transit, at rest, and in use, enforced by architecture and contract, not policy alone.
TLS 1.3 protects data in transit. AES-256 protects data at rest. No exceptions for AI traffic.
Per-firm, per-attorney, and per-conversation isolation. Your data is never co-mingled with another firm's.
Client documents never train any AI model. Enforced by BAAs with Anthropic and OpenAI, with zero data retention beyond session for inference.
Granular role-based permissions govern who can see and do what, with full audit logging of access and activity.
Compute runs on AWS EKS (Kubernetes) across multiple availability zones, with a 99.9% SLA and multi-region failover.
Data is purged within 24 hours of a deletion request, fully auditable. We analyze usage metadata to run the platform, never the substance of your documents.
Attorney-Client Privilege
OurFirm.ai was designed with attorney-client privilege in mind, and specifically post-Heppner v. United States (Feb. 2026), the first federal ruling to address privilege in the context of AI-assisted legal work.
Client communications stay within the attorney's controlled environment. Per-firm isolated data pipelines keep matters separate, and client data never enters an AI provider's training pipeline.
BAAs with both Anthropic and OpenAI prohibit model training on your data, with zero retention beyond session for inference, enforced by contract.
Document Library
Public documents you can read right now. Confidential reports, certificates, and policies are available to your General Counsel, IT security team, or malpractice carrier under a mutual NDA through our Trust Center.
The completed SOC 2 Type I report.
Request access→Certificate of registration and Statement of Applicability.
Request access→Privacy information management certification.
Request access→Our MSA, with custom redlines accepted for enterprise clients.
Request access→HIPAA-aligned BAA for firms handling protected health information.
Request access→A summary of our most recent third-party penetration test.
Request access→How we govern, classify, and protect information across the company.
Request access→Least-privilege, role-based access and review procedures.
Request access→Recovery objectives and continuity procedures for major disruption.
Request access→How we detect, triage, and communicate security incidents.
Request access→Subprocessors
The third parties that may process Customer Data to provide the Services. Each is bound by confidentiality, security, and data-protection obligations no less protective than our DPA and Security Addendum. No subprocessor may train models on Customer Data.
| Company | Purpose | Location | Data handling |
|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure: compute, storage, networking, backups, monitoring | United States | Encryption at rest and in transit; multi-AZ architecture |
| OpenAI, L.L.C. | Model inference for generation and analysis (where configured) | United States | No model training on Customer Data; enterprise endpoints |
| Anthropic PBC | Model inference for generation and analysis (where configured) | United States | Contractual prohibition on training on Customer Data |
| Google (Google Cloud / Gemini) | Model inference for generation and analysis (where configured) | United States | Contractual prohibition on training on Customer Data |
| Reducto.ai | OCR (document text extraction) | United States | No training on Customer Data; SOC 2 Type II-aligned controls |
Mirrors the Subprocessor List · Last updated Jan 29, 2026
Legal
The full set of versioned, dated documents that govern how we build and operate the platform.
Terms of service for using the Ourfirm.ai platform
How we collect, use, and protect your data
Details on our support and service level commitments
List of subprocessors we engage with
How we handle law enforcement and legal requests
Our security practices and commitments
Acceptable use guidelines for our services
Details on data processing and compliance
How we handle and use your usage data
Request Access
Knowledge Base
The questions security teams and General Counsel ask most often.
Yes. OurFirm.ai is built on enterprise-grade infrastructure with the following protections:
SOC 2 Type II certification is underway.
OurFirm.ai was architecturally designed with privilege in mind, and specifically post-Heppner v. United States (Feb. 2026), the first federal ruling to address attorney-client privilege in the context of AI-assisted legal work.
Key protections include: a privilege-protected client portal that keeps client communications within the attorney's controlled environment; BAAs executed with both Anthropic and OpenAI prohibiting model training on your data; per-firm isolated data pipelines; and zero data retention beyond session for AI inference calls. Client data never enters the AI provider's training pipeline, this is contractually enforced, not just policy.
Our MSA and DPA are available for review. We accept custom redlines from enterprise clients.
Yes. We support HIPAA-aligned workflows for clients who handle protected health information. Our Business Associate Agreement (BAA) is HIPAA-aligned, and we have executed BAAs with our AI subprocessors. Our DPA and subprocessor list are available on request. Contact us to discuss your firm's specific compliance requirements.
We provide a full enterprise security package on request, including:
We are available to speak directly with your GC, IT security team, or malpractice carrier. Contact andrew@ourfirm.ai to schedule.
Contact & Disclosure
Send suspected vulnerabilities and security concerns to our security team and we'll investigate promptly.
Enterprise contracting, MSA redlines, and General Counsel questions.
How we handle subpoenas, warrants, and other legal requests for data.
Enterprise MSA and onboarding support available