Skip to content

Security and Compliance

TrialKit protects your most sensitive case data with enterprise-grade security, compliance, and ironclad data privacy designed for any legal team.

Trusted and Certified

SOC 2 Type II badge
SOC 2 Type IICertified
TLS 1.2+ badge
TLS 1.2+Enforced
AES-256 badge
AES-256Encryption
ISO 27001 badge
ISO 27001Certified
HIPAA badge
HIPAAComing soon

Layered Security

Security is embedded into TrialKit's development lifecycle through mandatory secure-coding training, formal reviews, automated vulnerability assessments, and ongoing testing across all deployment environments.

End-to-end encryption

All customer data is encrypted in transit and at rest using industry-standard encryption protocols. Case documents, media files, and productions are protected throughout their lifecycle within the platform.

Zero model training

Your data stays yours. TrialKit does not use customer inputs, outputs, or uploaded documents to train or improve general AI models. This commitment is reinforced through contractual terms and internal controls designed to prevent customer data from being used for model training.

Defined data retention

Data is retained only as long as necessary to support active use of the platform. Authorized users may delete case data or choose to archive it in accordance with TrialKit's data-retention policies.

Backup recovery

Backups are performed and tested regularly in accordance with documented disaster-recovery procedures designed to support system availability and data integrity.

Foundational audit logs

User and system activity is logged to maintain a clear, time-stamped record of access and actions across the platform. Administrative and authentication logs are restricted and protected in accordance with TrialKit's access-control policies.

Continuous monitoring

TrialKit employs continuous security monitoring, vulnerability scanning, and regular penetration testing to help identify and address potential threats.

Your private workspace

Your workspace is private by default. Your case files, work product, and privileged communications are scoped to your office or firm, not pooled across customers, not shared, not surfaced anywhere outside the security boundary we define together.

Case-Level Data Isolation

Case ACase B
Defined Access

Access to data and system functionality is role-based. Attorneys, paralegals, and support staff see only what they need, nothing more.

Silo Process

Every case operates in its own dedicated environment that is never shared, reused, or co-mingled.

Safe Search

Metadata, search indexes, and AI-derived outputs are generated and stored uniquely in each case.

Clean Analysis

Search indexes, embeddings, and analytical artifacts are never merged or queried across organizational boundaries.

Common security questions

Does TrialKit use your data to train AI models?

No. TrialKit does not use customer inputs, outputs, or uploaded documents to train or improve general AI models. This commitment is reinforced through contractual terms and internal controls designed to prevent customer data from being used for model training.

Who can access your case files?

Your workspace is private by default. Your case files, work product, and privileged communications are scoped to your office or firm, not pooled across customers, not shared, not surfaced anywhere outside the security boundary we define together. Within your workspace, access is role-based: attorneys, paralegals, and support staff see only what they need, nothing more.

What security certifications does TrialKit have?

TrialKit is SOC 2 Type II and ISO 27001 certified, enforces TLS 1.2+, and uses AES-256 encryption. HIPAA compliance is coming soon.

How is your data encrypted?

All customer data is encrypted in transit and at rest using industry-standard encryption protocols, with AES-256 encryption and TLS 1.2+ enforced. Case documents, media files, and productions are protected throughout their lifecycle within the platform.

What happens to your data, and what is the retention policy?

Data is retained only as long as necessary to support active use of the platform. Authorized users may delete case data or choose to archive it in accordance with TrialKit's data-retention policies. Every case also operates in its own dedicated environment that is never shared, reused, or co-mingled.

Simplify your discovery

See what one clear, connected case file does for the way you work. Spend your time lawyering.