Security / Data handling

The statement your clients will ask you for

Every deployment ships with a definitive data handling statement. It answers the questions in outside counsel guidelines directly, in language a client security team accepts, and it is accurate because the architecture makes it so.

Compare architectures

What it says

Eight answers, none of them hedged

These are the positions the statement takes. They are short because a sealed deployment removes most of the qualifications a cloud product has to make.

Where data is processed

Entirely within the client controlled enclave. No processing occurs on Sanctum Lex infrastructure.

Who can access it

Only users authenticated against the firm's own identity provider. Sanctum Lex personnel have no access path to matter content.

Sub processors

None have access to client content. The enclave has no outbound path to a third party inference provider.

Training and model improvement

Client content is never used to train, tune, or evaluate any model, inside or outside the enclave.

Retention

Session and prompt history live for the life of the matter and are destroyed with it. Teardown wipes working memory.

Cross border transfer

None occurs, because content does not leave the deployment. Location is determined by where the firm places the node.

Incident notification

Any incident affecting the software is reported to the firm's named contact within the period set in the agreement.

Deletion and return

The firm holds the data throughout, so deletion is an operation the firm performs on its own systems.

Where firms use it

Outside counsel guidelines

Attach it to the client questionnaire that asks how AI tools handle matter content.

Client security audits

Answers the standard processing, retention, and sub processor questions in one document.

Internal risk registers

Gives your risk team a fixed statement to reference rather than a summary of a sales call.

The statement describes the software and its deployment model. It is not legal advice, and your firm remains responsible for its own obligations to clients and regulators.

Take the statement into your next client audit.

We will provide the current version and answer anything your client's security team raises.