Home Product Security

Your record is yours. Structurally.

Most security pages are a list of adjectives and a badge. This one is a description of where your documents live, who can reach them, what leaves and under what conditions — and a short section on what we don’t claim yet.

The four commitments

Four things, and the architecture that makes them true.

A promise you could break quietly is not a commitment. Each of these is enforced by how the system is built, which is the only version that survives a bad week.

01

Encrypted and company-isolated

Encrypted in transit and at rest, with per-document keys and per-tenant key material in AWS KMS. Isolation is not a filter applied to a shared pile: retrieval is scoped to your company before a query is formed, so there is no query that reaches another company’s record.

02

Never training data

Your documents are retrieved for your matters and are never training material for a shared model. Not opt-out, not off by default — the learning corpus lives in a different AWS account with no path from your record into it.

03

The model learns elsewhere

OpenLegalLM learns from its contributors — licensed attorneys who contributed knowledge on purpose, with rights and provenance — and from Clean-Room-anonymized review material. Never from your record. That is the Two-Corpus Rule.

04

Export or delete, any time

Everything is exportable in full, any day, in an open structure. Deletion is permanent and covers copies and derivatives, not just the file you can see. Neither is a support negotiation; both are product features.

The test we hold ourselves to: if we wanted to break one of these, would we have to change the architecture, or just change our minds? Only the first one counts.

The Two-Corpus Rule — drawn as two accounts.

A model that learns from customer documents and a model that doesn’t look identical from the outside. So the separation is not a policy inside one system. It is two systems.

Customer side · your company

// AWS account A — one per environment, isolated per tenant

Documents — S3, per-tenant KMS keys, per-document encryption

The record — Postgres, your Company Legal Graph and matters

Retrieval — pgvector, embeddings scoped to your company

Endpoint runs — deterministic rules, your facts, your approvals

Access log — every read of a document, by whom, when

Nothing here is training data. The model reads your record at run time to answer your matter, the way a lawyer reads a file — and reading is not learning.

Learning side · OpenLegalLM

// AWS account B — no network path to account A’s data stores

Contributed knowledge — playbooks, positions, clause patterns

Rights record — provenance, consent and permitted use per source

RLLF signal — reviewer corrections, rankings, redlines, escalations

Eval suites — regression, jurisdiction, escalation

Releases — versioned, gated, never a single correction

One narrow bridge, one direction. The only material that crosses from the customer side is output that has been through the Clean Room, and only where the rights to use it exist. Your identity does not make the crossing.

 Customer side (account A)Learning side (account B)
What lives there Your documents, your Company Legal Graph, your matters, your embeddings, your logs. Contributed legal knowledge, anonymized review artifacts, RLLF signal, eval suites, model weights.
Who reaches it You and your team; an attorney you engaged, scoped to that matter; the endpoint runtime. Model engineering and the eval pipeline. No customer identity exists here to reach.
What may cross Only Clean-Room-anonymized review material, only where the rights to use it exist, and only outbound. Nothing crosses back into your record but a released model version — the same one every company runs.
What never crosses Company and counterparty names, people, identifiers, amounts that identify a company, your embeddings, your logs, and any document in its executed form.

The Clean Room — what comes off before a reviewer sees anything.

Continuous review is how endpoint quality improves: licensed attorneys sample green-lane output, score it and flag patterns. They do it without knowing whose work it is, because the pipeline takes the company out before the artifact leaves.

What is removed

  • Your company — the entity name, trade names, addresses, domains, entity numbers.
  • People — founders, directors, employees, contractors, signers, and their contact details.
  • Counterparties — the other side of every agreement, their entities and their people.
  • Identifiers — matter numbers, document ids, account references, filing receipt numbers.
  • Identifying amounts — figures that would fingerprint a company, generalized to ranges where the legal question doesn’t turn on the number.

What is deliberately kept is the part a reviewer needs to judge: the structure of the document, the jurisdiction, the legal posture, the clause language and the choice the endpoint made. A reviewer sees a legal artifact with the facts intact and the company gone.

What the reviewer is bound to

  • Confidentiality — contributor terms covering everything they see in review, without expiry.
  • No re-identification — an explicit bar on attempting to work out whose matter an artifact came from.
  • No retention — review happens in the platform; artifacts are not theirs to keep, copy or reuse.
  • Named accountability — every review is attributable to a named licensed attorney, with a timestamp and a standard version.
  • Report, don’t read — if an artifact still carries something identifying, the obligation is to flag the leak, not to look further.

Anonymization is never claimed to be perfect. That is exactly why the contractual layer sits underneath it — the two are designed to hold together, not to substitute for one another.

And the other lane. None of this applies to Yellow or Red. A matter reviewer sees your live matter because you engaged them on it — conflict-checked, scoped, logged and closed with the matter. The two modes of review

Who can see what.

Written conservatively on purpose. Where a row says no, it means there is no product path to it — not that we would rather not.

