Cedent AI
Security and compliance

Your clients trust you.
You can trust us.

Attorney-client privilege demands the highest standard of data protection. Six commitments shape how Cedent is built, and none of them is a policy written after the fact.

Attorney-directed AI

No document is filed, no email is sent, and no case data is changed without your explicit direction. The assistant produces work product when you ask for it, not on its own initiative.

Firm-level isolation

Your matters, documents and case facts sit behind a boundary the database enforces on every request, not one the application is trusted to remember. A mistake in the software above it returns nothing at all rather than somebody else's case.

Encryption everywhere

Agent reasoning traces and case files are stored at the same encryption level as your documents.

in transit TLS 1.3 · at rest AES-256

Source-grounded output

AI output is tied to documents you have uploaded. Every fact links back to its source, so you can always verify what the AI is relying on.

trust levels P0-P5

PII detection

Social Security Numbers and sensitive information are automatically flagged before filing. Redaction tools remove protected data from service copies.

SSN · license · card · account · minor DOB

Session and workspace security

Case data is loaded into temporary workspaces during active sessions and wiped on termination. No residual client data persists in working memory.

Access control

The right people see the right data.

Two boundaries matter here: which colleague can open which matter, and what the assistant is permitted to do with text written by someone outside your firm.

Access scoped per person, per matter

Each person is either given the whole caseload or a named list of matters. Attorneys hold approvals, billing and firm settings; staff work inside a matter without them. Financial detail is visible only to the people whose role includes it.

Confidential matters and ethical walls

Mark a matter confidential and it stays with the people named on it, even for colleagues who otherwise see everything. A wall between a person and a matter is a hard block that no other permission overrides.

Outside text is treated as data, never instructions

Opposing counsel writes the emails and attachments Cedent reads. That text is fenced off before any model sees it, and what the assistant is allowed to do with a fact is capped by where the fact came from. No prompt-only defense is absolute, so the limits sit on the tools as well as the prompt.

Authentication and identity

Sign-in runs through a dedicated identity provider rather than a password table of our own. Every request re-establishes who you are, so nothing is assumed from the request before it.

Per-request authorization

Every request is checked against the user's firm and role. Attempting to reach another firm's data returns an error, not the data.

The people panel for one matter. A Confidential matter checkbox at the top, unticked, described as visible only to the people on this matter's team and the firm owner. Below it a Blocked from this matter panel, described as an ethical wall that no other permission overrides, currently reading no one is blocked. Then the team on the matter: an attorney marked lead and a paralegal. Then the client side: one client, with the email address redacted for this page.
The two controls a firm needs are on the matter itself: mark it confidential and it stops being visible to colleagues who otherwise see everything, and a wall blocks a named person outright. Camila Alvarez v. Nathan Reyes is a matter in our demonstration firm, so the parties are invented.
Ethics and compliance

Built with California Rule 1.1 in mind.

The duty of competence now includes understanding the technology you use to serve clients. Cedent is designed to help you meet that obligation.

Human oversight by default

AI assists, the attorney decides. The staging queue ensures a person reviews every output before it affects a client's case.

Traceable reasoning

See what the AI did and why. Tool traces log every action, and thought traces show the reasoning chain with references to statutory rules.

Data residency

Your data stays in the United States. We do not transfer client data outside the country or use it to train AI models.

SOC 2 Type II underway

SOC 2 Type II is underway. Our controls are built to the framework's Security and Confidentiality criteria, and we will share the report with firms under diligence once it is issued. We do not claim certification before it is.

This describes how Cedent is built, not legal advice about your obligations. Your duty of competence stays yours.

Due diligence

What a security review asks first.

These are the four questions that come back from a firm's own IT review, answered here in the same terms as the privacy policy that binds us to them.

Does anyone at Cedent read our client data?

Not as a matter of routine. We reach matter data in three situations only: when you ask us to, such as a support issue you have raised; when it is necessary to investigate abuse or a security incident; or when the law requires it. Access is limited to what that specific purpose needs. Our runtime logs are scrubbed before they are written, so the contents of messages and documents are not sitting in them to be read in the first place.

What happens to our data if we cancel?

Your firm is the controller of everything inside a matter and Cedent is a processor acting on your instructions. Canceling does not change that. You can ask us to delete your data at any point, during the subscription or after it ends. The working copies are shorter-lived than the account: a matter workspace is wiped when the session ends, not when you leave.

Where does the AI actually run, and does our data train it?

Model inference runs on infrastructure we contract for, inside the United States, under the same terms as the rest of the platform. Your prompts, documents and matter facts are not used to train models. Not by us, and not by the providers running them. That is a contractual commitment, not a setting someone could change.

Which outside providers touch our matter data?

Hosting, file storage, the database, document text extraction, sign-in, notification email and model inference each sit with a named provider, working on our instructions and under contract. We publish the current list rather than describing it in the abstract, and it is in the sub-processors section of our privacy policy.

The full detail behind these answers, including the current sub-processor list, is in our privacy policy.

Privileged by design

Questions about security?

Send them to a person. A due-diligence questionnaire, a vulnerability report, or whatever a firm's own IT review turns up all reach the same inbox, and we will acknowledge what you send.

security@cedent.ai

Privacy questions go to privacy@cedent.ai. If you would rather talk it through, book a demo and bring the questionnaire with you.