Neptune Data / Security
Law-firm data deserves law-firm caution. Neptune is designed so one firm can never see another, so sign-ins are verified, so activity is accountable — and so your reviewers stay in charge of every output.
Tenant isolation
Every firm signs in at its own address. Sessions are scoped to that host — a session at one firm is meaningless at another.
Every record, extraction, conversation and file is keyed to your firm and your matters at the data layer — isolation isn't a filter, it's the schema.
Users see the clients they're granted, and matters inherit from the client. Platform administration is separated from firm-facing accounts entirely.
Protection
TLS for every connection; storage encrypted at rest; credentials and API keys additionally encrypted at the application layer.
New devices confirm by email code. Password resets are single-use and time-boxed. Repeated failures lock the account.
Host-scoped session cookies, CSRF protection on every form, strict security headers and content-security policy across the app.
Firm admins manage users, applications, client access and the firm's AI configuration. Members get exactly what they're granted.
Sign-ins, uploads, extraction runs, administrative changes — logged with who, what and when, and reviewable by your admins.
Managed cloud infrastructure with encrypted databases and durable object storage; interrupted work recovers safely rather than hanging.
AI data handling
Neptune Data applications use large language models, and language models can make mistakes. Every output is a draft for professional review — with lineage tools built in so that review is fast — and nothing the platform produces is legal or tax advice. Your qualified reviewers remain responsible for the final work product, and the product is designed to make that responsibility easy to exercise: sources one click away, arithmetic shown, corrections remembered.
Good security is a partnership. Your admins control who's invited, which applications and clients they can reach, and when access ends. Before uploading, confirm you have the client consents your engagement requires — the platform ships with the disclaimers and acknowledgments to make that discipline routine.
Yes — records can be exported in bulk from the records room, and workbooks and abstracts download in standard formats. Ask us about full-workspace export as part of your engagement terms.
Matters can be closed or deleted by your admins. Deletion removes the matter's records, extracted data and outputs from the workspace, including stored files.
On managed AWS infrastructure in the United States, with encrypted databases and durable object storage. Ask for the current architecture overview in a security review.
Yes. We're a young platform and we'd rather show you exactly what exists than wave at a badge wall — send the questionnaire and we'll answer it directly.
Diligence welcome
We'll walk your team through the architecture, honestly.
Start a security review