Security · Privacy · Trust

Security controls and transparent boundaries for serious legal work.

Esheria documents identity, encryption, access, audit, token, privacy, model-processing, incident, and deployment controls without publishing certification claims that cannot be substantiated with scope and validity details.

Core commitments

Trust claims stay as specific as the evidence behind them.

01

Customer data is not foundation-model training data.

Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.

02

Credentials stay out of public surfaces.

API and OAuth tokens are never placed in marketing URLs, analytics payloads, public repositories, or generated discovery artifacts.

03

Least-privilege developer access.

Tokens, OAuth grants, pack entitlements, feature entitlements, scopes, and rate limits remain server enforced.

04

Encryption and controlled access.

Data is protected in transit and at rest with access controls appropriate to the deployed product and agreement.

05

Audit and traceability.

Trace IDs, token metadata, usage events, deployment evidence, and operational logs support investigation without exposing token secrets.

06

Procurement evidence on request.

Current security, privacy, sub-processor, residency, and contractual materials are supplied through the trust-review process.

Certification language

A badge is not a substitute for verifiable scope.

Any public certification claim must identify its status, issuer, certificate identifier, certified scope, and validity period.

Until those details are approved for publication, Esheria describes implemented controls and provides substantiating trust materials during procurement rather than making an unqualified certification claim.

Trust documents

Review the legal and operational boundaries behind the product.