TRUST & SECURITY

Your Data, Protected

How we secure your research and protect your information

SOC 2

Type II Certified

ISO 27001

Certified

256-bit

AES Encryption

Zero

Data Sold

Our AI Provider

🤖

Powered by Claude (Anthropic)

LawCite uses Claude, developed by Anthropic, for AI-powered legal analysis. Anthropic is an AI safety company committed to building reliable, interpretable, and steerable AI systems.

SOC 2 Type II

Audited security controls

ISO 27001

Information security management

ISO 42001

AI management systems

HIPAA Configurable

Healthcare data options

View Anthropic Trust Center

How Your Data is Handled

What We Store

Your account information (email, agency, preferences)
Search history (scenarios and results)
Pinned cases for quick reference
Subscription and billing records

What We Don't Store

Your password (handled by Auth0)
Payment card numbers (handled by Stripe)
Raw AI conversation logs
Personal case files or evidence

Your Scenarios Are Not Used to Train AI

LawCite uses Anthropic's API with data handling agreements that prevent your scenarios from being used to train or improve AI models. Your legal research remains private and is not incorporated into any machine learning datasets.

Infrastructure Security

Railway

Backend & Database

SOC 2 Type II
Encrypted at rest
Automated backups

Vercel

Frontend Hosting

SOC 2 Type II
Edge network
DDoS protection

Auth0

Authentication

SOC 2 Type II
MFA support
Secure sessions

Stripe

Payments

PCI DSS Level 1
Tokenized cards
Fraud detection

Encryption Standards

Data in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3, the latest transport layer security protocol.

TLS 1.3HTTPS Only

Data at Rest

All stored data is encrypted using AES-256 encryption. Database backups are also encrypted and stored securely.

AES-256Encrypted Backups

Session Security

Session Duration

16 hours

Designed for long shifts

Token Refresh

Every 45 min

Automatic, silent refresh

Secure Cookies

HttpOnly + Encrypted

Protected from XSS attacks

Your Security Controls

Delete search history

Remove individual searches or clear all history anytime

Export your data

Download your search history in PDF or Word format

Deactivate account

Temporarily disable your account (reversible)

Delete account

Permanently delete all your data from our systems

Log out remotely

End your session from any device

Security Incident Response

In the unlikely event of a security incident affecting your data, we commit to:

→Notify affected users within 72 hours of discovery
→Provide clear information about what data was affected
→Take immediate steps to contain and remediate the issue
→Conduct a thorough investigation and share findings

Security Questions?

Our team is here to answer any security or privacy concerns.

Contact Security Team