Security · Representations and warranties
Your contracts stay yours.
We never train on your contracts.
Your documents are processed to produce your review and nothing else. They are not used to train or tune Rubrel’s models or any third party’s.
Written into the DPA, not only the privacy policy.
Encrypted in transit and at rest.
TLS 1.3 on every connection and AES-256 on disk, with keys held in a managed KMS and rotated every 90 days. Enterprise workspaces can bring their own key.
BYOK available on Enterprise.
You choose where data lives.
Each workspace is pinned to US or EU hosting when it is created. Documents never leave that region, including for support.
EU region: Frankfurt. US region: Virginia.
Audited every year.
SOC 2 Type II and ISO 27001, both renewed annually by an independent auditor. Reports are available under NDA from the trust centre.
Latest report: June 2026.
Access ends when employment does.
SSO through Okta, Entra ID or Google, with SCIM provisioning so leavers lose access the moment they leave your directory.
Every access event is logged for 7 years.
Deleted means deleted.
Remove a contract and it is gone from live systems at once and from backups within 30 days. Close your account and we confirm deletion in writing.
Deletion certificates on request.