Trust

Security & privilege architecture

Last updated: July 22, 2026 · Confidential Mode · Honest beta

Core trust feature

Confidential Mode (default · ON)

Verify never needs client narrative. Only public authority strings leave the browser. Software does not create attorney-client privilege - Confidential Mode is how we reduce disclosure so you can work closer to existing confidentiality duties.

Confidential Mode path (default)

  1. You paste or load a draft in the browser (or open a Law Desk matter preview).
  2. Citation strings are extracted on-device.
  3. Only those public strings are sent for existence / risk checks (corpus, CourtListener, CAP, GovInfo when live).
  4. Client facts and strategy stay on device unless you arm Full document with double confirmation (checkbox + type SEND FULL).
  5. CiteSafe does not store verify request bodies in a product database. Beta matter memory and history stay in your browser until firm accounts ship.

Open VerifyLaw Desk preview

What we do not claim

  • No attorney-client relationship with CiteSafe.
  • Upload does not create privilege or work-product protection by itself.
  • No SOC 2 Type II badge until independently audited.
  • No enterprise SSO / on-prem as production fiction in public beta.
  • No “hallucination-free” guarantee.

Data handling (operations)

  • Verify API: request body not stored in a CiteSafe database ( body_stored=false). Response headers include X-CiteSafe-Body-Stored: false.
  • Max payload 200,000 characters.
  • Host logs: target 14 days; error logs exclude document bodies.
  • Much of the free beta history remains in your browser until cloud accounts ship.
  • HTTPS/TLS via hosting CDN (Vercel).
  • Training public generative models on customer content: No.

Other product surfaces

Brief Analyzer, Terminal demos, Command, Risk, and Research previews process content in the browser for interactive demos unless a screen explicitly sends data to a server API. Verify is the production path with cite-only default. Do not assume every screen is cite-only; check the on-screen “What leaves your browser” control when present.

Breach notification

If we confirm a personal-data breach affecting customers, we aim to notify affected customers within 72 hours of confirmation where required or appropriate. Report vulnerabilities or incidents to security@citesafe.co. Privacy requests: privacy@citesafe.co.

Contact

Firm hygiene

  • Prefer generative AI under counsel direction and firm policy.
  • Run cite-only verify before filing AI-assisted drafts.
  • Do not put client confidences into public consumer chatbots.
  • Human remains responsible for every filed authority.
  • Enterprise: request DPA and review subprocessors.

Roadmap (not yet shipped)

SSO/SAML, SOC 2 Type II, customer-managed keys, regional residency, immutable audit log export, and ethical walls for multi-matter firms are planned for enterprise readiness. We do not claim them until live.

Try cite-only verify · Privacy · Terms