JurovaBack to the site

Security and privacy

Your clients' words stay yours.

A client intake is the most sensitive thing a firm receives before it has even met the person. This page says, in plain terms, where that information lives, who can see it, what the AI does with it, and what we are still building. Ask us for anything it does not answer.

Where a firm's data lives

Each firm has its own database. Not its own rows in a shared one, its own database.

  • Every firm runs on a separate database project with its own keys, its own storage bucket and its own backups. There is no shared table between firms, so no query, bug or misconfiguration can return one firm's matters to another.
  • Canadian firms are hosted in Canada (Montreal region). US firms are hosted in the United States. A firm can ask for its region before it goes live.
  • Data is encrypted in transit (TLS) and at rest (AES-256). Our database provider, Supabase, publishes SOC 2 Type 2, ISO 27001 and HIPAA compliance.
  • When a firm leaves, its database, its documents and its backups are deleted. There is nothing else to find, because nothing was ever pooled.

Who can see it

The lawyers at the firm, on accounts the firm controls.

  • Every table is protected by row-level security that is enabled and forced, with no client-side policies. The only thing that reads a firm's data is the service running on that firm's own keys.
  • Firm users sign in with individual accounts on an allowlist the firm manages itself. Sessions end after 20 minutes idle and 8 hours regardless.
  • Two-step verification with an authenticator app, per user, and a firm-wide switch that requires it of everyone. The server refuses a session that has not passed the second step; a lost phone is reset by the firm's own admin.
  • Three roles: admins see every matter and manage people and settings; attorneys see and act on the matters assigned to them; staff read what admins read and decide nothing. Every server request is checked against the same table.
  • Sign in with the Google or Microsoft account the firm already has, per firm; the allowlist still decides who gets in. A firm's own identity provider (SAML) is available on request.
  • Every decision a lawyer makes is stamped with who made it and when. The attorney outranks the AI: no message reaches a client unless someone at the firm pressed a button.
  • Jurova's own staff access is limited to operating and supporting the service. We do not read matters for any other purpose.

What the AI sees, and what it does not

The AI writes the case memo. It never decides anything and it never learns from your clients.

  • What is sent to the model: the client's account of their matter and the questions the intake asked. What is never sent: passwords, keys, or anything the firm typed into its own settings.
  • Today the memo is written by OpenAI's API, with Google's Gemini API as a fallback if OpenAI is unavailable. Both providers state in their published terms that data sent through their APIs is not used to train their models.
  • OpenAI states it retains API inputs and outputs for abuse monitoring for up to 30 days, then deletes them. We do not opt in to any data-sharing program with any provider.
  • A firm's own grading rules and its intake pillars are stored in the firm's database and are never shared with another firm or used to train anything.

The client's consent, recorded

Nobody reaches the intake without proving who they are, and nobody is contacted without saying yes.

  • Every client verifies a code sent to their phone before they can tell their story.
  • Consent to be contacted about the inquiry is a separate, unchecked box, and the exact wording the client agreed to is recorded with the time, the language and the version.
  • STOP in reply to any text stops every text to that number, firm-wide, immediately. Nothing sends before 8 am or after 8 pm in the client's own time zone.
  • Follow-ups after a matter concludes are a second, optional consent. They are never bundled with the required one.

Backups and uptime

A backup nobody has restored is a hope. Ours are restored every night.

  • Every firm's database and documents are backed up nightly to a second vendor, Cloudflare R2, separate from the database provider.
  • Every night the backup is pulled back out and checked row by row against a receipt taken at dump time. Only a full pass counts.
  • An independent watchdog probes every firm's intake, portal and health endpoint every 10 minutes and alerts us, and it alarms separately if a night passes without a verified backup.
  • Nothing scheduled runs on a laptop. Every job runs in the cloud, from code, with its own key.

Who we rely on

The vendors under Jurova, and what each one holds

VendorWhat it does for a firmWhat it publishes
SupabaseDatabase, file storage, firm loginsSOC 2 Type 2, ISO 27001, HIPAA, per its published security page. One project per firm.
CloudflareHosting, DNS, backup storagePublishes its certifications and reports in its Trust Hub.
OpenAIWrites the case memoAPI data not used to train models; abuse-monitoring logs kept up to 30 days, per its published data-usage page.
Google (Gemini API)Fallback model onlyPaid API prompts and responses are not used to improve Google's products, per its published terms.
TwilioPhone verification and text messagesISO/IEC 27001, per its Trust Center.
ResendEmail delivery, from the firm's own domainSOC 2 Type II; encryption at rest (AES-256) and in transit (TLS 1.3), per its security page.

Vendor statements are quoted from each vendor's own published pages as of September 2026. Booking links belong to the firm's own scheduling tool; Jurova only carries the link.

What we are still building

We would rather you hear these from us. Each is on the roadmap, in this order.

  • A zero-data-retention configuration with our AI provider, and in-country model hosting for firms that require it.
  • An independent penetration test.
  • A SOC 2 report of our own.
  • Client-side encryption of backups before they leave the database provider.

Questions, questionnaires, agreements

If your firm has a vendor security questionnaire, a data processing agreement, or a question this page did not answer, send it to us. We answer in writing, and we will tell you plainly when the answer is "not yet".

info@jurova.ai