ProofGuard AI
Legal · Security

DataSecurity.

Law firms and legal departments hold privileged and sensitive information. Security is designed into every ProofGuard build from the first scoping conversation, not added later.
LAST UPDATED SEPTEMBER 23, 2026

Our approach

Every engagement starts with three questions: where client data will live, who can reach it, and what the AI is allowed to see. The answers are written into the statement of work before development begins, in a form your IT lead, malpractice carrier and clients can review.

Architecture

  • Sandboxed AI. Sensitive processing runs in an isolated environment on the client’s hardware or a dedicated environment we provision.
  • Single tenant. Each client has its own environment and database. No shared databases and no data flow between clients.
  • Documented external processing. Where a commercial model or service is used for a task, what it receives and on what terms is documented in advance.

Technical controls

  • Encryption of data in transit and at rest.
  • Role based and matter level access control, with ethical walls for conflicted matters.
  • Multi factor authentication for administrative access.
  • Audit logging of user and AI actions.
  • Backups with tested restoration for hosted deployments.
  • Patching and vulnerability management for systems we manage.

Operational controls

  • Least privilege access for ProofGuard staff, removed when an assignment ends.
  • Confidentiality agreements for all staff and contractors with access to client systems.
  • Security awareness training for staff.
  • Incident response procedures with notification to affected clients as required by contract and law.

Data ownership and exit

Clients own their data. Matters, documents and logs can be exported in open formats at any time. Clients may own the code and infrastructure of a custom build outright, or have ProofGuard host and manage it.

Reporting a security concern

If you believe you have found a security vulnerability or incident affecting ProofGuard, please report it through our contact page and select Other. We review reports promptly.