Security and data handling
Your contracts never leave your control.
You are being asked to hand over executed documents. This is how that works, and it is the part we expect your legal and IT teams to test hardest.
How documents arrive
- Read-only ingestion from your DMS, CLM or a dedicated data room
- No forwarding to any third party
- Named individuals only, on an access list you control
Where they live
- Single-tenant storage in the region you nominate
- Encrypted in transit and at rest
- Every access logged against a named user
- Deletion on request, with written confirmation
- On exit, your record and contracts are deleted or exported to you, whichever you choose
What we never do
- Train models on your documents
- Pool your terms into a shared benchmark without written consent
- Share anything with another customer, counterparty or adviser
- Retain anything past the term
Before anything is ingested
- We sign your NDA and your data processing agreement, not ours
- Scope is agreed in writing, on a document set you pick
- Security pack, subprocessor list and certification status provided at scoping