Skip to content
LITIGATERLITIGATER

DUTY OF CARE

AI built for informationthat cannot bleed.

Built for firms handling privileged communications, attorney work product, confidential discovery, third-party productions, protected personal information, and court-restricted material.

Security is part of the architecture that governs how information is stored, retrieved, processed, shared, and used by AI.

Your duties. Our architecture.

LITIGATER was built to the standard set by ABA Formal Opinion 512 (July 2024), the ABA's first ethics opinion on generative AI. That is the duty of care this page is named for, and every duty it names maps to something you can point at in the product.

Competence · Rule 1.1
Every product page on this site publishes what the module doesn't do, next to what it does. You can't supervise a capability you were oversold.
Confidentiality · Rule 1.6
Encryption everywhere, zero data retention with model providers, no training on your data, access controls you administer.
Supervision · Rules 5.1 & 5.3
Every AI-assisted output logged with who ran it and what checked it. The Gate verifies citations before anything ships. Built to be supervised, not just used.
Candor · Rules 3.1 & 3.3
Two-layer citation verification: good law, and says what you claim it says.

Legal matters are security boundaries.

Traditional SaaS treats the organization as the primary security perimeter. Legal work is different.

Access varies between firms, matters, teams, ethical walls, discovery classifications, outside experts, clients, and categories of information inside the same matter.

  • Organization isolation: customer information is segregated between law firms at the architecture level, independent of UI permissions.
  • Matter isolation: access to one matter does not imply access to another. Matter authorization is independently evaluated throughout the platform.
  • Information-level controls: privileged, confidential, highly confidential, attorneys' eyes only, sealed, regulated, or otherwise restricted information can carry additional access and processing controls.
  • Policy-aware access: permissions can reflect roles, matter relationships, ethical walls, information classification, processing purpose, and customer policy.
  • Default deny: access must be affirmatively authorized. Broad organizational access does not silently override matter-specific restrictions.

The matter is the boundary. Everything else is enforcement detail.

AI never decides what it is allowed to see.

LITIGATER separates AI reasoning from authorization. Models do not receive unrestricted access to a firm's knowledge base, and they are not relied upon to enforce security policy.

Before information can enter an AI context, the platform determines whether the requesting user, service, or AI agent is authorized for the relevant firm, matter, information class, action, and processing context. AI agents operate with scoped, temporary authority rather than standing access.

This design keeps cross-firm, cross-matter, and unauthorized retrieval from becoming an AI problem in the first place.

Private matter data stays private.

Customer matter information is never treated as a shared intelligence corpus. It is designed never to enter another firm's:

  • Search results
  • Retrieval context
  • AI memory
  • Semantic cache
  • Vector corpus
  • Analytics dataset
  • Model-training data

"Zero data retention" is a defined, contractual arrangement with each model provider we use, not a marketing phrase. With every model provider we use today, zero data retention means your content (prompts, documents, outputs) is not stored after the response is generated.

Approved AI providers are governed through enterprise data-processing controls, including no-training requirements and zero-data-retention configurations where contractually and technically supported. Provider, model, endpoint, retention, and processing policies are centrally controlled, not left to individual users.

Retention and deletion are customer-controlled. Delete a matter's data on your own schedule; deletion on demand is addressed in the DPA.

Privilege, protected by design.

Nothing protects privilege absolutely except never telling anyone anything. Short of that, the law protects communications handled with reasonable care, and the early decisions draw the line where you'd expect it: unilateral use of consumer AI tools, whose terms permit retention and disclosure, has destroyed protection, while courts have expressly left the door open for tools operating under counsel's direction and bound to confidentiality.

Source: United States v. Heppner (S.D.N.Y. 2026), consumer-tool use destroyed privilege with the professional-tool question expressly reserved; Warner v. Gilbarco (E.D. Mich. 2026), AI treated as a tool, not a person, and work product preserved.

LITIGATER is engineered to be the second kind:

  • Contractually bound to confidentiality: LITIGATER and every subprocessor, by name.
  • Zero data retention with our model providers: nothing you send survives past the response that answers it.
  • No training on your data. Ever. Ours or theirs.
  • Your matters are logically isolated. Access is yours to grant and yours to revoke.

We will never tell you waiver is impossible. No honest vendor will. What we built is the record that makes the argument.

Encryption is expected. Key isolation matters more.

Information is protected in transit and at rest with modern cryptographic controls, but encryption alone is not sufficient for multitenant legal information.

On the Litigation Team tier, encryption keys live in your key management system, not ours. Disable the key, and LITIGATER loses the ability to read your data. Including us. Revocation is a control you exercise directly, no support ticket required.

No ordinary support workflow depends on unrestricted standing access to customer matter content.

The controls that carry that weight:

  • AES-256 encryption at rest, TLS in transit
  • IP allow-listing
  • Authorization of cryptographic operations
  • Workload identity
  • Key isolation
  • Service-to-service authentication
  • Controlled administrative access
  • Credential lifecycle
  • Separation of production security responsibilities

Enterprise isolation when shared infrastructure is not enough.

Some firms will not permit sensitive workloads in a shared application environment. We designed for that.

