Security · Trust

Security, privacy, and trust controls for serious legal work.

Esheria is designed for legal work that carries confidentiality, professional responsibility, and procurement scrutiny. Customer prompts, uploads, matter context, and workspace data are not used to train foundation models.

Core commitments

The posture, plainly stated.

01

Customer data stays yours.

Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.

02

Legal-work access controls.

Role-based permissions, workspace controls, matter-level scoping where available, and privileged action audit logs protect sensitive work.

03

Encryption and transport security.

Data is protected with encryption in transit and at rest, with key management and access controls appropriate to the product and plan.

04

Model-provider safeguards.

Where model providers process customer content, Esheria uses enterprise or zero-retention model endpoints where applicable.

05

Data residency options.

Primary hosting is in Esheria's configured cloud region, with Kenya residency, EU hosting, customer-cloud, and on-prem deployment paths available for qualifying LegalOS customers.

06

Procurement transparency.

Security documentation, sub-processor information, DPA terms, and trust materials are available during vendor review.

Security programme

Controls built for confidentiality, auditability, and customer assurance.

01

Identity and access.

SSO and MFA options are available for qualifying plans, with account, workspace, and role controls designed around legal teams.

02

Auditability.

Audit logs, trace IDs, API token controls, workspace records, and production access reviews support investigation and accountability.

03

Vendor governance.

Sub-processors are reviewed for security, confidentiality, data protection, and operational need before they support the service.

04

Incident readiness.

Monitoring, logging, vulnerability management, patching, backup and recovery processes, and incident response procedures support service resilience.

05

Secure developer surfaces.

API tokens, rate limits, trace IDs, idempotency controls, and predictable error envelopes support safer production integrations.

06

Security awareness.

Personnel confidentiality, access discipline, and security awareness are part of how Esheria handles customer data.

Privacy and compliance

The legal-data controls customers expect before procurement.

ISO

ISO/IEC 27001 certification

Esheria holds a valid ISO/IEC 27001 certification for its information security management system. Certificate and scope details are shared during trust review.

DPA

Data Processing Agreement

Processor terms govern customer personal data when Esheria processes it on customer instructions.

Privacy

Data protection posture

Applicable corporate, privacy, and vendor-review materials are available during procurement or trust review.

GDPR

International transfer safeguards

Where GDPR or similar transfer rules apply, Esheria uses data processing terms, standard contractual clauses, equivalent safeguards, and technical controls.

Trust

Trust pack and sub-processors

Current sub-processor information, security materials, and procurement responses are available through the trust review process.

Trust & security FAQ

The questions customers ask before procurement.

01

Where is data stored?

By default, in Esheria's configured cloud region. Kenya residency, EU hosting, customer-cloud, and on-premises options are available for LegalOS customers under signed terms.

02

Who can see our data?

Production access is limited, logged, reviewed, and granted only where needed to operate, support, secure, or troubleshoot the service.

03

Are sub-processors disclosed?

Yes. The current list is available through the trust pack or on request, and updates are handled under the DPA or customer agreement.

04

What happens if we leave?

Customer data is returned or deleted according to the customer agreement, DPA, product functionality, and documented instructions.

05

Does our data train models?

No. Customer prompts, uploads, matter context, workspace records, and API inputs are not used to train foundation models.

06

Can legal teams keep review control?

Yes. Esheria is designed around source links, review steps, traceability, role controls, and human approval for legal and high-risk workflows.