Security & trust
Law firms hand us their clients' most sensitive documents. This page says plainly what happens to them.
Encryption, everywhere it matters
Documents are encrypted in transit (TLS) and at rest. Object-storage keys are themselves encrypted per record with AES-GCM and unique IVs, and contact details (emails, phone numbers) are encrypted at rest as well.
Uploads are scanned before they're processed
Every uploaded file passes malware scanning before translation. Files that fail scanning never reach a deliverable; inconclusive scans hold the document for human review rather than shipping it into your firm.
Signer integrity is enforced, not assumed
A certification is a legal attestation attributed to a person. In FirmCert, only the designated signer's own authenticated session can sign a document — a firm admin can't sign for a colleague, our operators can't sign for anyone, and our own support tooling is hard-blocked from signing. Uploads can be delegated; signatures cannot.
Departed members are deactivated, never deleted: the identity attached to every signed certification and audit entry survives staff changes.
A complete audit trail
Every page credit is logged — when, who uploaded, which document, how many pages, and which signer path — and the log is visible to your firm admins, not just to us. Support actions taken by our team on your workspace are recorded with both identities.
How the engine processes documents
Translations are produced by our proprietary pipeline, which combines commercial language-processing technology with our own formatting and quality systems. Document content is transmitted to the technology providers under API agreements that do not permit training on submitted content. The full subprocessor list is published at /subprocessors.
Text the engine cannot read is marked illegible rather than guessed — an invented name in a legal filing is a far bigger risk than an honest marker, and your reviewers see exactly what the engine saw.
Data handling and deletion
Client documents belong to your firm. Deletion requests are honored on demand, and certain records (billing, audit entries) are retained in de-identified or minimal form where law requires. A data-processing agreement (DPA) for firms is available as part of onboarding.
