Skip to content

Security & Data Controls

Control is part of the architecture.

CouncilGPT is being built for legal teams that cannot treat confidentiality, access and auditability as optional features. This page describes how the product is designed and where our assurance program stands today.

Five controls

Built into how work is executed, not added afterwards.

Matter isolation

Keep matter context and work product separated according to authorized access.

  • The matter is the boundary for documents, work product, plans, approvals and activity.
  • Access is checked on the server for every request — membership of the matter team is required.
  • Ethical walls screen named people from a matter, and denied access attempts are recorded.

Role & policy controls

Define who may see a matter and what Lisa may do with its information.

  • Roles such as partner, associate, paralegal and knowledge carry different permissions.
  • Firm policy classifies actions by consequence: read and analyze, draft internally, finalize, and external or irreversible.
  • Policy is enforced by the application, not by instructions in a prompt.

Model governance

Route requests only through approved model providers and data-handling configurations.

  • Lawyers do not pick models. CouncilGPT routes work to capabilities the firm has approved.
  • Provider selection and data-handling configuration are set at deployment, per firm.
  • Firms can require providers and configurations that exclude client data from model training.

Human checkpoints

Require named approval before consequential external or irreversible actions.

  • Each checkpoint shows what will happen, to whom, which conclusions it relies on and whether it can be undone.
  • Approvals are attributed to a named lawyer and recorded with the version of the work product approved.
  • Returning work to Lisa sends nothing and keeps the draft in the matter.

Auditable activity

Record material system actions, source use, work-product versions and approvals.

  • Material events are written to an append-only log that clients cannot edit or delete.
  • Each event is hash-chained to the one before it, so later alteration is detectable.
  • The matter record is designed to be exported for internal review, insurers or regulators.

Assurance status

We do not display certification badges until an audit is complete and a report can be shared. Current status:

SOC 2
In preparation
ISO/IEC 27001
Planned
Data processing agreement
On request for evaluations

Privacy & data handling

Client documents and work product stay inside the matter they belong to. Retention periods, regional processing and deletion are configured per firm as part of deployment.

Deployments are designed to serve legal teams in the United States and India, with region-aware data and policy controls.

Subprocessors

The subprocessors used in a deployment — including model providers and hosting — are listed in the data processing documentation provided during evaluation.

Data processing

A data processing agreement is available on request for evaluation and pilots. Contact us through the demo request form and note that you need it.

Responsible AI

CouncilGPT is software for legal professionals. AI-generated output may contain errors and requires appropriate professional review. CouncilGPT does not provide legal advice.

The product is designed to make review practical: sources are labeled by type, quoted language is checked against the cited document, model inference is marked as inference, and consequential actions wait for a named lawyer.

Security review in progress at your firm? We will walk your team through the controls on a live matter.

Talk to our team