Built to protect confidential documents
CounselDraft.ai handles legal documents and the personal information of your clients, buyers, and sellers. Security isn’t a feature we bolted on — it’s how the platform is built, from the database layer up.
Encryption everywhere
Documents and data are encrypted at rest with AES-256 and protected in transit with TLS 1.2+ and modern cipher suites.
Per-account isolation
Access is enforced at the database layer with row-level security — your documents are walled off to your authenticated account, not merely by application code.
Your data never trains AI
Content sent to AI features is used only to generate your response. Our AI provider, Anthropic, is contractually restricted from training its models on it.
Trusted infrastructure
Built on cloud infrastructure independently certified to SOC 2 Type II and ISO 27001 — AWS, Vercel, Supabase, Cloudflare, and Stripe.
Encryption
All document content and account data is encrypted at rest using AES-256 and protected in transit using TLS 1.2+ with modern cipher suites. Encrypted backups are retained for disaster recovery and purged on a rolling schedule.
Access control & isolation
Access is enforced at the database layer using row-level security. Every record is scoped to its owner, so your documents are isolated to your authenticated account at the infrastructure layer — not merely by application code. Row-level security provides an independent layer of defense beneath the application code.
Uploaded files are stored in private storage and served only through short-lived, signed URLs generated after an ownership check — files are never publicly addressable.
AI & confidentiality
AI-assisted drafting is powered exclusively by Anthropic’s Claude models, and sends your content to Anthropic solely to generate a response. We do not authorize Anthropic to train its models on your content, and its commercial API terms restrict such use. Your documents are never used to train AI models.
If you are a licensed attorney, you remain responsible for ensuring your use of AI features complies with your jurisdiction’s professional-responsibility rules on client confidentiality.
Infrastructure & compliance
CounselDraft.ai runs on cloud infrastructure that is independently certified to SOC 2 Type II and ISO/IEC 27001 — including Amazon Web Services, Vercel, Supabase, Cloudflare, and Stripe. These certifications belong to our infrastructure providers; CounselDraft inherits the protections of that certified infrastructure.
Subprocessors
We rely on a small set of vetted service providers (subprocessors) to operate the platform — for hosting, database/storage, payments, e-signature, and AI features. Each is listed, with its purpose and privacy policy, in our Privacy Policy.
Account security
We support strong, unique passwords and OAuth sign-in. We strongly recommend using a unique password for your account. Multi-factor authentication (MFA) is available — enable an authenticator app in Settings for a one-time code at sign-in.
Data retention & deletion
We retain your data while your account is active. On account deletion, your information and documents are permanently deleted within 30 days (except where retention is legally required); residual copies in encrypted backups are purged within 90 days. You may request an export of your data at any time.
Responsible disclosure
If you believe you’ve found a security vulnerability, please report it to support@counseldraft.ai. We investigate every report and appreciate coordinated disclosure.
This page describes our current security practices and is provided for informational purposes; it is not a contractual commitment or warranty. For our full data-handling terms, see the Privacy Policy.