This page lists the specific security controls we operate to protect sensitive legal information — and names the certifications we do not hold.
We hold no SOC 2 Type I or Type II attestation and do not claim one. We make no HIPAA de-identification claim: identifier detection is automated and best-effort, and name and address matching in particular are heuristics rather than guarantees. What is listed on this page is what is actually in place. If a vendor shows you a compliance badge, ask to see the report behind it.
We understand that legal professionals handle highly sensitive information. This page describes the controls we operate, and names the certifications we do not hold, rather than asserting a general standard.
AES-256 encryption at rest and TLS 1.3 in transit protect your data
Personal identifiers are tokenized before any AI processing
Application and security events are logged for review
Security questions are answered directly by the founder — write to security@demandai.pro