CounselorAI handles case files, medical records and protected health information. This page is the full description of how that data is protected — the controls, where it lives, and what we sign before we touch PHI. It is written to be forwarded to whoever at your firm reviews vendors.
Access control
Role-based access control (RBAC). Attorneys, paralegals and intake coordinators work the same case at different permission levels, scoped per case. SSO with Google Workspace, Microsoft 365 and Okta. MFA required. Idle session timeout is configurable per firm.
Access to case data is restricted to authorized users in your firm with appropriate role permissions, and to CounselorAI engineers under audit-logged access — only for support requests you initiate or critical security and availability investigations. We do not allow third-party vendor access to client case data.
Audit logging
Comprehensive audit logging with user attribution and timestamps. Every entered field, every AI extraction, every override and every access event is logged and queryable for compliance review.
Pre-draft corrections require a mandatory reason note, and the original value is preserved alongside the corrected one — so the record shows how each value was reached, not just where it landed. Audit logs export on demand.
Encryption
Encryption at rest and in transit — AES-256, TLS 1.3.
Data isolation
Per-firm encryption keys and data isolation. Tenant-level scoping at the case, user and firm level: your firm’s case data is invisible to every other firm on the platform.
Your data is never used to train shared models. Where the platform improves on your firm’s settlement outcomes, that improvement is scoped to your firm’s predictions and does not reach any other firm.
Infrastructure
Hosted on AWS in the United States. Standard cloud infrastructure rather than a proprietary stack, which also means your data can be exported or migrated out — case data, demand letters, negotiation histories and audit logs, in PDF, JSON and CSV — rather than stranded.
PHI and BAAs
BAA signed before access to any PHI. Personal injury work involves protected health information at every step — medical records, treatment histories, billing — so the business associate agreement is signed as standard before any PHI reaches the platform, not negotiated afterward.
Security questionnaires
We complete vendor security questionnaires as part of procurement. Send yours — or any architecture question your IT, security or compliance team has — to [email protected] and we will work through it with them.