Built for people with a duty of care.
Every safeguard in LITIGATER exists because your license depends on it, not because a compliance checklist said so.
- SOC 2 Type II compliant
- GDPR compliant
- Subprocessors: listed below
- Full documentation: on request
Your duties. Our architecture.
LITIGATER was built to the standard set by ABA Formal Opinion 512 (July 2024), the ABA's first ethics opinion on generative AI. Every duty it names maps to something you can point at in the product.
- Competence · Rule 1.1
- Every product page on this site publishes what the module doesn't do, next to what it does. You can't supervise a capability you were oversold.
- Confidentiality · Rule 1.6
- Encryption everywhere, zero data retention with model providers, no training on your data, access controls you administer.
- Supervision · Rules 5.1 & 5.3
- Every AI-assisted output logged with who ran it and what checked it. The Gate verifies citations before anything ships. Built to be supervised, not just used.
- Candor · Rules 3.1 & 3.3
- Two-layer citation verification: good law, and says what you claim it says.
Privilege, protected by design.
Nothing protects privilege absolutely except never telling anyone anything. Short of that, the law protects communications handled with reasonable care, and the early decisions draw the line where you'd expect it: unilateral use of consumer AI tools, whose terms permit retention and disclosure, has destroyed protection, while courts have expressly left the door open for tools operating under counsel's direction and bound to confidentiality.
LITIGATER is engineered to be the second kind:
- Contractually bound to confidentiality: LITIGATER and every subprocessor, by name. Not just configured for it. Bound to it.
- Zero data retention with our model providers: your prompts and documents are never stored after the response is generated.
- No training on your data. Ever. Ours or theirs.
- Your matters are logically isolated. Access is yours to grant and yours to revoke.
We will never tell you waiver is impossible. No honest vendor will. What we built is the record that makes the argument.
Zero data retention, precisely.
"Zero data retention" is a defined, contractual arrangement with each model provider we use, not a marketing phrase. Your content (prompts, documents, outputs) is never stored by a model provider after the response is generated.
You hold the key.
On the Litigation Team tier, encryption keys live in your key management system, not ours. Disable the key, and LITIGATER loses the ability to read your data. Including us. Revocation is a control you hold, not a ticket you file.
The architecture.
- AES-256 encryption at rest. TLS in transit. Every document, every time.
- The evidence record is sealed, hash-chained, and stored write-once. The same chain of custody we market is the one protecting your file.
- SAML SSO, role-based access control, IP allow-listing, and a full audit log of every action on every matter.
- Retention and deletion are customer-controlled: delete a matter's data on your schedule, not ours.
Compliance, stated exactly.
SOC 2: LITIGATER is SOC 2 Type II compliant. Our controls have been independently audited and attested against the AICPA Trust Services Criteria. The report is available under NDA on request.
GDPR: LITIGATER is GDPR compliant. A Data Processing Agreement is available on request, Standard Contractual Clauses govern any EU-to-US transfer, and an EU hosting option exists for firms that require in-region processing.
Subprocessors: every subprocessor, named. Every region, disclosed. No black box.
Deposition consent, by jurisdiction.
Some states require one party's consent to record a conversation; some require everyone's. LITIGATER's live deposition features begin with a consent workflow, on the record, before anything runs. The feature doesn't start without it.
And the position we'll repeat anywhere it's printed: LITIGATER works beside your court reporter. The official transcript belongs to the certified reporter, and stays theirs.
Judge analytics, and the ethics question.
Is organizing a judge's record even allowed?
In the United States, yes. Dockets, filings, and rulings are public records, and understanding them is a long tradition; what a court does in public is the public's to understand. France chose differently and banned judicial analytics; the American tradition treats sunlight on public acts as the default. We think that's the right answer, and we built to it.
What Litigation Intelligence will not do: touch anything private, scrape anything from behind a login, or present a raw number as a prophecy. Everything is sourced to the public record and benchmarked against a baseline. Patterns, not verdicts about people.
Procurement, welcomed.
Security documentation, the DPA, subprocessor list, and audit reports are available during evaluation. Bring the questionnaire.