Security posture

Written for your compliance team.

Cerulean holds the most sensitive material a firm possesses: privileged, confidential, often market-moving. This page sets out the security posture in the terms your reviewers will ask about, with reference numbers they can cite. Everything below is the default; nothing is an upgrade.

01

Architecture

SEC·01

Single-tenant per matter

Each matter is isolated in its own tenant. Nothing crosses the boundary, not even at the index layer.

SEC·02

UK-hosted and region-locked

Hosted in UK data centres and region-locked on request, so privileged material never leaves the jurisdiction you choose.

SEC·03

Encrypted in transit and at rest

Strong encryption throughout, with keys managed per tenant.

SEC·04

Zero Trust

Every request is verified, limited and logged; there is no implicit network trust anywhere in the stack.

02

AI governance

The part legal IT scrutinises hardest. How the models behave, what they are allowed to touch, and what happens to your documents are all governed by contract and by a certified management system, not by a checkbox.

AI·01

No training on client data

Documents are never used to train models, ours or anyone else's, and answers are never retained for training. This is contractual, not a setting.

AI·02

Grounded-only answers

Nothing is generated without a paragraph to point at; where the record is silent, Cerulean says so.

AI·03

Out-of-bundle research segregated

Reported authorities and open-web material are labelled and held apart from the record, never silently mixed in.

AI·04

ISO 42001 AI management system

A certified management system governs how models are selected, run and monitored.

03

Certifications

SOC 2 Type IIMaintained
ISO 27001Certified
ISO 42001Certified
UK & EU GDPRCompliant

Full reports and our Data Processing Agreement are available to your compliance team on request.

04

Access and operations

OPS·01

SAML single sign-on

Single sign-on against your identity provider, so access follows your existing joiner and leaver process.

OPS·02

Multi-factor authentication

Enforced on every account, with authenticator-app codes and single-use recovery codes.

OPS·03

Role-based access control

Granular, matter-scoped roles: reading, uploading and managing are separate permissions, assigned per person per matter.

OPS·04

IP allow-listing

Access can be restricted to the networks you nominate, so the platform is reachable only from chambers, the firm or the room.

OPS·05

Audit trail, every action

Every open, search, push and annotation is logged with cryptographic integrity, and exportable in full for the tribunal.

OPS·06

Right to erasure

Verified erasure of a document, a matter, or a person's data across live stores, caches and derived indexes.

05

For your data protection officer

We answer to your data protection officer directly. The Data Processing Agreement and our current sub-processor list are available on request. You will have a named security contact, and your questions are answered by the founding team, not a ticket queue.