Your clients trust you.
You can trust us.
Attorney-client privilege demands the highest standard of data protection. Six commitments shape how Cedent is built, and none of them is a policy written after the fact.
The right people see the right data.
Two boundaries matter here: which colleague can open which matter, and what the assistant is permitted to do with text written by someone outside your firm.
Access scoped per person, per matter
Confidential matters and ethical walls
Outside text is treated as data, never instructions
Authentication and identity
Per-request authorization
Built with California Rule 1.1 in mind.
The duty of competence now includes understanding the technology you use to serve clients. Cedent is designed to help you meet that obligation.
This describes how Cedent is built, not legal advice about your obligations. Your duty of competence stays yours.
What a security review asks first.
These are the four questions that come back from a firm's own IT review, answered here in the same terms as the privacy policy that binds us to them.
Does anyone at Cedent read our client data?
Not as a matter of routine. We reach matter data in three situations only: when you ask us to, such as a support issue you have raised; when it is necessary to investigate abuse or a security incident; or when the law requires it. Access is limited to what that specific purpose needs. Our runtime logs are scrubbed before they are written, so the contents of messages and documents are not sitting in them to be read in the first place.
What happens to our data if we cancel?
Your firm is the controller of everything inside a matter and Cedent is a processor acting on your instructions. Canceling does not change that. You can ask us to delete your data at any point, during the subscription or after it ends. The working copies are shorter-lived than the account: a matter workspace is wiped when the session ends, not when you leave.
Where does the AI actually run, and does our data train it?
Model inference runs on infrastructure we contract for, inside the United States, under the same terms as the rest of the platform. Your prompts, documents and matter facts are not used to train models. Not by us, and not by the providers running them. That is a contractual commitment, not a setting someone could change.
Which outside providers touch our matter data?
Hosting, file storage, the database, document text extraction, sign-in, notification email and model inference each sit with a named provider, working on our instructions and under contract. We publish the current list rather than describing it in the abstract, and it is in the sub-processors section of our privacy policy.
The full detail behind these answers, including the current sub-processor list, is in our privacy policy.
Questions about security?
Send them to a person. A due-diligence questionnaire, a vulnerability report, or whatever a firm's own IT review turns up all reach the same inbox, and we will acknowledge what you send.
Privacy questions go to privacy@cedent.ai. If you would rather talk it through, book a demo and bring the questionnaire with you.
