Legal

Security

Built for privileged work product.

Last Updated: May 26, 2026

LawDiem treats every document as if a protective order applies to it. This page describes the architectural, operational, and contractual safeguards we have put in place — and, just as importantly, the residual risks every practicing lawyer must understand before entrusting client material to any cloud service. It is written for an audience of licensed attorneys who carry duties of confidentiality, technological competence, and supervisory responsibility under the ABA Model Rules of Professional Conduct (and the corresponding state-bar rules).

Architecture at a Glance

Hosted on AWS, isolated by tenant, sequestered from the public internet.

  • Single cloud, single jurisdiction by default. All Customer Data is hosted in Amazon Web Services regions located within the United States. No Customer Data is copied to any third-party AI vendor, analytics platform, or “external” data store. AI inference runs inside the same AWS environment that holds your data.
  • Per-tenant logical isolation. Each Customer (each firm) is provisioned with a dedicated tenant. Multi-tenant isolation is enforced at the data layer — every query is firm-scoped, and the application cannot return data outside the firm whose user is authenticated.
  • Virtual Private Cloud (VPC). Production workloads run inside an AWS VPC with private subnets, no public ingress except through hardened, rate-limited, authenticated edges, and outbound traffic restricted to a vetted allow-list of endpoints.
  • No external data storage. Customer Data is not stored, cached, or mirrored to any service outside the LawDiem AWS environment. We do not use third-party generative-AI services that retain prompts or outputs, log content for training, or share content across customers.

Encryption

  • Encryption at rest using AES-256, with per-tenant Customer-scoped encryption keys held in AWS Key Management Service (KMS). Keys are rotated on a defined schedule and are revocable.
  • Encryption in transit using TLS 1.3 for all client-to-service and service-to-service traffic. Internal service-to-service traffic within the VPC is also encrypted.
  • Secrets management through AWS Secrets Manager (or equivalent), with no production credentials checked into source control and no shared developer access to live secrets.

Sequestered AI Inference

Generative-AI features (such as SpotlightAuthority, Rebuttal, and the analysis features inside DiscoveryBridge) run on inference infrastructure inside the LawDiem AWS environment, scoped to your tenant. Specifically:

  • Prompts and outputs are not retained outside your tenant. Inference requests are processed and the working memory is released; we do not log the substantive content of prompts or outputs to a shared store.
  • No training on your data. Customer Data is never used to train, fine-tune, evaluate, or otherwise improve any AI or machine-learning model — whether ours, our sub-processors’, or any third party’s — outside the confines of your dedicated tenant. This is a contractual commitment in our Privacy Policy and is enforced architecturally.
  • No cross-customer leakage. Models do not “remember” content across requests, and there is no shared cache, vector store, or context window that spans tenants.
  • No “self-learning” tools on Customer Data. Consistent with ABA Formal Opinion 512 (July 29, 2024), LawDiem does not use self-learning AI tools that ingest one Customer’s information for the benefit of another.

Access Control and Authentication

  • Single sign-on (SSO) via standard SAML / OIDC identity providers for enterprise tenants.
  • Multi-factor authentication (MFA) is supported, and required for administrative actions.
  • Role-based access control at the firm, matter, and feature level. Customer administrators can scope what each Authorized User sees and can build ethical-wall configurations to support conflicts and screening obligations.
  • Just-in-time, audited support access. LawDiem personnel do not have standing access to Customer Data. Any support access to a Customer tenant requires (a) a documented Customer request, (b) time-boxed credentials, and (c) an entry in the append-only audit log visible to the Customer.

Audit Logging

  • Append-only audit logs record every meaningful action: every document access, every export, every analysis call, every administrative change, every authentication event, every support-access session.
  • Logs are scoped to the Customer’s tenant and are available to Customer administrators.
  • Logs are retained for a period appropriate to support incident response and forensic review, and are themselves stored with encryption and access controls.

Operational Safeguards

  • Least-privilege engineering. Production access is limited to a small, on-call engineering rotation, with hardware-backed MFA, time-boxed permissions, and full audit trails.
  • Code review and change control. Production changes pass through code review, automated testing, and staged deployment.
  • Vulnerability management. Dependency monitoring, automated scanning, and a defined process for triaging and patching vulnerabilities on a risk-weighted schedule.
  • Backups and recovery. Customer Data is backed up on a defined schedule using encrypted, region-redundant storage, with documented recovery objectives.
  • Sub-processor diligence. Every sub-processor is reviewed for security posture and bound by written terms compatible with our obligations to you and yours to your clients. See the sub-processor list in the Privacy Policy.
  • Endpoint and personnel security. Employees and contractors with production access are subject to background checks (where permitted by law), confidentiality obligations, security training, and centrally managed endpoints.

