Your data, protected
Security is not a feature — it is how we build. Every document, message, and analysis is encrypted at rest and in transit.
AES-256 encryption at rest and in transit
All user-generated content — documents, analyses, chat messages, clauses — is encrypted with AES-256 before it hits disk, under versioned keys with rotation support. TLS 1.2+ protects data in transit. Only non-content metadata, such as file names and timestamps, remains searchable in plaintext.
GDPR compliant, hosted in the EU
Attorly runs in Railway's EU-West region and your case data lives in our EU database; uploaded files are stored encrypted on Cloudflare R2. Where a processor operates from the US — Cloudflare and the AI model providers among them — transfers rely on Standard Contractual Clauses or the EU-US Data Privacy Framework, documented per processor in our subprocessor register. We provide data processing agreements, honor right-to-erasure requests, and support full data portability.
SOC 2 Type II readiness
Infrastructure and processes designed to meet SOC 2 Type II criteria. Continuous monitoring, access controls, and change management — with third-party audit on the roadmap.
SSO with SAML 2.0
Centralize access management with enterprise single sign-on. SAML 2.0 integration with your identity provider — Okta, Azure AD, Google Workspace, and others.
Complete audit trail
Every action is logged: who did what, when, on which document. Immutable records for compliance reviews, internal investigations, and regulatory reporting.
Where your data lives
Attorly runs on EU servers in Railway's EU-West region, and your case data lives in our EU database. Uploaded files are encrypted on our servers before they are stored on Cloudflare R2, which does not guarantee they stay in the EU. AI analysis is processed by US-based model providers under EU standard contractual clauses — see the AI providers section below. Enterprise customers can bring their own storage bucket and encryption keys to keep files in a region of their choice.
How AI providers handle your data
Attorly uses frontier AI models for analysis, drafting, and research. This is exactly what leaves our infrastructure, and on which terms: requests are routed through our EU-hosted gateway (or directly to the same providers if it is unreachable), providers receive only the text needed for that request, and provider-side retention is limited to short-term abuse monitoring under the API terms linked below.
| Provider | Purpose | Location | Data terms |
|---|---|---|---|
| GetPlatform AI Gateway | Request routing and usage metering — our own service, the first hop for AI requests; if it is unreachable, requests go directly to the same providers | EU (Netherlands) | View data terms |
| Anthropic (Claude) | Primary model for legal analysis, drafting, and research | United States | View data terms |
| OpenAI | Fallback model and document embeddings | United States | View data terms |
| Google (Gemini API) | Legal-corpus embeddings and fallback model | Global (Google Cloud) | View data terms |
| Mistral AI | Document OCR; optional EU-only analysis with your own key or self-hosted deployment | EU (France) | View data terms |
| Voyage AI | Legal-tuned embeddings — opt-in, bring-your-own-key only | United States | View data terms |
Never used for training
Your content is never used to train AI models — not by us, and not by our providers. Every provider is used under API terms that exclude training on customer data.
Only what the request needs
Providers receive the prompt and the document excerpts required for that specific request — never your document store. Your documents stay encrypted in our own storage, not with AI providers.
Your keys, your models
Bring your own model key, or run analysis on a self-hosted EU-only deployment. Enterprise plans also support bring-your-own encryption keys (BYOK).
Full transparency
Every third party that touches your data is listed in our public subprocessor register, with its location, transfer mechanism, and data processing agreement.
Legal data sources
Attorly's legal research is built on official public-sector publications. Every legal text shown in the product names its publisher and the terms we reuse it under, as those terms require. This is the complete list.
| Publisher | What we use | Terms | Required notice |
|---|---|---|---|
| Lovdata | Norwegian laws and central regulations in forceStored in our research corpus | NLOD 2.0 | Inneholder data under Norsk lisens for offentlige data (NLOD) tilgjengeliggjort av Lovdata |
| Stortinget | Norwegian parliamentary committee recommendations (innstillinger) on billsStored in our research corpus | NLOD 2.0 | Kilde: Stortinget |
| Sveriges riksdag | Swedish statutes (SFS) and government bills (propositioner)Stored in our research corpus | terms of use | Källa: Sveriges riksdag |
| Sveriges Domstolar | Swedish precedent decisions from all courtsStored in our research corpus | CC0 1.0 | None prescribed |
| Retsinformation | Danish statutes and regulations, bills (lovforslag) and committee reports (betænkninger)Stored in our research corpus | ophavsretsloven § 9 | None prescribed |
| Gesetze im Internet | German federal statutes and regulationsStored in our research corpus | UrhG § 5 | None prescribed |
| Rechtsprechung im Internet | Decisions of the German Federal Court of Justice (civil senates), Federal Labour Court and Federal Constitutional Court, with their official headnotesStored in our research corpus | terms of use | None prescribed |
| EUR-Lex | EU regulations and directives in force, and judgments of the Court of Justice of the European UnionStored in our research corpus | Decision 2011/833/EU | None prescribed |
| Finlex | Finnish legislationSearched live at query time, not stored | tekijänoikeuslaki 9 § | None prescribed |
| legislation.gov.uk | UK legislationSearched live at query time, not stored | OGL v3.0 | Contains public sector information licensed under the Open Government Licence v3.0. |
| Congress.gov | US federal bills and statutesSearched live at query time, not stored | 17 U.S.C. § 105 | None prescribed |
| CourtListener | US court opinionsSearched live at query time, not stored | terms of use | None prescribed |
| SEC EDGAR | US company filingsSearched live at query time, not stored | terms of use | None prescribed |
Official texts such as statutes and court decisions are outside copyright in the jurisdictions whose texts we store (åndsverkloven § 14, upphovsrättslagen 1 kap. 9 §, ophavsretsloven § 9, UrhG § 5), and EU documents are reused under Commission Decision 2011/833/EU. We take them only from the publishers' own open-data channels and never extract from privately compiled databases.
The research corpus contains no user data and is therefore not encrypted at rest. Its texts are sent to our embedding provider to build the search index, and excerpts are sent to the answering model when they ground a request.
The publishers listed here do not endorse Attorly, and Attorly is not a service of any of them.
How long we keep your data
These are the periods in our data processing agreement. A daily job deletes audit logs after two years and discarded playbook imports after 30 days; documents and analyses are deleted when you delete them or your account, within the periods below.
| Data | Kept for |
|---|---|
| Account data | While the account is active |
| Documents | Until you delete them, or 30 days after account deletion |
| Analyses | 90 days after the document is deleted |
| Audit logs | Two years |
| Discarded playbook imports | 30 days after the last change |
Security questionnaires
Send your security questionnaire or vendor assessment to security@attorly.ai. Attorly is not SOC 2 or ISO 27001 certified; our answers say so and describe the controls in place.
Email security@attorly.aiSecurity built for legal work
Read our security documentation or talk to our team about your requirements.
Start your trial