Home Product Security

Your record is yours. Structurally.

This page says where your documents live, who can reach them, what leaves and under what conditions, and what we don’t claim.

The four commitments

Four things, and the architecture behind them.

Each of these is enforced by how the system is built. Each is a control we keep testing.

01

Encrypted and company-isolated

Encrypted in transit and at rest, with per-document keys and per-tenant key material in AWS KMS. Isolation is structural, not a filter on a shared pile. Retrieval is scoped to your company before a query is formed.

02

Never training data

Your documents are read for your matters and are never training data. Not opt-out, not off by default. The learning corpus lives in a different AWS account. Any material that crosses goes through one controlled, monitored path.

03

The model learns elsewhere

FinePrint LM learns from licensed attorneys who contributed knowledge, and from lawyers’ answers on work anonymized in the Clean Room, through AnswerLoop. Never from your record. That is the Two-Corpus Rule.

04

Export or delete, any time

Everything is exportable in full, any day, in an open structure. Deletion is immediate in live systems, completes as backups expire. Both are product features, not a support negotiation.

The test: to break one of these, we would have to change the architecture, not our minds. Every exception is an incident.

The Two-Corpus Rule, drawn as two accounts.

From the outside, a model that learns from customer documents and one that doesn’t look the same. So the separation is not a policy inside one system. It is two systems.

Customer side · your company

// AWS account A — one per environment, isolated per tenant

Documents — S3, per-tenant KMS keys, per-document encryption

The record — Postgres, your Legal Room and matters

Retrieval — pgvector, embeddings scoped to your company

Endpoint runs — deterministic rules, your facts, your approvals

Access log — every read of a document, by whom, when

Nothing here is training data. The model reads your record at run time to answer your matter, the way a lawyer reads a file. Reading is not learning.

Learning side · FinePrint LM

// AWS account B — no route to account A’s data stores

Contributed knowledge — playbooks, positions, clause patterns

Rights record — provenance, consent and permitted use per source

AnswerLoop signal — lawyers’ answers: corrections, rankings, redlines, stops

Eval suites — regression, jurisdiction, escalation

Releases — versioned, gated, never a single correction

One narrow bridge, one direction. The only material that crosses from the customer side has been through the Clean Room, and only where the rights to use it exist. Your identity never crosses.

For technical buyers: a written architecture brief (accounts, key management, data flows, the Clean Room pipeline) is available on request. Email security@fineprintai.us and we send the current version.

The Clean Room: what comes off before a reviewer sees anything.

Lawyers score samples of Green work. That is how endpoint quality improves. They do not know whose work it is, because the pipeline removes the company before the artifact leaves.

What is removed

  • Your company. The entity name, trade names, addresses, domains, entity numbers.
  • People. Founders, directors, employees, contractors, signers, and their contact details.
  • Counterparties. The other side of every agreement, their entities and their people.
  • Identifiers. Matter numbers, document ids, account references, filing receipt numbers.
  • Identifying amounts. Figures that would fingerprint a company, generalized to ranges where the legal question doesn’t turn on the number.

What the reviewer is bound to

  • Confidentiality. Contributor terms cover everything they see in review, without expiry.
  • No re-identification. An explicit bar on working out whose matter an artifact came from.
  • No retention. Review happens in the platform. Artifacts are not theirs to keep, copy or reuse.
  • Report, don’t read. If an artifact still carries something identifying, the reviewer flags it and stops.
The residual risk, named. Anonymization is not perfect. An unusual clause or fact pattern could narrow down its source. The bar on re-identification and the generalization of amounts exist because of that risk. Review artifacts stay on the learning side only as long as curation and the regression suites need them, and they never return to any customer context. None of this applies to Yellow or Red: a matter reviewer sees your live matter because you engaged them on it. Who reviews the work

Who can see what.

Where a row says no, there is no product path to it.

WhoYour documents & recordYour live matterAnonymized artifacts
You and your team Yes. Everything, under the roles you set within your company. Yes. Not applicable. Nothing is anonymized for you.
An attorney you engaged The parts the matter needs, scoped to that matter, granted by your approval and logged. Yes, while engaged. Access closes when the matter closes. Not applicable.
A continuous reviewer No. No. Yes. Sampled, with the company removed and re-identification barred.
FinePrint staff No routine access. Support or engineering reach your record only when you ask for help with a specific issue and grant it. Time-boxed, logged, and visible to you. No, unless you grant it for that issue. Only the pipeline that produces them.
FinePrint LM Reads your record at run time to answer your matter. Retrieval is scoped to your company. It is never trained on it. Yes, at run time, for your matter. Trained on these, plus contributed knowledge, under the rights record.
The recorded version. Every read of a document is logged, including ours and an engaged attorney’s. The log is yours, exportable with everything else.

Confidentiality & privilege

Where the software stops and the lawyer starts.

