Security Overview

How Centralize Legal protects firm data. Last updated July 4, 2026.

What we are

Centralize Legal is a retrieval layer between your firm's practice systems (Clio, Microsoft 365, Dropbox) and your AI assistant. We retrieve, filter, and format information you request. We do not run an LLM on your data and we do not use your content to train models.

Data minimization (the trust story)

  • At rest: encrypted OAuth refresh tokens; non-privileged structural metadata in our index (IDs, statuses, dates, counts, file types — never email bodies, filenames, matter titles, or client names); metadata-only audit logs; billing identifiers.
  • In transit: TLS (HTTPS) for all browser and API traffic.
  • Pass-through: when you search or open a file, privileged content may pass through our servers transiently to fulfill your request, then is discarded. We do not cache file bytes or email bodies on disk.

We do not claim "we never see your data." We claim we never retain privileged source content in our database or index.

Permissions & tenant isolation

  • Each user connects their own OAuth accounts; we never use one user's token for another.
  • Every database query is scoped by tenant_id and user_id. Cross-tenant access is rejected.
  • Search results reflect the permissions you already have in Clio, Microsoft 365, and Dropbox.

Encryption & secrets

  • OAuth refresh tokens: envelope encryption (AES-256-GCM per record, tenant-bound AAD) with data encryption keys wrapped by Google Cloud KMS.
  • Secrets and keys are never logged, returned in API responses, or stored in plaintext.
  • Session cookies are sealed via WorkOS AuthKit.

Audit & logging

Audit logs record metadata only: user, firm, tool name, source system, timestamp, status, latency, result count, and error category. They do not contain email bodies, document content, matter names, or tokens.

Outbound reminders

SMS and email reminders are intentionally generic — no client names, matter titles, or privileged details. Users reach their data through their AI assistant, not via links in reminder messages.

Your AI environment (BYO-AI)

Centralize Legal is AI-agnostic. We recommend connecting a business or enterprise-tier AI appropriate for confidential client data. Your firm's relationship with its AI provider is governed by your agreement with that provider. See our Data Processing Agreement and Terms of Service.

Important: Content retrieved via the service is transmitted to the AI environment the Customer connects. That AI provider is a Customer-connected system under the Customer's own agreement, not a Subprocessor of Centralize Legal.

Report a vulnerability

We welcome responsible disclosure from security researchers and customers. Contact security@centralizelegal.com (preferred) or support@centralizelegal.com.

  • Scope: https://centralizelegal.com and subdomains; report only issues affecting Centralize Legal infrastructure — not third-party systems (Clio, Microsoft, Dropbox, your AI provider).
  • Safe harbor: we will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.
  • Response: we aim to acknowledge reports within 5 business days and keep you informed of remediation status.
  • Out of scope: social engineering, physical attacks, denial-of-service, and issues in customer-controlled AI clients or source systems.

Machine-readable contact: /.well-known/security.txt (RFC 9116).

Security testing & assurance

  • Dependency scanning: GitHub Dependabot monitors npm dependencies for known CVEs with automated fix pull requests.
  • Tenant isolation: automated hostile tests plus manual cross-tenant verification (see MVSP Self-Assessment).
  • Log hygiene: production logs are metadata-only; periodic spot-checks for token or privileged payload leaks.

MVSP self-assessment: https://centralizelegal.com/mvsp

Data deletion

  • Disconnect a source: removes that OAuth connection and associated index rows for that connection.
  • Firm account closure: after a 14-day grace period, operational data (connections, index rows, checklists, SMS opt-in fields) is purged. Audit metadata may be retained for compliance.

Details: Data Residency Statement · Privacy Policy

Hosting & subprocessors

Production is hosted in United States — Google Cloud and Railway region us-west1 (Oregon / US West). See the full Subprocessor List.

Compliance posture

We follow MVSP-aligned best practices. We do not hold SOC 2 Type II or ISO 27001 certifications at this time; our architecture minimizes stored data to reduce exposure. We use SOC 2–compliant infrastructure providers (WorkOS, Google Cloud, Stripe) where applicable.

Contact

Security reports: security@centralizelegal.com · General: support@centralizelegal.com

Related: Privacy Policy · Terms of Service · Security Overview · Data Processing Agreement · Subprocessors · Data Residency