Trust
Security & privilege architecture
Last updated: July 22, 2026 · Confidential Mode · Honest beta
Core trust feature
Confidential Mode (default · ON)Verify never needs client narrative. Only public authority strings leave the browser. Software does not create attorney-client privilege - Confidential Mode is how we reduce disclosure so you can work closer to existing confidentiality duties.
Confidential Mode path (default)
- You paste or load a draft in the browser (or open a Law Desk matter preview).
- Citation strings are extracted on-device.
- Only those public strings are sent for existence / risk checks (corpus, CourtListener, CAP, GovInfo when live).
- Client facts and strategy stay on device unless you arm Full document with double confirmation (checkbox + type SEND FULL).
- CiteSafe does not store verify request bodies in a product database. Beta matter memory and history stay in your browser until firm accounts ship.
What we do not claim
- No attorney-client relationship with CiteSafe.
- Upload does not create privilege or work-product protection by itself.
- No SOC 2 Type II badge until independently audited.
- No enterprise SSO / on-prem as production fiction in public beta.
- No “hallucination-free” guarantee.
Data handling (operations)
- Verify API: request body not stored in a CiteSafe database ( body_stored=false). Response headers include X-CiteSafe-Body-Stored: false.
- Max payload 200,000 characters.
- Host logs: target 14 days; error logs exclude document bodies.
- Much of the free beta history remains in your browser until cloud accounts ship.
- HTTPS/TLS via hosting CDN (Vercel).
- Training public generative models on customer content: No.
Other product surfaces
Brief Analyzer, Terminal demos, Command, Risk, and Research previews process content in the browser for interactive demos unless a screen explicitly sends data to a server API. Verify is the production path with cite-only default. Do not assume every screen is cite-only; check the on-screen “What leaves your browser” control when present.
Breach notification
If we confirm a personal-data breach affecting customers, we aim to notify affected customers within 72 hours of confirmation where required or appropriate. Report vulnerabilities or incidents to security@citesafe.co. Privacy requests: privacy@citesafe.co.
Contact
- Security: security@citesafe.co
- Privacy: privacy@citesafe.co
- General: hello@citesafe.co
- Legal: legal@citesafe.co
Firm hygiene
- Prefer generative AI under counsel direction and firm policy.
- Run cite-only verify before filing AI-assisted drafts.
- Do not put client confidences into public consumer chatbots.
- Human remains responsible for every filed authority.
- Enterprise: request DPA and review subprocessors.
Roadmap (not yet shipped)
SSO/SAML, SOC 2 Type II, customer-managed keys, regional residency, immutable audit log export, and ethical walls for multi-matter firms are planned for enterprise readiness. We do not claim them until live.