Security & privacy commitments
You hold privileged material. Your duty of confidentiality doesn't bend for software vendors — so the software has to meet the duty. These are the measures we take, stated concretely enough to be checked.

Encryption everywhere
All traffic is TLS-encrypted; all data is encrypted at rest. Case documents and dictation audio live in private storage buckets that are unreachable without authentication — downloads happen only through short-lived signed links that expire in minutes.
Isolation enforced by the database itself
Your firm's records are separated with row-level security: rules enforced by the database engine on every single query, not just by application code. We attack-test this — a hostile account in another firm sees zero rows and cannot forge writes into yours. And when you join us, your firm's data lives in its own dedicated database instance, not a shared pool.
Your cases never train an AI
Transcription and drafting run through commercial AI services under contractual no-training terms. Your dictations, transcripts, and case files are processed to serve your request and are not used to train models — ours or anyone else's.
Consent-gated client contact
Automated calls and emails require per-client consent flags, checked when an update is queued and re-checked at the moment of sending. A client who hasn't consented to a channel simply cannot be contacted on it.
An audit log that can't be edited
Every material action — access, filing, approval, delivery — is written to an append-only audit log. Database permissions physically prevent updating or deleting entries, including by us.
You stay the decision-maker
The professional-responsibility buck stops with the attorney, so the software is built around attorney checkpoints: AI output is always a proposal, delivery always passes an approval gate, and every applied item traces back to its source dictation.
Questions we invite you to ask
Ask us — and ask every vendor you evaluate: Where exactly is my data stored, and who can query it? Do your AI providers train on my content? What happens at the database layer if another customer's account is compromised? Can your own staff silently edit the audit trail? We'll answer in writing at security@counselrelay.com.
Wondering what your state bar says about using AI at all? See the 50-state guide →