Trust & Security

Built for firms that
can't afford to guess

Privileged client data and AI-generated legal work product demand real controls, not marketing badges. Here's exactly what protects your data today.

Platform security

Tenant isolation

Every organization's data is separated by Postgres row-level security (RLS) policies keyed on organization_id, enforced at the database layer, not just in application code.

Enterprise SSO

Sign in with your organization's Microsoft Entra ID (Azure AD) or Google Workspace tenant. Multi-factor authentication is enforced by your own tenant's conditional access policies.

Role-based access control

Four roles (owner, admin, member, viewer) gate every organization resource through an explicit permission matrix — no ad-hoc access checks.

Audit logging

Every sensitive action is recorded with actor, action, resource, organization, IP address, and timestamp, and is queryable by org owners and admins.

Encryption

Data in transit is TLS-encrypted end to end, including the database connection (sslmode=require). Connected third-party OAuth tokens (Microsoft 365, Google Workspace, Slack, DocuSign) are encrypted at rest and never returned by the API.

Secrets management

Production credentials are held in Azure Key Vault and injected via managed identity — never committed to source control or baked into container images.

AI you can cite in a filing

Hallucinated case law has gotten lawyers sanctioned. Cojuri's grounding pipeline exists specifically to stop that before it reaches you.

Three-gate claim grounding

Every AI-generated legal claim is checked against the source document before it reaches you: verbatim extraction, an adversative-qualifier scan (catching "but/unless/subject to" clauses that flip a claim's meaning), and a numeric constraint solver that rejects unsupported figures, dates, and counts.

External citation verification

Case law citations are checked against CourtListener, Cornell LII, and Harvard's Case Access Project — not just the model's own self-consistency.

Hallucination audit trail

Every time content is stripped by the grounding pipeline, a timestamped record of what was removed and why is retained, giving you a per-response audit history.

Gated write actions

Higher-risk AI-driven writes pass through a deterministic policy kernel before they're committed, rather than executing directly on model output.

What we're not going to do

We won't put a compliance badge on this page that we haven't earned. We don't hold a SOC 2 or ISO 27001 certification today. If your security review requires one, or you need our data processing agreement, subprocessor list, or penetration test results, tell us — we'd rather have that conversation directly than make a claim we can't back up.

Security team has questions?

We'll walk through architecture, data flows, and controls directly.

security@cojuri.com