How Legal Brain protects your firm's data, your clients' privacy, and your professional reputation.
How well each security area is covered in Legal Brain
Step-by-step: how client data is protected before AI processing
Defence in depth: five concentric layers of protection
Security features implemented and ready for review
Prompt injection and jailbreak testing outcomes
Test types included: multi-turn probes, social engineering attempts, encoded instructions, jailbreak techniques, architecture probes, and data extraction attempts. Testing is ongoing with continuous improvement to defences.
Common questions from security and technology teams
Deeper technical questions and prepared responses
Legal Brain uses a commercial large language model via API. Our AI provider's commercial terms explicitly prohibit training on customer content. Queries are processed and discarded. All PII is removed before any query is sent.
Legal Brain can be deployed within your firm's infrastructure. On-premise deployment options are available - contact us to discuss your requirements.
Users can delete documents and conversations at any time. Configurable retention policies are available to automatically purge records according to your firm's requirements.
Regular adversarial testing is conducted. A formal external penetration test can be commissioned if required as a condition of engagement.
Automated threat detection and blocking with real-time alerting. Comprehensive security logs support forensic investigation. A formal incident response plan can be provided.
No. Strict data isolation ensures each user can only access their own documents, search results, and conversation history.
PII anonymisation is automatic and proactive. The architecture strongly supports compliance with Australian privacy requirements. Formal Data Processing Agreements and Privacy Impact Assessments can be prepared on request.
What we can provide to meet your firm's security requirements