§ Custody


Your file remains your file

You are about to put privileged material into someone else’s software. This page sets out exactly what happens to it, so you can make that decision on facts rather than on reassurance.

§ 01 · The short answers

The three questions every practitioner asks first

Question one

Is my material used to train models?

No. Case material is processed to answer your instructions and for nothing else. Our agreement with the AI provider prohibits training on material sent through our account, and we do not enable any feature that would permit it.

Question two

Does anyone at your company read my matters?

Not as a matter of routine. Access happens only where you ask us to investigate a specific problem, where it is strictly necessary to keep the platform running, or where we are compelled by law. Every such access is written to the audit log.

Question three

Can I get it deleted?

Yes, at any time. Delete a matter and its documents from the workspace. It is removed from live systems immediately and purged from backups within 30 days, subject only to retention we are required by law to observe.

§ 02 · Storage and transmission

Where documents actually sit

In transit

TLS on every connection

Every request between your browser and the platform, and between the platform and the AI provider, travels over TLS. The site is served over HTTPS only; session cookies are marked Secure, so sign-in will not function at all over an unencrypted connection.

At rest

Encrypted, and outside the web root

Uploaded documents are stored encrypted, in a directory placed outside the public web root and additionally blocked from direct URL access at the web server level. There is no URL that serves a document without passing through authentication and a permission check first.

Secrets

Keys are not stored in plain text

Passwords are stored as bcrypt hashes and are not recoverable by anyone, including us. Two-factor secrets, recovery codes and platform API credentials are encrypted with AES-256 and authenticated with HMAC.

§ 03 · Access control

Who can see a matter

Scoped to the organisation

A matter is visible only within the organisation it was created in. There is no cross-organisation index, search or aggregation of any kind.

Scoped to the seat

Within a firm, partners, associates and clerks see only the matters they are assigned to. Permissions are set by the account holder, not by us.

Two-factor authentication

Time-based one-time codes are available on every account and can be made mandatory across a firm. On an account holding client material, we would treat this as expected rather than optional.

Session and lockout controls

Sessions expire on idle timeout. Repeated failed sign-ins lock the account for a period. Changing a password revokes every other active session.

Everything is logged

Sign-ins, uploads, runs, exports, permission changes and deletions are each written with user, action and timestamp, so the chain of handling on any matter can be reconstructed.

Support access is exceptional and recorded

We do not browse customer matters. Where you ask us to look at a specific problem, that access is logged like any other.

§ 04 · Subprocessors

Who else touches the data

Four parties, each for one purpose. No advertising networks, no analytics profiling, no data brokers.

PartyPurposeWhat it sees
AI providerPerforms the analysis The relevant portions of the matter, transiently. Contractually prohibited from training on it.
Hosting providerRuns the application and database Encrypted data at rest. No application-level access.
Payment gatewayTakes payment Your card details, directly. These never reach our servers.
Email providerDelivers verification and notification email Your email address and the content of those messages. Never case material.

The identity of each current provider, and its published data policy, is available on request and is listed in the data processing agreement. Ask at privacy@litoraai.com.

§ 05 · Retention and deletion

How long anything is kept

DataRetention
Case documents and mattersUntil you delete them. Removed from live systems immediately, purged from backups within 30 days.
Account dataWhile the account is open, then 90 days after closure.
Billing records and credit ledger8 years, as required by Indian tax and company law.
Audit and security logs12 months.
Server and error logs90 days.
Support correspondence24 months.

On account closure you have 30 days to export your matters before deletion. Ask us about unspent credits before you close the account rather than after — see the refund policy.

§ 06 · Incidents

What happens if something goes wrong

If we suffer a breach

Where a personal data breach is likely to result in a risk to affected people, we notify the relevant authority within the period the law requires and tell affected customers without undue delay. You will be told what happened, what data was involved, what we have done about it and what you should do.

We will not describe an incident as a “security event” and hope you do not ask further.

If you find a vulnerability

Report it to security@litoraai.com. We will not pursue researchers who act in good faith, do not access or exfiltrate other users' data, and give us a reasonable opportunity to fix the problem before disclosing it.

If you want to test the platform actively, ask first and we will usually say yes. Testing without permission is a breach of the acceptable use policy, and we would rather give permission than deal with it that way.

What we do not claim

No system is perfectly secure and we will not pretend otherwise. We hold no security certification at present, and we would rather say so than imply one. What this page describes is what we actually do; if your firm requires a formal assurance report before it can use a processor, tell us what standard you need and we will tell you honestly whether we meet it.


Need a DPA for your compliance file?

Ask and we will send one. If your firm has a security questionnaire, send that too — we will answer it straight, including where the answer is “we do not do that yet”.

Operated by Rank First Technologies Private Limited, CIN U58201PB2026PTC068900, S.A.S. Nagar (Mohali), Punjab 160055, India.

Prepare your next contested matter

Put one file through it — £99

The whole bundle read page by page, an assessment of where you are exposed, and both sides argued in front of a bench. No subscription, nothing to cancel.