FinePrint is a legal technology company, not a law firm, and does not provide legal advice. Where a matter needs legal judgment, a licensed attorney reviews it or takes it. You engage them, the scope is shown first, and the review is included in your plan.

  • The engagement is yours

    The relationship runs between you and the attorney. We route the matter, build the file and show you the terms. We are not a party to the engagement.

  • Kept separate on purpose

    A matter under engagement is its own record, with its own access grant and its own log. The attorney’s work product on your matter is not read for product purposes, not sampled into review, and not used to improve anything.

  • Continuous review never touches it

    Lawyers score samples of Green work, anonymized in the Clean Room, on the learning side. Engaged matters are never in that stream.

  • Ask your attorney about your facts

    Whether privilege attaches, to what, and in which jurisdiction is a legal question about your situation. The attorney you engaged answers it. We do not answer it on a marketing page.

What we don’t claim.

FinePrint is an early company. What is described above is how the system is built today: encryption in transit and at rest, per-document keys and per-tenant key material, company-scoped retrieval, two separated AWS accounts, access logging, export and permanent deletion.

We hold no third-party security certification today. There is no badge in the footer. An external assurance program is in progress. When it is finished we will name it, date it, and say what it covers, in the trust center below.

If procurement needs an answer before then, email security@fineprintai.us. You will get a written description of where the program stands and what is in place, from a person.

Reporting a vulnerability

If you have found something, we would rather hear it from you than from an incident. Tell us what you found, how to reproduce it, and how to reach you. We will acknowledge it, tell you what we are doing about it, and tell you when it is fixed. Good-faith research is welcome and we will not pursue it. Please don’t access, alter or retain anybody’s data while you look.

The trust center, in one table.

The questions a security review sends first, answered as of August 2026. When a row changes, the table changes.

Hosting & regions Amazon Web Services, United States regions. Two separated accounts: customer data and learning data never share one. This website is served by Netlify.
Subprocessors AWS (infrastructure and storage) · Anthropic (frontier model API) · Voyage AI (legal embeddings) · Clerk (authentication) · Netlify (this website and its request forms). The current list, with what each processes, comes with the DPA — and we notify customers before it changes.
Retention & backups Live data is retained while your subscription runs. Encrypted backups exist for disaster recovery and expire on a short, fixed schedule; deletion removes data from live systems immediately and completes as backups expire. Deleted data is not restored from backup.
Incident response A written incident process with named owners. If an incident affects your data, we notify you without undue delay, tell you what we know, what we are doing, and what we will change. Contact: security@fineprintai.us.
Vulnerability disclosure Report to security@fineprintai.us. We acknowledge, keep you informed, and don’t pursue good-faith research.
DPA & customer terms The customer agreement and data-processing addendum are provided during procurement — ask and we send current drafts, before you commit to anything.
Assurance roadmap No third-party certification held today, and none implied. An external assurance program is in progress; scope and dates will be published here when they are real, not before.

The questions procurement sends.

Do you train on our documents?

No. Your record is read for your matters and is never training data. FinePrint LM learns from knowledge licensed attorneys contributed and from lawyers’ answers on work anonymized in the Clean Room, through AnswerLoop. Customer data and learning data live in two separated AWS accounts.

Where is our data, exactly?

Documents in S3 with per-tenant KMS keys and per-document encryption. The record and its embeddings in Postgres with pgvector, scoped to your company. Both inside the customer-side AWS account, in US regions. Retrieval is scoped before the query is formed.

Can your staff read our documents?

No routine access. When you ask for help with a specific issue, you grant access for it. That access is time-boxed, logged, and visible to you in the access log you can export.

Do you have a security certification we can put in the file?

Not today, and we don’t imply one. An external assurance program is in progress. When it completes we will name it, date it and say what it covers. Until then, email security@fineprintai.us and we will describe what is in place.

What happens if we leave?

Export everything, in full, in an open structure: executed documents with version history, signer lists, fingerprints and the matter each came from, plus your access log. Then delete. Deletion is immediate in live systems, completes as backups expire. If your company is under a legal hold, we raise that before you confirm. Inside the Legal Room

Who is reviewing our work, and can they see us?

A continuous reviewer sees anonymized artifacts and does not know whose work it is. They are bound by contributor terms, including a bar on re-identification. An attorney you engaged on a Yellow or Red matter sees that matter, scoped, logged and closed with the matter. Independence by design

Does using FinePrint give us privilege over everything in it?

That is a legal question about your facts and jurisdiction, and we will not assert it on a website. What we can say is structural: attorney engagements are yours, held as separate records with their own access grants, kept out of the review stream, and never used to improve the product. Ask your engaged attorney how privilege applies to you.

Two corpora. Your record never crosses.

Isolation you can check beats a promise you have to take.

Running a security review? Ask for the architecture brief, the subprocessor list and the draft DPA. We send them in writing.

Request security documentation

Or see the other side of the Two-Corpus Rule: what FinePrint LM is trained on, and what a release has to pass before it ships.

Inside FinePrint LM