Is Jurisio SOC 2 or ISO certified?
Not yet. Jurisio has implemented SOC 2 Security-criteria controls and is preparing for an independent SOC 2 Type I audit (SOC 2 Type I — in progress), but no auditor has issued a SOC 2 report. Jurisio is not ISO 27001 certified. Technical safeguards described here are separate from independent certification. See Compliance status.
Is my data encrypted?
Document storage is configured with AWS KMS encryption at rest and HTTPS in transit. Jurisio’s application services can read content to deliver document and AI features. This is not end-to-end encryption.
Can I upload confidential client documents to Ask?
Ask is governed by the Privacy Policy and Terms of Service, not a separate product addendum. Submitting information to Ask does not create attorney-client privilege. As a guest (without signing in), do not submit material you are not permitted to disclose to AI providers whose policies may permit retention or training; every signed-in account (Free, Pro, and Max) routes requests only to providers that have committed not to train on submitted content. Firm workspace terms are different. Review the Terms of Service before uploading sensitive material.
Is my content used to train AI?
Jurisio itself never trains on your data. For Ask, requests from every signed-in account (Free, Pro, and Max) are routed only to providers that have committed not to train on submitted content. Guest requests made without signing in use a cost-optimized route whose providers may retain prompts and outputs and, under their own terms, use them to train or improve their models or products. Firm workspace processing is governed by the organization's written agreement. See Privacy Policy §4.
Does Jurisio offer zero data retention?
For signed-in accounts, yes, with AI providers: Jurisio sends requests only to AI providers that have committed to keep no data. Three limits apply. Guest requests made without signing in use a route that is not zero-retention. Jurisio itself keeps AI request and response logs for 180 days for quality and safety review. Documents and conversations you save stay in your account until you delete them. Separately, web searches send the search query, after a privacy check, to search providers, which are search services rather than AI model providers.
What happens when I delete a document?
Deleting a workspace document does not immediately erase every related backup, log, or audit record. Retention varies by record type. Ask keeps documents until you delete them. When you delete one, its stored files are deleted right away and its database record expires within a few days; copies in database point-in-time recovery age out within 35 days; separate raw AI model logs have a 180-day lifecycle; and Firm audit records use immutable storage with multi-year retention (six to seven years depending on record type). Contact us about your specific deletion request.
Where is information processed?
Core infrastructure is configured in AWS US regions. AI requests and other features may involve external service providers. This page does not guarantee that all data processing stays in the United States or within AWS.
Do you support HIPAA or a business associate agreement?
Firm customers can request a Business Associate Agreement (BAA) with Jurisio; HIPAA commitments apply only under a signed BAA. Ask is not offered for HIPAA-regulated use; don't upload protected health information to Ask.
How can I review security documentation?
Public privacy terms and product addenda are linked in Documents. Formal internal security policies and independent test reports are not yet available. You can request information about a specific safeguard or a prospective firm review.
How do I report a vulnerability?
Use Report a concern to open our existing contact form with a security-report topic. Include a non-sensitive description of the affected feature. Do not send credentials, confidential documents, or an exploit containing customer data. We do not promise an emergency response time or operate a published bounty program.