Security

Attorney-client privilege starts here.

Client documents are sensitive. We designed the architecture so that your firm — not Undwrlyft — controls the perimeter.

Isolated Per-Firm Architecture
Firm A
Undwrlyft Engine
Firm B

Architecture: isolated per-firm environments

  • Dedicated processing environment per firm — no document co-mingling across clients
  • Documents processed in-memory and purged post-brief delivery
  • No persistent document storage on Undwrlyft infrastructure
  • Matter data never used for model training or improvement

Encryption and access controls

  • TLS 1.3 in transit
  • AES-256 at rest for any transient matter data
  • Per-firm API keys with fine-grained scope
  • Audit log of every document access event
  • RBAC for firm admin, review attorney, and read-only roles

Compliance posture

Undwrlyft is designed with CTDPA (Connecticut Data Privacy Act) and ABA Model Rules 1.6 (confidentiality) and 5.3 (supervision of nonlawyers and technology) in mind. We do not claim third-party certification at this stage. What we can tell you is what the architecture actually does: per-firm processing isolation, no document persistence, no model training on client data. Our controls are designed to satisfy those obligations — your firm's technology team can review them in detail.

Compliance Framework
  • CTDPA — Connecticut Data Privacy Act
  • ABA Model Rule 1.6 — Confidentiality of Information
  • ABA Model Rule 5.3 — Supervision of Technology
  • Architecture designed to align with SOC 2 Type II control requirements — no third-party certification claimed at this stage

Questions about our security stack?

We're happy to walk through the architecture in detail with your firm's technology or compliance team.

Contact us