Jurisyn

Security and confidentiality

A tool that handles privileged material has to be judged on what it cannot do, not on what it promises. This page states plainly how Jurisyn is built, what it holds, and what we have not yet completed.

Commitments

The four that matter most

Where documents live

They stay in your system of record

Jurisyn indexes your documents where they live. It does not copy your document library onto our servers. What we hold is a search index and the passages needed to answer a question.

Model training

No training on customer data, ever

Your material is never used to train or fine-tune any model, ours or a third party’s. Model providers used for reasoning operate under zero-retention terms: prompts are not stored and not used for training.

Access control

Permissions are enforced at query time

Every question triggers a live permission check against your document system. There is no path by which a user receives content from a matter they cannot open, including through a summary or an aggregate answer.

Audit

Everything is logged and exportable

Each query records the user, the question, the documents retrieved, the permissions applied and the response. Firms use this for supervision, for client audits, and for regulator questions.

Technical detail

Controls in place

Encryption in transit
TLS 1.3 for all connections, with TLS 1.2 as the minimum accepted fallback.
Encryption at rest
AES-256 on all stored indexes, logs and backups.
Tenant isolation
Each firm gets a separate index and separate encryption keys. No shared retrieval surface between customers.
Data residency
Chosen at deployment and fixed: India, European Union, United Kingdom, or your own cloud tenancy.
Authentication
SAML 2.0 and OIDC single sign-on. Multi-factor enforced by your identity provider. No separate Jurisyn password.
Internal access
Jurisyn staff have no standing access to customer content. Support access requires named customer approval, is time-limited, and is logged and reported to you.
Retention
Query logs kept for the period you set. Index and logs deleted within 30 days of contract end, with written confirmation.
Subprocessors
Listed in full in the data processing agreement, with 30 days’ notice before any change.
Backups
Encrypted, held in the same region as the primary index, restore-tested quarterly.

Being straight with you

Certifications in progress

Jurisyn is an early-stage company and we would rather tell you where we are than imply more. As of 28 July 2026:

  • SOC 2 Type II — readiness work under way. Not yet certified. We will not claim it until the report is issued, and we will send you the report when it is.
  • ISO/IEC 27001 — planned after SOC 2. Not yet certified.
  • GDPR and India’s Digital Personal Data Protection Act — we act as a processor and offer a data processing agreement covering both. Ask and we will send it before you share a single document.
  • Penetration testing — independent testing scheduled before general availability. Summary reports will be shared with customers under NDA.

If your firm has a security questionnaire, send it to hello@jurisyn.ai. We answer it honestly, including the questions where the answer is “not yet”.

Reporting

Found a vulnerability?

Write to security@jurisyn.ai with enough detail to reproduce the issue. We acknowledge within two business days and will tell you what we are doing about it. We do not pursue legal action against researchers who report in good faith and give us reasonable time to fix the problem before disclosing.

Last reviewed 28 July 2026

See it answer a question from your own files

A demo runs on a folder of your documents, not ours. Thirty minutes, no slides, and you keep the index or we delete it — your call.