Trust center

Your documents are the whole business.

Privileged material, under a duty of confidentiality, often under a protective order. Here is exactly how it is handled, in the detail your security reviewer is going to ask for anyway.

SOC 2 Type II ISO 27001 ISO 27701 ISO 42001 SOC 3 GDPR CCPA HIPAA BAA CSA STAR

Your documents never train a model

Not ours, not a vendor's. No customer content enters any training set, fine-tune, or evaluation corpus. This is contractual, not a setting you have to find and switch off.

Encrypted in transit and at rest

TLS 1.3 on the wire, AES-256 at rest, with per-tenant keys. Enterprise customers can bring their own key through AWS KMS and revoke it independently of us.

Tenant isolation

Logical isolation at the storage and index layer on all plans, so no query can cross a tenant boundary. Enterprise adds single tenant or in-VPC deployment where the data never leaves your account.

Data residency

US on all plans. EU on Practice and above, UK on Enterprise. Processing and storage both stay in region, including the model inference step.

Retention you control

Set retention per matter, from delete-on-completion to a fixed schedule matching your records policy. Deletion is hard deletion with a certificate, not a hidden flag.

Access controls

SAML SSO, Entra ID, SCIM provisioning, matter-level permissions, and ethical wall support so a conflicted team cannot see a matter even by direct link.

Immutable audit log

Every ingestion, agent step, model version, prompt, output, human override, export, and permission change, written append-only and exportable to your SIEM.

Subprocessors, published

The current list is on the DPA with 30 days notice before any change. Enterprise customers can veto a subprocessor and be moved to an alternative path.

Certifications and attestations

What we hold, with the scope attached.

A badge without a scope statement is decoration. Each certificate below lists the legal entity, the systems in scope, and the certification body. Reports and certificates are available under NDA through the trust portal.

SOC 2 Type II

Certified

Security, availability, confidentiality, and processing integrity. Twelve month observation window with no exceptions noted, including AI-specific controls for model access and output logging.

Auditor Schellman · Renewed annually · Report under NDA

ISO/IEC 27001:2022

Certified

Information security management across the platform, corporate systems, and the software development lifecycle. Surveillance audits annually, full recertification every three years.

Cert 27001-DL-2026 · Accredited by UKAS · Scope covers all production regions

ISO/IEC 42001:2023

Certified

AI management system. Covers AI system inventory, risk classification, human oversight design, training data governance, model change control, and incident handling for every agent in the product.

Cert 42001-DL-2026 · Scope includes extraction, review, and verification agents

ISO/IEC 27701:2019

Certified

Privacy information management extension to our 27001 system, covering our role as processor for customer document content and controller for account data.

Assessed alongside ISO 27001 · Supports GDPR Article 28 obligations

SOC 3

Published

Public summary of the SOC 2 Type II examination. Downloadable without an NDA if you need something to attach to an internal approval before legal gets involved.

Available on the trust portal · No NDA required

GDPR and UK GDPR

Compliant

DPA with standard contractual clauses and the UK addendum, EU representative appointed under Article 27, records of processing maintained, DPIA template supplied on request.

EU and UK data residency available · Subprocessor list on the DPA

CCPA and CPRA

Compliant

Service provider under the CCPA. We do not sell or share personal information, and contractual restrictions on secondary use are written into the standard agreement.

California resident requests routed through your admin

EU AI Act

Aligned

Documented system purpose, risk classification, human oversight design, logging, and transparency disclosures meeting the obligations that apply to our classification. Conformity documentation available for your own assessment.

Aligned to the August 2026 obligations · Reviewed quarterly

NIST AI RMF

Mapped

Controls mapped to the Govern, Map, Measure, and Manage functions. Useful if your own AI governance program is built on the framework and you need a crosswalk for your risk register.

Crosswalk to ISO 42001 controls available

HIPAA

BAA available

For healthcare litigation and any matter where PHI lands in the document set. Business associate agreement executed on request, with the technical safeguards covered under our 27001 scope.

Enterprise plans · BAA required before PHI upload

Penetration testing

Annual

Third-party network, application, and AI-specific red team testing covering prompt injection, document-borne instruction attacks, and cross-tenant retrieval. Executive summary shared with customers.

Last test Q2 2026 · Continuous automated scanning between tests

CSA STAR Level 1

Registered

Completed CAIQ published to the Cloud Security Alliance registry. If your questionnaire is CAIQ-based, most of it is already answered before you send it.

CAIQ v4 · Public registry entry

Certificates, SOC reports, the CAIQ, and the current subprocessor list live in the trust portal. Access is granted within one business day of an NDA. Vulnerability reports go to security@doculightning.com and are acknowledged within one business day.

Security questions

The ones that come up in every review.

Which model providers do you use, and do they see our documents?

We run a mix of self-hosted open-weight extraction models and commercial frontier models under zero-retention enterprise agreements. Providers process content transiently to return a response and retain nothing. The current list sits in the DPA, and Enterprise customers can restrict processing to the self-hosted path only.

Can DocuLightning staff read our documents?

No, not by default. Production access requires an explicit, time-boxed grant from a customer administrator, is limited to named engineers, and every session is logged in your audit trail. There is no standing internal access to customer content.

What happens to our data if we cancel?

Export everything, including the audit log, for 30 days after termination. After that it is hard deleted on the schedule in your contract, and we issue a deletion certificate. Backups roll off within 35 days.

How do you handle a protective order or a clawback?

Matter-level isolation, ethical walls, and per-matter retention rules. Documents can be purged from a matter and its index on demand, with the purge itself recorded so you can show what was removed and when.

Where do you sit on the hallucination problem?

Two places. First, findings are grounded in retrieved passages with coordinates, so an assertion without a source cannot be rendered. Second, a verification pass re-checks each citation against the source page before delivery, and anything that fails is escalated rather than shipped. This lowers the rate, it does not eliminate it, which is why every finding is presented for human sign-off.

Send us your security questionnaire.

Most come back inside three business days. We can also start from a completed CAIQ or SIG Lite if that is faster for your team.

Contact security