Security & Compliance at Disclosure Assistant
Institutional-grade protection engineered for legal practices handling privileged financial records, bank statement discovery, and court disclosures.
Last updated: September 17, 2026
Our Commitment to Legal Confidentiality
At Disclosure Assistant, protecting attorney-client work product and confidential financial records is our highest architectural mandate. We understand that bank statements, account ledgers, and cash flow records processed in our system represent sensitive discovery materials subject to strict legal privilege and ethical confidentiality rules.
Our platform operates on uncompromising principles of data minimization, zero artificial intelligence model training on customer files, and total cryptographic isolation between law firms. We do not sell, monetize, or repurpose user documents under any circumstances.
Every architectural layer—from file ingestion to database queries—is built to ensure that confidential client financial records remain accessible solely to authorized legal counsel.
Data Security Architecture
Encryption in Transit (TLS 1.3)
All data exchanged between client browsers, edge compute routers, and database instances is encrypted using Transport Layer Security (TLS 1.3 / TLS 1.2) with strict modern cipher suites. Insecure HTTP connections are automatically redirected to HTTPS via HSTS headers.
Encryption at Rest (AES-256)
Uploaded bank statement PDFs, parsed transaction records, and database rows are encrypted at rest using industry-standard AES-256 encryption. Encryption keys are managed and rotated via FIPS 140-2 compliant hardware security modules.
Row Level Security (RLS) on All Tables
Our PostgreSQL database enforces Row Level Security (RLS) directly at the database engine level across all tables (cases, transactions, case_files, integrations). Each database query is scoped strictly to the authenticated user ID (auth.uid()), mathematically preventing cross-tenant data leakage.
Continuous Backups & PITR
Database states are continuously backed up via write-ahead logging (WAL) with point-in-time recovery (PITR) capabilities. Backup archives are encrypted and geographically distributed across fault-isolated availability zones to guarantee disaster resilience.
Infrastructure & Third-Party Subprocessors
Disclosure Assistant engages a limited set of verified, SOC 2 / ISO-compliant service providers to deliver hosting, database storage, email notifications, and payment processing.
| Subprocessor / Vendor | Purpose in Architecture | Location | Data Accessed |
|---|---|---|---|
| Vercel, Inc. | Application hosting, serverless compute runtime, global edge routing | United States (US-East) / Global Edge | Ephemeral HTTP payloads, client IP addresses; temporary file upload streams in memory |
| Supabase, Inc. (AWS) | Managed PostgreSQL database, user authentication, and encrypted object storage | United States (AWS us-east-1) | User accounts, case names, parsed financial transactions, uploaded statement PDFs |
| OpenAI, LLC | Table reconstruction & semantic transaction categorization (API) | United States | Text-layer transaction lines (date, description, amount). Commercial zero-retention API; never used for model training |
| OkraPDFScanned PDF OCR Fallback | Optical character recognition (OCR) and layout extraction for scanned paper statements lacking a digital text layer | United States | Document image buffers of scanned bank statements. Ephemeral processing; zero model training |
| Paddle.com Market Ltd | Primary Merchant of Record, subscription billing, and tax compliance | United Kingdom / United States | Billing contact details, subscription status, payment methods (PCI-DSS Level 1 compliant; raw card data never touches our servers) |
| Creem | Secondary checkout and payment processing provider | United States | Customer billing email, checkout session tokens, payment transaction confirmation |
| Resend, Inc. | Transactional email delivery | United States | User email addresses, password reset tokens, security notifications |
| PostHog, Inc. | Product analytics and user session diagnostic telemetry | United States (PostHog US Cloud) | User IDs, email addresses, browser/device metadata, UI interaction events. Statement file contents are strictly excluded |
| Clio (Themis Solutions)Optional Integration | Direct export of completed review reports into law firm matter folders | Multi-Region (US, CA, EU, AU based on firm setup) | OAuth tokens, matter IDs, and exported report PDFs/CSVs when explicitly dispatched by user |
Access Control & Engineering Hygiene
Mandatory Two-Factor Authentication (2FA)
Hardware-backed or authenticator-based 2FA is strictly enforced across all internal accounts, code repositories, cloud infrastructure consoles, and administrative services.
Principle of Least Privilege (PoLP)
Access to production systems is restricted strictly to programmatic API roles. Engineering personnel do not hold standing administrative database access; any operational maintenance requires documented, time-bounded elevation.
Protected Branches & Mandatory Code Reviews
All source code is maintained under strict GitHub branch protection rules. No direct commits to production branches are permitted; every pull request requires automated type checking, linting, and peer code review before deployment.
Strict Environment Isolation
Development, staging, and local environments operate against synthetic test fixtures and zero-value mock statements. Live production client data and uploaded statements are never cloned or mirrored to test environments.
Data Handling & Retention Policy
Customer-Controlled Retention
Uploaded statements, case ledgers, custom rules, and analysis summaries are retained in your account for as long as your case remains active. You maintain full control over the lifecycle of your client files.
Instant Self-Serve Deletion
Attorneys can delete individual files, specific cases, or their entire account at any time directly through the dashboard. Deleting a case triggers an immediate cascading database purge of all transaction lines, extraction files, and review findings. Deleting an account permanently wipes all user data and credentials from active production databases.
Absolute No-AI-Training Guarantee
We contractually ensure that customer documents, transaction descriptions, notes, and financial figures are NEVER used to train, retrain, or improve public or proprietary artificial intelligence or machine learning models (including OpenAI foundational models).
Incident Response & Breach Notification
Disclosure Assistant maintains a documented Incident Response (IR) Plan covering incident detection, threat isolation, forensic auditing, containment, and recovery.
24-Hour Notification Commitment: In the unlikely event of a verified security incident resulting in unauthorized access to, exposure of, or alteration of customer data, Disclosure Assistant will notify affected account owners via email within 24 hours of incident confirmation.
Breach communications provide actionable information including the scope of data involved, remediation steps implemented, and guidance for counsel.
Regulatory Compliance & Standards
GDPR Compliance
Full support for European and UK data protection standards, including individual rights to access, rectification, portability (CSV/JSON export), and erasure ("Right to be Forgotten").
CCPA / CPRA Compliance
Adherence to California consumer privacy requirements. We do not sell, rent, or monetize client personal or financial information.
PCI-DSS Level 1
All payment card handling is outsourced directly to certified PCI-DSS Level 1 Service Providers (Paddle & Creem). Our infrastructure never ingests or stores card numbers.
Security Questions & Vulnerability Reporting
Direct channel to our engineering and security response team
For security inquiries, vendor due diligence questionnaires, or to report a suspected vulnerability under responsible disclosure principles, please contact our security team: