Skip to trust center

Security & Trust

Security controls, privacy terms, and service providers.

Reviewed September 13, 2026

Security overview

Security controls

“Configured” reflects reviewed code and infrastructure settings, not an independent audit of the live service.

Access & identity

Workspace boundaries Configured
Firm + Ask

Firm storage enforces workspace paths; Ask document access is scoped to the signed-in account.

Protected sign-in cookies Configured
Firm + Ask

Sign-in cookies use Secure and HttpOnly protections.

Session revocation Configured
Firm

Firm requests reject disabled users and revoked sessions.

Two-step verification Product dependent
Firm + Ask

TOTP two-step verification is available for Ask accounts (optional; you turn it on). Firm admins can enable it per workspace. It is not required by default.

Data protection

Encrypted document storage Configured
Firm + Ask

Document storage uses AWS KMS encryption and blocks public access.

Encrypted connections Configured
Firm + Ask

Document storage requires HTTPS; application websites redirect to HTTPS.

AI processing & retention Product dependent
Firm + Ask

Ask retains raw model request and response logs for 180 days. Requests from every signed-in Ask account (Free, Pro, and Max) route only to no-training AI providers; guest requests made without signing in use a cost-optimized route whose providers may retain prompts and use them for training. Firm processing and contractual terms differ.

Formal data-handling policy Not established
Organization

No formal internal data-handling policy established. Published privacy terms apply.

Backup & recovery

Database recovery safeguards Configured
Firm + Ask

Core application tables have point-in-time recovery and deletion protection. No recovery-time commitment.

Recovery exercises Not assessed
Organization

No published recovery-test results or validated recovery times.

Business continuity plan Not established
Organization

No formal business continuity or disaster recovery plan established.

Email security

Authentication email controls Configured
Authentication email

Ask authentication email configures DKIM, SPF, and DMARC reporting in infrastructure code. Firm authentication-email DNS is managed outside this repository and was not verified in this review.

Company mail protection Not assessed
Organization

Company-wide email filtering and mailbox protections have not been verified.

Device security

Employee device protections Not assessed
Organization

Employee device encryption, anti-malware, and device management have not been assessed.

Infrastructure

Private document buckets Configured
Firm + Ask

Document buckets block public access; application checks govern file access.

Defined cloud permissions Configured
AWS services

Cloud service permissions are defined in infrastructure code. A complete least-privilege review is not established.

Versioned infrastructure Configured
Platform

Most cloud resources are defined in version-controlled infrastructure code; some DNS and email settings are managed separately.

Browser security headers Configured
Marketing website

The marketing site configures a content security policy and HTTPS security headers.

Monitoring & incidents

Operational logging Configured
Firm + Ask

Operational logging and cloud monitoring are configured. Ask logs include model content.

Firm audit records Configured
Firm

Firm audit records use immutable storage with a separate retention period.

Incident response plan Not established
Organization

No formal incident response plan established. Reports use the contact form; no emergency response time is promised.

Organizational practices

Published product terms Published
Firm + Ask

Published privacy terms and product addenda define applicable commitments.

Internal security policies Not established
Organization

No formal internal information-security or access-control policies established.

Personnel security program Not assessed
Organization

Employee training, access-review schedules, and signed policy records have not been assessed.

Risk & vendors

Service-provider visibility Published
Firm + Ask

Key integrations are listed below. Active downstream AI hosts require further verification.

Formal risk program Not established
Organization

No documented risk-management or vendor-review program established.

Vulnerability management

Independent penetration test Not completed
Platform

No independent penetration-test report available.

Security reporting Available
Platform

Security reports use the contact form. Submit a non-sensitive summary first.

Remediation timelines Not established
Organization

No published remediation schedule or bug-bounty program.

Published terms and the status of internal policies and reports.

Formal assurance documents

Internal policies and independent reports are not yet available.

  • Information security policyNot established
  • Access-control policyNot established
  • Incident response planNot established
  • Independent penetration-test reportNot completed
  • SOC 2 / ISO audit reportsNot started
Ask about status

Frequently asked questions

Ask another question
Is Jurisio SOC 2 or ISO certified?

No. Jurisio plans to pursue a SOC 2 audit but has not started one, and is not ISO 27001 certified. Technical safeguards described here are separate from independent certification. See Compliance status.

Is my data encrypted?

Document storage is configured with AWS KMS encryption at rest and HTTPS in transit. Jurisio’s application services can read content to deliver document and AI features. This is not end-to-end encryption.

Can I upload confidential client documents to Ask?

