Neptune Data / Security

Built like the confidential practice it serves.

Law-firm data deserves law-firm caution. Neptune is designed so one firm can never see another, so sign-ins are verified, so activity is accountable — and so your reviewers stay in charge of every output.

Tenant isolation

Your firm's workspace is yours alone

A subdomain per firm

Every firm signs in at its own address. Sessions are scoped to that host — a session at one firm is meaningless at another.

Data keyed to the firm

Every record, extraction, conversation and file is keyed to your firm and your matters at the data layer — isolation isn't a filter, it's the schema.

Access follows the engagement

Users see the clients they're granted, and matters inherit from the client. Platform administration is separated from firm-facing accounts entirely.

Protection

Encrypted, verified, accountable

Encryption throughout

TLS for every connection; storage encrypted at rest; credentials and API keys additionally encrypted at the application layer.

Verified sign-ins

New devices confirm by email code. Password resets are single-use and time-boxed. Repeated failures lock the account.

Session discipline

Host-scoped session cookies, CSRF protection on every form, strict security headers and content-security policy across the app.

Role-based control

Firm admins manage users, applications, client access and the firm's AI configuration. Members get exactly what they're granted.

Audit trails

Sign-ins, uploads, extraction runs, administrative changes — logged with who, what and when, and reviewable by your admins.

Resilient operations

Managed cloud infrastructure with encrypted databases and durable object storage; interrupted work recovers safely rather than hanging.

AI data handling

Your documents make your outputs. Nothing else.

  • Your own model agreement. Documents are processed with Anthropic's Claude under your firm's own API key and terms — you hold the contractual relationship for your data.
  • No training on your content. The model provider's API terms do not use customer content to train models, and Neptune never sells or shares your data.
  • Purpose-bound processing. Documents are sent for the extraction or analysis you requested, and the results come back to your workspace — that's the whole loop.
  • Support access, limited and logged. Neptune staff access is restricted to platform operation and support, and it leaves a trail.

On AI, plainly

Neptune Data applications use large language models, and language models can make mistakes. Every output is a draft for professional review — with lineage tools built in so that review is fast — and nothing the platform produces is legal or tax advice. Your qualified reviewers remain responsible for the final work product, and the product is designed to make that responsibility easy to exercise: sources one click away, arithmetic shown, corrections remembered.

Shared responsibility

What we ask of your firm

Good security is a partnership. Your admins control who's invited, which applications and clients they can reach, and when access ends. Before uploading, confirm you have the client consents your engagement requires — the platform ships with the disclaimers and acknowledgments to make that discipline routine.

Can we get a copy of our data?

Yes — records can be exported in bulk from the records room, and workbooks and abstracts download in standard formats. Ask us about full-workspace export as part of your engagement terms.

What happens when a matter ends?

Matters can be closed or deleted by your admins. Deletion removes the matter's records, extracted data and outputs from the workspace, including stored files.

Where is the infrastructure hosted?

On managed AWS infrastructure in the United States, with encrypted databases and durable object storage. Ask for the current architecture overview in a security review.

Will you complete our security questionnaire?

Yes. We're a young platform and we'd rather show you exactly what exists than wave at a badge wall — send the questionnaire and we'll answer it directly.

Diligence welcome

Put us through your security review.

We'll walk your team through the architecture, honestly.

Start a security review