WhoYour documents & recordYour live matterAnonymized artifacts
You and your team Yes — everything, under the roles you set within your company. Yes. Not applicable — nothing is anonymized for you.
An attorney you engaged The parts the matter needs, scoped to that matter, granted by your approval and logged. Yes, while engaged. Access closes when the matter closes. Not applicable.
A continuous reviewer No. No. Yes — sampled, with the company removed and re-identification barred.
FinePrint staff No routine access. Support or engineering reach your record only when you ask for help with a specific issue and grant it — time-boxed, logged, and visible to you. No, unless you grant it for that issue. Only the pipeline that produces them.
OpenLegalLM Reads your record at run time to answer your matter. Retrieval is scoped to your company. It is never trained on it. Yes, at run time, for your matter. Trained on these, plus contributed knowledge, under the rights record.
The recorded version. Every read of a document is logged — including ours, including an engaged attorney’s — and the log is yours, exportable with everything else. An access claim you cannot check is just a sentence on a website.

Confidentiality & privilege

Where the software stops and the lawyer starts.

This is the part where vagueness would be convenient, so here it is plainly. FinePrint is a legal technology company. It is not a law firm, it does not practice law, and it does not provide legal advice. Where a matter requires legal judgment, a licensed attorney reviews it or takes it — engaged by you, with the scope shown before any work begins and the review included in your plan.

  • The engagement is yours

    The relationship runs between you and the attorney. We route, we build the file and we show you the terms, but we are not a party to the engagement and we do not sit between you and your counsel as an intermediary who has to be trusted for the relationship to work.

  • Kept separate on purpose

    A matter under engagement is held as its own record, with its own access grant and its own log. The attorney’s work product on your matter lives under that engagement rather than in the general product surface, and it is not read for product purposes, not sampled into review, and not used to improve anything.

  • Continuous review never touches it

    The sampled stream is Clean-Room-anonymized green-lane output on the learning side. It cannot contain a live engaged matter, because engaged matters are not part of that stream at all.

  • Ask your attorney about your facts

    Whether privilege attaches, to what, and in which jurisdiction is a legal question about your specific situation — which makes it exactly the kind of question the attorney you engaged should answer, and exactly the kind we will not answer for you on a marketing page.

What we don’t claim yet.

FinePrint is an early company and this page is written accordingly. What is described above is how the system is built today: encryption in transit and at rest, per-document keys and per-tenant key material, company-scoped retrieval, two separated AWS accounts, access logging, export and permanent deletion.

We hold no third-party security certification today. There is no audit report to hand you, and you will not find a badge in this footer — a security page is a bad place to imply something you have not earned. A formal external assurance program is work in progress; when it is finished we will name it, date it, and say what it covers.

If your procurement process needs an answer before then, ask us. You will get a straight description of where the program stands and what is and isn’t in place — in writing, from a person, rather than a badge.

Reporting a vulnerability

If you have found something, we would rather hear it from you than from an incident. Tell us what you found, how to reproduce it, and how to reach you. We will acknowledge it, tell you what we are doing about it, and tell you when it is fixed. Good-faith research is welcome and we will not pursue it — please don’t access, alter or retain anybody’s data while you look.

The questions procurement actually sends.

Do you train on our documents?

No. Your record is retrieved for your matters and is never training material for a shared model. OpenLegalLM learns from knowledge licensed attorneys contributed on purpose, with rights and provenance, and from Clean-Room-anonymized review material. Customer data and learning data live in two separated AWS accounts that never share one.

Where is our data, exactly?

Documents in S3 with per-tenant KMS keys and per-document encryption; the record and its embeddings in Postgres with pgvector, scoped to your company; both inside the customer-side AWS account. Retrieval is scoped before the query is formed, so there is no cross-company query to get wrong.

Can your staff read our documents?

Not as a matter of course. There is no routine internal browsing of customer records. When you ask for help with a specific issue, you grant access for it; that access is time-boxed, logged, and visible to you in the same access log you can export.

Do you have a security certification we can put in the file?

We do not hold a third-party security certification today and we don’t imply one. An external assurance program is in progress; when it completes we will name it, date it and say what it covers. Until then, ask and we will describe exactly what is in place — the controls above are real, the attestation isn’t there yet.

What happens if we leave?

Export everything, in full, in an open structure — executed documents with version history, signer lists, fingerprints and the matter each came from, plus your access log. Then delete, permanently, including copies and derivatives. Neither one requires a conversation with anybody. Inside the Legal DataRoom

Who is reviewing our work, and can they see us?

A continuous reviewer sees Clean-Room-anonymized artifacts and does not know whose work it is; they are bound by contributor terms including a bar on re-identification. An attorney you engaged on a Yellow or Red matter sees that matter, because you engaged them on it, scoped and logged and closed with the matter. Independence by design

Does using FinePrint give us privilege over everything in it?

That is a legal question about your specific facts and jurisdiction, and it is the sort of thing we will not assert on a website. What we can tell you is structural: attorney engagements are yours, held as separate records with their own access grants, kept out of the review stream, and never used to improve the product. Ask your engaged attorney how privilege applies to your situation.

Two corpora. One of them is never yours.

Isolation you can check beats a promise you have to take.

See where the documents actually land — filed by the endpoint that produced them, with the version, the signers, the fingerprint and the record fields each one proves.

Inside the Legal DataRoom

See the other side of the Two-Corpus Rule: what OpenLegalLM is trained on, how RLLF works, and what a release has to pass before it ships.

Inside OpenLegalLM