Security and confidentiality
Specific about implemented controls. Clear about current limits.
Private workspace requests require authentication and are limited to the authorised organisation and matter. The public demo uses separate synthetic records.
Implemented control areas
What these controls protect.
Scoped to the authorised matter
Private application operations carry authenticated organisation and matter scope.
Identity retained
Document version, page, extracted offsets and verification state remain attached to displayed results.
Synthetic record only
The public experience serves approved demonstration PDFs and never reads a client matter.
No certification claim
This describes implemented product boundaries; it does not claim an external security certification or audit.
A document request path
Scope is checked before content is served.
- 01
An authenticated practitioner requests an upload for one matter.
- 02
The server verifies organisation, membership and matter scope.
- 03
Private document access is issued for a defined purpose rather than exposed as a public object URL.
- 04
Source identity and verification state stay attached to matter intelligence.
- 05
The practitioner reviews material outputs against the source record.
Current limitations
These are product controls, not a certification.
This page describes implemented product boundaries; it is not a claim of an external certification, audit or universal production configuration.
Private access is not yet available. Do not submit confidential or client material through the public site or ordinary email.
The public samples prove separation for the approved synthetic experience. They do not establish every future deployment or workflow.
Control statement reviewed · 11 September 2026
Request a security review conversation →