Your contracts are confidential. We take that seriously.

Clausebeam is built with data security practices appropriate for legal document handling.

How uploaded contracts are handled

Encryption in transit and at rest
All document uploads travel over TLS. Documents stored at rest are encrypted using AES-256. Keys are managed with restricted-access controls.
No training on customer data
Uploaded contracts are used only to generate your flag report. We do not use your documents to train or improve our detection model.
Document retention policy
Uploaded documents are retained for 90 days after the flag report is generated, then deleted. You can request immediate deletion at any time.
Access controls
Documents are isolated by organization. Clausebeam staff access to uploaded documents requires explicit authorization and is logged for audit purposes.

Who can access your documents

Data isolation is enforced at the organization level. Documents uploaded by one organization are never accessible to users of another organization.

Organization isolation
Each organization's documents exist in a separate, isolated data store. Cross-organization access is architecturally prevented.
Deletion controls
Request deletion of any uploaded document at any time via your account or by emailing [email protected]. We confirm deletion within 5 business days.
Least-privilege access
Internal access to customer data follows the principle of least privilege. Only personnel who require access to perform their role have it.

Data flow summary

Upload → TLS encrypted transfer
Analysis → isolated org store
Flag report → delivered to you
Document → deleted at 90 days

Designed with attorney-client privilege in mind

Law firms and in-house legal teams operate under professional responsibility rules that constrain how client documents can be handled. We designed Clausebeam's data handling to support those obligations, not work against them.

Clausebeam does not store or transmit uploaded documents to third-party AI providers. Analysis runs within isolated compute environments. Your documents do not leave the analysis pipeline and are not used outside the scope of generating your flag report.

Isolated analysis pipeline
Document processing runs in isolated compute environments. Analysis results are returned only to the uploading organization. No cross-organization data exposure by design.
Data processing agreement
Firm plan customers can request a Data Processing Agreement that formally documents our data handling obligations. Contact [email protected] to request one.
Honest about certification status
We do not claim SOC 2 certification or HIPAA compliance. We describe our actual practices. A formal certification audit is on our roadmap. If your firm requires specific compliance documentation before use, contact us to discuss your requirements.

Questions about data handling?

For data questions, deletion requests, security concerns, or to request a Data Processing Agreement:

[email protected]

We respond to security-related inquiries within 2 business days.