Enterprise deployments can be provisioned with dedicated infrastructure boundaries: isolated cloud environments, networking, compute, databases, storage, cryptographic controls, search infrastructure, backups, logging, and customer-specific security policy.

Private connectivity, enterprise identity integration, customer-managed security requirements, and regional deployment are supported per the firm's security profile.

The same LITIGATER product. A security boundary appropriate for the customer.

Every consequential action leaves a trail.

Security and matter activity is recorded in attributable, tamper-evident records.

Sensitive matter content is intentionally minimized within centralized security telemetry.

  • Authentication and authorization decisions
  • Matter and document access
  • Permission and ethical-wall changes
  • AI processing
  • Exports and external disclosures
  • Administrative access
  • Legal-hold and retention activity
  • Evidence ingestion and transformation
  • Security-policy changes

For evidentiary workflows, LITIGATER can preserve source provenance, version lineage, transformation history, and a sealed, hash-chained, write-once evidence record designed to support chain-of-custody requirements.

Derived information remains protected.

Security should not disappear when information is summarized. When protected source material is used to create facts, timelines, summaries, AI analysis, work product, or other derivatives, the architecture is designed to preserve relevant restrictions and provenance.

This prevents confidential or specially restricted material from being laundered into a less-protected derivative simply because an AI system transformed it.

Built for zero trust.

Network location does not establish trust. Identity, authorization, workload, resource, and policy are evaluated independently.

Identity
Enterprise SSO, federation, automated provisioning and deprovisioning, strong authentication, and short-lived service identities.
Authorization
Fine-grained, policy-driven access with explicit denial, matter-level controls, and least privilege.
Infrastructure
Hardened containerized workloads, restricted network communication, private service access, and segregated production environments.
Data
Encryption, isolation, retention controls, immutable storage where required, and customer-specific processing policies.
Operations
Controlled privileged access, separation of duties, security monitoring, incident response, vulnerability management, and auditable change control.
AI
Authorized retrieval, scoped agent permissions, provider governance, data-retention controls, and isolation of customer context.

Lines we hold, in writing.

Deposition consent, by jurisdiction.

Some states require one party's consent to record a conversation; some require everyone's. LITIGATER's live deposition features begin with a consent workflow, on the record, before anything runs. The feature doesn't start without it.

And the position we'll repeat anywhere it's printed: LITIGATER works beside your court reporter. The official transcript belongs to the reporter of record, and stays theirs.

Judge analytics, and the ethics question.

Is organizing a judge's record even allowed?

In the United States, yes. Dockets, filings, and rulings are public records, and understanding them is a long tradition; what a court does in public is the public's to understand. France chose differently and banned judicial analytics; the American tradition treats sunlight on public acts as the default. We think that's the right answer, and we built to it.

What Litigation Intelligence will not do: touch anything private, scrape anything from behind a login, or present a raw number as a prophecy. Everything is sourced to the public record and benchmarked against a baseline. Patterns, not verdicts about people.

Designed for independent scrutiny.

We expect sophisticated law firms to verify our claims. The security program is built around established frameworks.

Where additional contractual, regulatory, client, jurisdictional, or matter-specific requirements apply, policy overlays extend the baseline rather than forcing every matter into a single security profile.

  • AICPA Trust Services Criteria
  • SOC 2
  • NIST Cybersecurity Framework
  • NIST Zero Trust Architecture
  • NIST security and access-control guidance
  • GDPR privacy and processor requirements
  • Secure software-development practices
  • Legal confidentiality and professional-responsibility obligations

SOC 2 Type II: our controls are independently audited and attested against the AICPA Trust Services Criteria. The report is available under NDA on request.

GDPR: a data processing agreement with Standard Contractual Clauses governs data transfers, and EU hosting is available for firms that require in-region processing.

Subprocessors are named in the Data Processing Agreement. The full list, by category and region, is available in the security portal.

Subprocessors by category
CategoryVendors
Cloud infrastructureNamed in the security portal
Model providersNamed in the security portal
TranscriptionNamed in the security portal
EmailNamed in the security portal

What we disclose, and when.

Security disclosure at LITIGATER happens in three stages, widening as trust and diligence deepen.

Public websiteEveryone, no conditions.
  • Architecture principles
  • Security assurances
  • Control categories
  • Assurance posture
Security portalCustomers and prospective firms, under NDA.
  • Detailed diagrams
  • Data flows
  • Subprocessor list
  • Retention matrix
  • Penetration-test summary
  • SOC report
  • Disaster-recovery testing
  • Encryption and key architecture
  • AI-provider controls
  • Secure development lifecycle
  • Isolation methodology
Enterprise diligenceActive enterprise evaluations, under strengthened NDA.
  • Deeper implementation discussion with your security architect
  • Particular enforcement points
  • Cloud boundaries
  • Penetration-test scope
  • Controls evidence
  • Whatever your security group legitimately needs to validate

We disclose enough for your security team to evaluate LITIGATER, while withholding the implementation detail required to attack it.

Your security team does not have to take our word for it.

Qualified customers and prospective enterprise firms may request the security diligence package under appropriate confidentiality protections. Tell us what your review requires, and we will scope the disclosure to match.

Request security documentation

Powerful enough to understand the entire matter.

Disciplined enough to understand what it is not allowed to know.