Security Overview
Encryption, data residency, tenant isolation, AI-specific controls, certifications and incident response — the detail your security team will ask for.
Last updated: 1 September 2026 · Effective: 1 September 2026
1. Our security posture
JuriPro processes documents that are frequently privileged, commercially sensitive, or both. Our security programme is designed around a simple assumption: a customer should be able to satisfy their own professional and regulatory obligations while using our platform, without having to take our word for anything.
We hold ISO/IEC 27001:2022 certification for our information security management system and undergo an annual SOC 2 Type II examination. Current reports are available under NDA from [email protected].
2. Encryption and key management
All data in transit is encrypted using TLS 1.3, with TLS 1.2 supported only for legacy integrations on request. HSTS is enforced with preloading. All data at rest is encrypted using AES-256.
Encryption keys are managed in a hardware security module in the customer’s elected region and rotated annually. Enterprise customers may bring their own keys, in which case revoking the key renders the data unreadable to JuriPro immediately.
3. Data residency and isolation
Customers elect a data residency region at signup: the European Union (Frankfurt and Paris) or the United States (Northern Virginia and Oregon). Customer content, derived artefacts, backups and support access all remain within the elected region. Cross-region access does not occur without the customer’s written approval.
Each customer’s data is logically isolated at the storage, index and application layers, with tenant identity enforced at every data access path rather than in the application logic alone. Enterprise customers may elect single-tenant deployment in a dedicated environment.
4. Access control
Access to production systems follows least privilege and is granted through a documented request and approval process with quarterly recertification. Multi-factor authentication is mandatory for all personnel without exception. Administrative access requires a hardware security key.
Support personnel cannot read customer documents by default. Where access is required to resolve an issue, it is requested from the customer, time-limited, scoped to the specific matter, and recorded in an audit log the customer can inspect.
Customer-side controls include SAML single sign-on with SCIM provisioning, role-based permissions, matter-level access restrictions, session timeout policies and IP allow-listing on Enterprise plans.
5. AI-specific controls
No training on customer data. Customer content is never used to train, fine-tune or evaluate models made available to other customers. This is contractual, not configurable.
Model inference runs within the customer’s elected region. Prompts and completions are retained only for the period required to deliver and audit the feature, and are subject to the same encryption, isolation and deletion controls as documents.
Every analysis records the model version and playbook version used, so any report can be reproduced and explained. Model updates are released on a published schedule with change notes, and Enterprise customers may pin a model version for the duration of a matter.
6. Infrastructure and operations
Production runs in a hardened cloud environment with network segmentation, private subnets for data stores, and no direct inbound access to compute nodes. Infrastructure is defined as code and changes go through peer review and automated policy checks.
Monitoring covers availability, integrity and security events, with centralised tamper-evident logging retained for twelve months. Backups are encrypted, stored in a separate account within the same region, and restore procedures are tested quarterly. Recovery objectives: RPO of one hour, RTO of four hours.
7. Secure development
All code changes require peer review and pass automated static analysis, dependency vulnerability scanning and secret detection before merge. Dependencies are patched on a defined schedule, with critical vulnerabilities remediated within 72 hours of a fix becoming available.
Independent penetration testing is carried out annually and after any significant architectural change; summary reports are available to customers under NDA. We operate a responsible disclosure programme — report a vulnerability to [email protected] and we will acknowledge within one business day.
8. Incident response
We maintain a documented incident response plan with defined severity levels, an on-call rota and named decision-makers. The plan is exercised at least annually through a tabletop simulation.
Where an incident affects customer personal data, affected customers are notified without undue delay and in any event within 48 hours of confirmation, with the information required under Article 33(3) GDPR. Post-incident reviews are shared with affected customers.
9. People and suppliers
All personnel undergo background screening appropriate to their role and jurisdiction, sign confidentiality undertakings, and complete security and data protection training on joining and annually thereafter. Access is revoked within one hour of departure.
Suppliers with access to customer data are assessed before onboarding and reviewed annually, and are subject to contractual obligations no less protective than our own.
10. Working with your security team
We know that vendor assessment is a real cost for legal teams. To reduce it, we maintain a standard evidence pack — ISO certificate, SOC 2 Type II report, penetration test summary, architecture overview, sub-processor list, DPA, and completed CAIQ and SIG Lite questionnaires — available under NDA within one business day of request. Write to [email protected].
Questions about this document? Write to [email protected], or to JuriPro SARL, 18 Rue de la Paix, 75002 Paris, France.