01
Encrypted and company-isolated
Encrypted in transit and at rest, with per-document keys and per-tenant key material in AWS KMS. Isolation is structural, not a filter on a shared pile. Retrieval is scoped to your company before a query is formed.
Home Product Security
This page says where your documents live, who can reach them, what leaves and under what conditions, and what we don’t claim.
The four commitments
Each of these is enforced by how the system is built. Each is a control we keep testing.
01
Encrypted in transit and at rest, with per-document keys and per-tenant key material in AWS KMS. Isolation is structural, not a filter on a shared pile. Retrieval is scoped to your company before a query is formed.
02
Your documents are read for your matters and are never training data. Not opt-out, not off by default. The learning corpus lives in a different AWS account. Any material that crosses goes through one controlled, monitored path.
03
FinePrint LM learns from licensed attorneys who contributed knowledge, and from lawyers’ answers on work anonymized in the Clean Room, through AnswerLoop. Never from your record. That is the Two-Corpus Rule.
04
Everything is exportable in full, any day, in an open structure. Deletion is immediate in live systems, completes as backups expire. Both are product features, not a support negotiation.
The test: to break one of these, we would have to change the architecture, not our minds. Every exception is an incident.
From the outside, a model that learns from customer documents and one that doesn’t look the same. So the separation is not a policy inside one system. It is two systems.
// AWS account A — one per environment, isolated per tenant
◆Documents — S3, per-tenant KMS keys, per-document encryption
◆The record — Postgres, your Legal Room and matters
◆Retrieval — pgvector, embeddings scoped to your company
◆Endpoint runs — deterministic rules, your facts, your approvals
◆Access log — every read of a document, by whom, when
Nothing here is training data. The model reads your record at run time to answer your matter, the way a lawyer reads a file. Reading is not learning.
// AWS account B — no route to account A’s data stores
◆Contributed knowledge — playbooks, positions, clause patterns
◆Rights record — provenance, consent and permitted use per source
◆AnswerLoop signal — lawyers’ answers: corrections, rankings, redlines, stops
◆Eval suites — regression, jurisdiction, escalation
◆Releases — versioned, gated, never a single correction
One narrow bridge, one direction. The only material that crosses from the customer side has been through the Clean Room, and only where the rights to use it exist. Your identity never crosses.
Lawyers score samples of Green work. That is how endpoint quality improves. They do not know whose work it is, because the pipeline removes the company before the artifact leaves.
Where a row says no, there is no product path to it.
| Who | Your documents & record | Your live matter | Anonymized artifacts |
|---|---|---|---|
| You and your team | Yes. Everything, under the roles you set within your company. | Yes. | Not applicable. Nothing is anonymized for you. |
| An attorney you engaged | The parts the matter needs, scoped to that matter, granted by your approval and logged. | Yes, while engaged. Access closes when the matter closes. | Not applicable. |
| A continuous reviewer | No. | No. | Yes. Sampled, with the company removed and re-identification barred. |
| FinePrint staff | No routine access. Support or engineering reach your record only when you ask for help with a specific issue and grant it. Time-boxed, logged, and visible to you. | No, unless you grant it for that issue. | Only the pipeline that produces them. |
| FinePrint LM | Reads your record at run time to answer your matter. Retrieval is scoped to your company. It is never trained on it. | Yes, at run time, for your matter. | Trained on these, plus contributed knowledge, under the rights record. |
Confidentiality & privilege
FinePrint is a legal technology company, not a law firm, and does not provide legal advice. Where a matter needs legal judgment, a licensed attorney reviews it or takes it. You engage them, the scope is shown first, and the review is included in your plan.
The relationship runs between you and the attorney. We route the matter, build the file and show you the terms. We are not a party to the engagement.
A matter under engagement is its own record, with its own access grant and its own log. The attorney’s work product on your matter is not read for product purposes, not sampled into review, and not used to improve anything.
Lawyers score samples of Green work, anonymized in the Clean Room, on the learning side. Engaged matters are never in that stream.
