Customer data stays yours.
Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.
Security · Trust
Esheria is designed for legal work that carries confidentiality, professional responsibility, and procurement scrutiny. Customer prompts, uploads, matter context, and workspace data are not used to train foundation models.
Core commitments
Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.
Role-based permissions, workspace controls, matter-level scoping where available, and privileged action audit logs protect sensitive work.
Data is protected with encryption in transit and at rest, with key management and access controls appropriate to the product and plan.
Where model providers process customer content, Esheria uses enterprise or zero-retention model endpoints where applicable.
Primary hosting is in Esheria's configured cloud region, with Kenya residency, EU hosting, customer-cloud, and on-prem deployment paths available for qualifying LegalOS customers.
Security documentation, sub-processor information, DPA terms, and trust materials are available during vendor review.
Security programme
SSO and MFA options are available for qualifying plans, with account, workspace, and role controls designed around legal teams.
Audit logs, trace IDs, API token controls, workspace records, and production access reviews support investigation and accountability.
Sub-processors are reviewed for security, confidentiality, data protection, and operational need before they support the service.
Monitoring, logging, vulnerability management, patching, backup and recovery processes, and incident response procedures support service resilience.
API tokens, rate limits, trace IDs, idempotency controls, and predictable error envelopes support safer production integrations.
Personnel confidentiality, access discipline, and security awareness are part of how Esheria handles customer data.
Privacy and compliance
Esheria holds a valid ISO/IEC 27001 certification for its information security management system. Certificate and scope details are shared during trust review.
Processor terms govern customer personal data when Esheria processes it on customer instructions.
Applicable corporate, privacy, and vendor-review materials are available during procurement or trust review.
Where GDPR or similar transfer rules apply, Esheria uses data processing terms, standard contractual clauses, equivalent safeguards, and technical controls.
Current sub-processor information, security materials, and procurement responses are available through the trust review process.
Trust & security FAQ
By default, in Esheria's configured cloud region. Kenya residency, EU hosting, customer-cloud, and on-premises options are available for LegalOS customers under signed terms.
Production access is limited, logged, reviewed, and granted only where needed to operate, support, secure, or troubleshoot the service.
Yes. The current list is available through the trust pack or on request, and updates are handled under the DPA or customer agreement.
Customer data is returned or deleted according to the customer agreement, DPA, product functionality, and documented instructions.
No. Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.
Yes. Esheria is designed around source links, review steps, traceability, role controls, and human approval for legal and high-risk workflows.