Back to Home

Security & Compliance

This page lists the specific security controls we operate to protect sensitive legal information — and names the certifications we do not hold.

Security Status

System SecurityActive
Data EncryptionEnabled
Access ControlsEnforced
MonitoringLogging enabled

Data Protection

All data encrypted with AES-256
User data isolation enforced
Generation activity recorded per account
Application and security event logging

What we do not claim

We hold no SOC 2 Type I or Type II attestation and do not claim one. We make no HIPAA de-identification claim: identifier detection is automated and best-effort, and name and address matching in particular are heuristics rather than guarantees. What is listed on this page is what is actually in place. If a vendor shows you a compliance badge, ask to see the report behind it.

Our Security Commitment

We understand that legal professionals handle highly sensitive information. This page describes the controls we operate, and names the certifications we do not hold, rather than asserting a general standard.

Encryption Everywhere

AES-256 encryption at rest and TLS 1.3 in transit protect your data

Privacy by Default

Personal identifiers are tokenized before any AI processing

Event Logging

Application and security events are logged for review

Security Questions?

Security questions are answered directly by the founder — write to security@demandai.pro