Whether privilege attaches, to what, and in which jurisdiction is a legal question about your situation. The attorney you engaged answers it. We do not answer it on a marketing page.
FinePrint is an early company. What is described above is how the system is built today: encryption in transit and at rest, per-document keys and per-tenant key material, company-scoped retrieval, two separated AWS accounts, access logging, export and permanent deletion.
We hold no third-party security certification today. There is no badge in the footer. An external assurance program is in progress. When it is finished we will name it, date it, and say what it covers, in the trust center below.
If procurement needs an answer before then, email security@fineprintai.us. You will get a written description of where the program stands and what is in place, from a person.
If you have found something, we would rather hear it from you than from an incident. Tell us what you found, how to reproduce it, and how to reach you. We will acknowledge it, tell you what we are doing about it, and tell you when it is fixed. Good-faith research is welcome and we will not pursue it. Please don’t access, alter or retain anybody’s data while you look.
The questions a security review sends first, answered as of August 2026. When a row changes, the table changes.
| Hosting & regions | Amazon Web Services, United States regions. Two separated accounts: customer data and learning data never share one. This website is served by Netlify. |
| Subprocessors | AWS (infrastructure and storage) · Anthropic (frontier model API) · Voyage AI (legal embeddings) · Clerk (authentication) · Netlify (this website and its request forms). The current list, with what each processes, comes with the DPA — and we notify customers before it changes. |
| Retention & backups | Live data is retained while your subscription runs. Encrypted backups exist for disaster recovery and expire on a short, fixed schedule; deletion removes data from live systems immediately and completes as backups expire. Deleted data is not restored from backup. |
| Incident response | A written incident process with named owners. If an incident affects your data, we notify you without undue delay, tell you what we know, what we are doing, and what we will change. Contact: security@fineprintai.us. |
| Vulnerability disclosure | Report to security@fineprintai.us. We acknowledge, keep you informed, and don’t pursue good-faith research. |
| DPA & customer terms | The customer agreement and data-processing addendum are provided during procurement — ask and we send current drafts, before you commit to anything. |
| Assurance roadmap | No third-party certification held today, and none implied. An external assurance program is in progress; scope and dates will be published here when they are real, not before. |
No. Your record is read for your matters and is never training data. FinePrint LM learns from knowledge licensed attorneys contributed and from lawyers’ answers on work anonymized in the Clean Room, through AnswerLoop. Customer data and learning data live in two separated AWS accounts.
Documents in S3 with per-tenant KMS keys and per-document encryption. The record and its embeddings in Postgres with pgvector, scoped to your company. Both inside the customer-side AWS account, in US regions. Retrieval is scoped before the query is formed.
No routine access. When you ask for help with a specific issue, you grant access for it. That access is time-boxed, logged, and visible to you in the access log you can export.
Not today, and we don’t imply one. An external assurance program is in progress. When it completes we will name it, date it and say what it covers. Until then, email security@fineprintai.us and we will describe what is in place.
Export everything, in full, in an open structure: executed documents with version history, signer lists, fingerprints and the matter each came from, plus your access log. Then delete. Deletion is immediate in live systems, completes as backups expire. If your company is under a legal hold, we raise that before you confirm. Inside the Legal Room
A continuous reviewer sees anonymized artifacts and does not know whose work it is. They are bound by contributor terms, including a bar on re-identification. An attorney you engaged on a Yellow or Red matter sees that matter, scoped, logged and closed with the matter. Independence by design
That is a legal question about your facts and jurisdiction, and we will not assert it on a website. What we can say is structural: attorney engagements are yours, held as separate records with their own access grants, kept out of the review stream, and never used to improve the product. Ask your engaged attorney how privilege applies to you.
Isolation you can check beats a promise you have to take.
Running a security review? Ask for the architecture brief, the subprocessor list and the draft DPA. We send them in writing.
Request security documentationOr see the other side of the Two-Corpus Rule: what FinePrint LM is trained on, and what a release has to pass before it ships.
Inside FinePrint LM