Ask is governed by the Privacy Policy and Terms of Service, not a separate product addendum. Submitting information to Ask does not create attorney-client privilege. As a guest (without signing in), do not submit material you are not permitted to disclose to AI providers whose policies may permit retention or training; every signed-in account (Free, Pro, and Max) routes requests only to providers that have committed not to train on submitted content. Firm workspace terms are different. Review the Terms of Service before uploading sensitive material.

Is my content used to train AI?

Jurisio itself never trains on your data. For Ask, requests from every signed-in account (Free, Pro, and Max) are routed only to providers that have committed not to train on submitted content. Guest requests made without signing in use a cost-optimized route whose providers may retain prompts and outputs and, under their own terms, use them to train or improve their models or products. Firm workspace processing is governed by the organization's written agreement. See Privacy Policy §4.

Does Jurisio offer zero data retention?

Not across the service. Workspace content and operational records are retained. Ask is configured to log AI requests and responses, with a 180-day model-log lifecycle. AI-provider retention is a separate question and depends on the service and configuration; no-training routing for signed-in accounts is not a zero-retention commitment, and the guest route is not zero-retention.

What happens when I delete a document?

Deleting a workspace document does not immediately erase every related backup, log, or audit record. Retention varies by record type. Ask keeps documents until you delete them, and deletion erases them; separate raw AI model logs have a 180-day lifecycle, and Firm audit records use immutable storage with multi-year retention (six to seven years depending on record type). Contact us about your specific deletion request.

Where is information processed?

Core infrastructure is configured in AWS US regions. AI requests and other features may involve external service providers. This page does not guarantee that all data processing stays in the United States or within AWS.

Do you support HIPAA or a business associate agreement?

Firm customers can request a Business Associate Agreement (BAA) with Jurisio; HIPAA commitments apply only under a signed BAA. Ask is not offered for HIPAA-regulated use; don't upload protected health information to Ask.

How can I review security documentation?

Public privacy terms and product addenda are linked in Documents. Formal internal security policies and independent test reports are not yet available. You can request information about a specific safeguard or a prospective firm review.

How do I report a vulnerability?

Use Report a concern to open our existing contact form with a security-report topic. Include a non-sensitive description of the affected feature. Do not send credentials, confidential documents, or an exploit containing customer data. We do not promise an emergency response time or operate a published bounty program.

The Privacy Policy, Terms of Service, and applicable written agreements govern product commitments.

Service providers

Key external services identified in the code. Use varies by product and configuration; this is not a complete, contract-verified subprocessor register.

Amazon Web Services

Firm + Ask
Used for

Cloud infrastructure. Storage, databases, compute, authentication email, and model processing through Amazon Bedrock where configured.

Information involved

Documents, account records, application content, and operational data relevant to the service.

Privacy

OpenRouter & routed model providers

Ask only
Used for

AI processing. Routes model requests to downstream providers. The active provider can vary by workflow, model, and configuration.

Information involved

Prompts, relevant document context, and model responses; for guest requests, providers may also receive a pseudonymous session identifier. A complete active downstream-host register is not yet verified.

Privacy

Tavily

Ask
Used for

Web research. Searches the web and extracts web-page content for research workflows.

Information involved

Search queries and requested URLs; the query may include context generated from a user request.

Privacy

Stripe

Paid subscriptions
Used for

Payments. Handles payment and subscription workflows.

Information involved

Billing details, account references, and subscription/payment records required for those workflows.

Privacy

PostHog

Ask · when enabled
Used for

Product analytics. Measures a defined set of product-use events. Session recording is disabled in the reviewed configuration.

Information involved

Allowlisted usage properties plus request-level technical data described in the Cookie Policy, including an IP-derived daily identifier and approximate location; no question text, document contents, filenames, email, or account identifiers.

Privacy

Google

Where used
Used for

Sign-in, website fonts & Drive import. Google sign-in supports account access. Some public pages also request Google-hosted fonts. If you connect Google Drive, Jurisio imports only the files you pick and follows Google's API Services User Data Policy for that data.

Information involved

Sign-in profile information where authorized; browser connection information when loading fonts. Connected-file data and authorization tokens when Google Drive is connected.

Privacy

Microsoft

Ask · when connected
Used for

OneDrive import. Only used when you connect Microsoft OneDrive to import files into your Ask account.

Information involved

Connected-file data and authorization tokens for the files you choose to import.

Privacy

Dropbox

Ask · when connected
Used for

File import. Only used when you connect Dropbox to import files into your Ask account.

Information involved

Connected-file data and authorization tokens for the files you choose to import.

Privacy

Box

Ask · when connected
Used for

File import. Only used when you connect Box to import files into your Ask account.

Information involved

Connected-file data and authorization tokens for the files you choose to import.

Privacy
Provider inquiries

Request the provider list and processing terms applicable to your workflow.

Request provider details