Enterprise Legal Data Safeguards

Security & Compliance at Disclosure Assistant

Institutional-grade protection engineered for legal practices handling privileged financial records, bank statement discovery, and court disclosures.

Last updated: September 17, 2026

Our Commitment to Legal Confidentiality

At Disclosure Assistant, protecting attorney-client work product and confidential financial records is our highest architectural mandate. We understand that bank statements, account ledgers, and cash flow records processed in our system represent sensitive discovery materials subject to strict legal privilege and ethical confidentiality rules.

Our platform operates on uncompromising principles of data minimization, zero artificial intelligence model training on customer files, and total cryptographic isolation between law firms. We do not sell, monetize, or repurpose user documents under any circumstances.

Every architectural layer—from file ingestion to database queries—is built to ensure that confidential client financial records remain accessible solely to authorized legal counsel.

Data Security Architecture

Encryption in Transit (TLS 1.3)

All data exchanged between client browsers, edge compute routers, and database instances is encrypted using Transport Layer Security (TLS 1.3 / TLS 1.2) with strict modern cipher suites. Insecure HTTP connections are automatically redirected to HTTPS via HSTS headers.

Encryption at Rest (AES-256)

Uploaded bank statement PDFs, parsed transaction records, and database rows are encrypted at rest using industry-standard AES-256 encryption. Encryption keys are managed and rotated via FIPS 140-2 compliant hardware security modules.

Row Level Security (RLS) on All Tables

Our PostgreSQL database enforces Row Level Security (RLS) directly at the database engine level across all tables (cases, transactions, case_files, integrations). Each database query is scoped strictly to the authenticated user ID (auth.uid()), mathematically preventing cross-tenant data leakage.

Continuous Backups & PITR

Database states are continuously backed up via write-ahead logging (WAL) with point-in-time recovery (PITR) capabilities. Backup archives are encrypted and geographically distributed across fault-isolated availability zones to guarantee disaster resilience.

Primary Data Hosting Region: Our core database, encrypted object storage, and serverless compute infrastructure are deployed in the United States (AWS us-east-1, Northern Virginia) through Supabase and Vercel. All client financial data resides within this region.

Infrastructure & Third-Party Subprocessors

Disclosure Assistant engages a limited set of verified, SOC 2 / ISO-compliant service providers to deliver hosting, database storage, email notifications, and payment processing.

Subprocessor / VendorPurpose in ArchitectureLocationData Accessed
Vercel, Inc.Application hosting, serverless compute runtime, global edge routingUnited States (US-East) / Global EdgeEphemeral HTTP payloads, client IP addresses; temporary file upload streams in memory
Supabase, Inc. (AWS)Managed PostgreSQL database, user authentication, and encrypted object storageUnited States (AWS us-east-1)User accounts, case names, parsed financial transactions, uploaded statement PDFs
OpenAI, LLCTable reconstruction & semantic transaction categorization (API)United StatesText-layer transaction lines (date, description, amount). Commercial zero-retention API; never used for model training
OkraPDFScanned PDF OCR FallbackOptical character recognition (OCR) and layout extraction for scanned paper statements lacking a digital text layerUnited StatesDocument image buffers of scanned bank statements. Ephemeral processing; zero model training
Paddle.com Market LtdPrimary Merchant of Record, subscription billing, and tax complianceUnited Kingdom / United StatesBilling contact details, subscription status, payment methods (PCI-DSS Level 1 compliant; raw card data never touches our servers)
CreemSecondary checkout and payment processing providerUnited StatesCustomer billing email, checkout session tokens, payment transaction confirmation
Resend, Inc.Transactional email deliveryUnited StatesUser email addresses, password reset tokens, security notifications
PostHog, Inc.Product analytics and user session diagnostic telemetryUnited States (PostHog US Cloud)User IDs, email addresses, browser/device metadata, UI interaction events. Statement file contents are strictly excluded
Clio (Themis Solutions)Optional IntegrationDirect export of completed review reports into law firm matter foldersMulti-Region (US, CA, EU, AU based on firm setup)OAuth tokens, matter IDs, and exported report PDFs/CSVs when explicitly dispatched by user

Access Control & Engineering Hygiene

Mandatory Two-Factor Authentication (2FA)

Hardware-backed or authenticator-based 2FA is strictly enforced across all internal accounts, code repositories, cloud infrastructure consoles, and administrative services.

Principle of Least Privilege (PoLP)

Access to production systems is restricted strictly to programmatic API roles. Engineering personnel do not hold standing administrative database access; any operational maintenance requires documented, time-bounded elevation.

Protected Branches & Mandatory Code Reviews

All source code is maintained under strict GitHub branch protection rules. No direct commits to production branches are permitted; every pull request requires automated type checking, linting, and peer code review before deployment.

Strict Environment Isolation

Development, staging, and local environments operate against synthetic test fixtures and zero-value mock statements. Live production client data and uploaded statements are never cloned or mirrored to test environments.

Data Handling & Retention Policy

Customer-Controlled Retention

Uploaded statements, case ledgers, custom rules, and analysis summaries are retained in your account for as long as your case remains active. You maintain full control over the lifecycle of your client files.

Instant Self-Serve Deletion

Attorneys can delete individual files, specific cases, or their entire account at any time directly through the dashboard. Deleting a case triggers an immediate cascading database purge of all transaction lines, extraction files, and review findings. Deleting an account permanently wipes all user data and credentials from active production databases.

Absolute No-AI-Training Guarantee

We contractually ensure that customer documents, transaction descriptions, notes, and financial figures are NEVER used to train, retrain, or improve public or proprietary artificial intelligence or machine learning models (including OpenAI foundational models).

Incident Response & Breach Notification

Disclosure Assistant maintains a documented Incident Response (IR) Plan covering incident detection, threat isolation, forensic auditing, containment, and recovery.

24-Hour Notification Commitment: In the unlikely event of a verified security incident resulting in unauthorized access to, exposure of, or alteration of customer data, Disclosure Assistant will notify affected account owners via email within 24 hours of incident confirmation.

Breach communications provide actionable information including the scope of data involved, remediation steps implemented, and guidance for counsel.

Regulatory Compliance & Standards

GDPR Compliance

Full support for European and UK data protection standards, including individual rights to access, rectification, portability (CSV/JSON export), and erasure ("Right to be Forgotten").

CCPA / CPRA Compliance

Adherence to California consumer privacy requirements. We do not sell, rent, or monetize client personal or financial information.

PCI-DSS Level 1

All payment card handling is outsourced directly to certified PCI-DSS Level 1 Service Providers (Paddle & Creem). Our infrastructure never ingests or stores card numbers.

Security Questions & Vulnerability Reporting

Direct channel to our engineering and security response team

For security inquiries, vendor due diligence questionnaires, or to report a suspected vulnerability under responsible disclosure principles, please contact our security team:

Contact Security Teamsecurity@disclosureassistant.com