How Our Posture Maps to Your ABA Duties

Our security and confidentiality controls are designed to make it reasonable for a careful lawyer to entrust Customer Data to LawDiem, consistent with:

  • Model Rule 1.6 (confidentiality of information) — see especially Rule 1.6(c) (reasonable efforts to prevent inadvertent or unauthorized disclosure) and Comment 18 (factors to consider when safeguarding client information).
  • Model Rule 1.1 cmt. 8 (technological competence) — the 2012 amendment requiring lawyers to keep abreast of “the benefits and risks associated with relevant technology.”
  • Model Rule 5.3 cmt. 3 (nonlawyer assistance outside the firm) — addressing the supervisory duty owed when a lawyer uses internet-based document storage and similar third-party services. Customer administrators have the tools (audit logs, role-based access, exportable data, written commitments in these Terms and the Privacy Policy) needed to fulfill that supervisory duty.
  • ABA Formal Opinion 512 (Generative AI Tools, July 29, 2024) — competence, confidentiality, communication with clients, supervision, candor, and reasonable fees when using generative AI.

These mappings describe what we have built. They are not legal advice and do not discharge your duties. Whether the safeguards are sufficient for a particular matter, a particular client, or a particular jurisdiction is a professional judgment you must make.

Honest Disclosures About Residual Risk

Every responsible security page must end with this section. Pretending otherwise would itself be a security failure.

  • No system is invulnerable. All modern software systems are subject to evolving cyber-threats — zero-day vulnerabilities in widely used components, supply-chain compromises of upstream dependencies, social-engineering attacks against employees and Customers, insider threats, and well-resourced nation-state actors. LawDiem implements the safeguards described above, but no vendor — not LawDiem and not any provider in the market — can warrant invulnerability to attack.
  • AI-assisted programming has changed the threat landscape. The same generative-AI capabilities that make modern software more productive have materially accelerated the rate at which adversaries can read source and binary code, identify weaknesses, generate working exploits, and locate undocumented or backdoor access paths in production systems. Defending against this newer class of attack is meaningfully harder than it was even a few years ago. We are investing accordingly — and so should every law firm with respect to its own endpoints, identity systems, and email infrastructure.
  • Every data transfer carries irreducible risk. Sending data across the internet, between client devices and cloud services, between cloud services and counterparties (including opposing counsel and clients), and across third-party integrations involves an irreducible risk of interception, misdirection, corruption, loss, or unauthorized disclosure. Encryption reduces, but does not eliminate, this risk.
  • AI outputs are probabilistic. Generative-AI features may produce inaccurate, incomplete, biased, or fabricated content — including invented citations, mischaracterized holdings, and omitted material facts. Every AI-generated output must be independently verified by a competent attorney before it is filed, served, sent, billed, or relied upon. See ABA Formal Op. 512.
  • Inadvertent disclosure remains possible. Notwithstanding our safeguards, inadvertent disclosure of confidential, sensitive, or privileged information can occur — by misconfiguration, user error, opposing-counsel error, third-party compromise, court order, or otherwise. Under our Terms of Service, you agree to hold LawDiem harmless for any such inadvertent disclosure except to the extent it is caused by LawDiem’s gross negligence or willful misconduct.
  • You are the lawyer; you bear ultimate responsibility. Under Rule 1.6 the duty of confidentiality runs from you to your client. Under Rule 5.3 the supervisory duty over outside services is yours. Under Rule 1.1, Comment 8 and Formal Op. 512 the duty of technological competence is yours. LawDiem provides a tool. The professional judgment, the supervision, and the accountability remain with you. By using the Services, you accept this allocation of responsibility.

Responsible Disclosure

If you believe you have found a security vulnerability in the Services, please report it to notice@lawdiem.com. We ask researchers to (a) avoid privacy violations, data destruction, and service disruption while investigating; (b) give us a reasonable opportunity to remediate before disclosing publicly; and (c) act in good faith. We will respond promptly, investigate, remediate validated reports, and credit researchers who request it.

Security Incident Notification

If we become aware of a security incident that has resulted in, or that we reasonably believe has resulted in, unauthorized access to your Customer Data, we will notify you without undue delay and consistent with applicable law and any commitments in your subscription agreement. The notification will describe what we know about the incident, the categories of data affected, the steps we are taking, and steps you may wish to take. As the data controller for purposes of your professional and ethical obligations, you remain responsible for any client, court, regulatory, or bar notifications that may be required.

Questions


© 2026 LawDiem Inc. All rights reserved.