Security

Built for the confidentiality demands of legal work.

Client data is privileged. Qanooni is engineered, certified and operated to protect it, and your data is never used to train a model.

Independently certified

Audited to the standards enterprise legal teams require.

SOC 2 Type II
Independently audited controls
ISO 27001
Certified information-security management
GDPR
Compliant data protection & privacy
Per-firm isolation
Your data, walled off from every other firm
How we protect your data

Privacy and control, by design.

Never trained on your data

Qanooni references your documents through retrieval, at the moment of use. Your content is never used to train a model, ours or anyone else's.

Per-firm isolation

Every firm's data is logically isolated. Your matters, precedents and knowledge are accessible only to your firm, never pooled or shared.

Encrypted in transit and at rest

Your data is encrypted in transit and at rest, on enterprise-grade cloud infrastructure.

Least-privilege access

Role-based access, single sign-on, and full audit logging across the platform, so only the right people see the right matters.

You own your data

Your matter graph and everything in it is your intellectual property. Export or delete it whenever you choose.

Model-agnostic

Qanooni is independent of any single AI provider. The model underneath can change without moving your data or your firm's knowledge.

How your data is used

Referenced at the moment of use. Never trained on. Never shared.

Qanooni connects securely to the systems your firm already runs on and references your documents through retrieval when you ask. The same grounding is what stops it inventing case law. Nothing is used to train a model, and no firm's data is ever visible to another. Your knowledge stays in your isolated matter graph, owned by you.

Security FAQ

The questions security teams ask.

Do you train any AI model on our data?+

No. Qanooni references your documents and precedents through retrieval at the moment of use. Your data is never used to train a model, and it is never shared with other firms.

Who can access our data?+

Only your firm. Data is logically isolated per firm, protected by role-based access controls and single sign-on, with all access logged.

Where is our data stored, and is it encrypted?+

Your data is hosted on enterprise-grade cloud infrastructure and encrypted both in transit and at rest.

Can we export or delete our data?+

Yes. Your matter graph and its contents are your intellectual property. You can export or permanently delete your data at any time.

What certifications does Qanooni hold?+

SOC 2 Type II, ISO 27001, and GDPR compliance, with per-firm isolation across the platform. Our security documentation is available on request.

What happens when you change the underlying AI model?+

Qanooni is model-agnostic. We can change the model underneath without moving your data; your firm's knowledge stays in your matter graph.

Security questions? Bring them.

Request our security documentation or talk to our team about your firm's requirements.