← Back to clientlyy.com
Security & Trust
Clientlyy handles attorney–client communications, so how we protect that data
matters. This page describes the controls in place today and where our formal
compliance program stands.
Compliance program status
Clientlyy has not obtained SOC 2 or an equivalent third-party security
attestation. We've engaged Vanta and Workstreet to run a SOC 2 Type II
program — a Trust Center, a complete policy set, a risk assessment,
and an independent penetration test. Kickoff was September 24, 2026, and
Vanta's service begins October 31, 2026. We'll publish our audit report and
Trust Center right here once an independent auditor issues them.
- Agreement signedSep 18, 2026
- Program kickoffSep 24, 2026
- Vanta service beginsOct 31, 2026
Security architecture
- Tenant isolation. Every request is scoped to the signed-in user's firm in application code, which is designed to keep each firm's clients and documents separate from every other firm's.
- Sign-in. Password or Google sign-in, with two-factor authentication (authenticator app) available on every account.
- Roles. Attorney, admin and paralegal roles. Turning on a capability that sends case documents to an AI model is limited to an attorney.
- Encryption. Connections are served over HTTPS only. The disk that holds the database and uploaded documents is encrypted at rest.
- Model egress controls. Case documents are not sent to an AI model until the firm has turned that capability on and the service's checks pass; each document sent is recorded.
- Audit log. Document events, drafts, edits, approvals and sends are recorded on an append-only, hash-chained log that the firm can export.
AI and your data
- We do not use your firm's data to train AI models.
- Client messages go through the review workflow your firm chooses; by default an attorney approves each one before it is sent.
- The AI providers that process customer data are listed on our sub-processor page.
Legal data protections
Reporting a security issue
To report a vulnerability or a suspected security incident, email
mtorre@truth-computing.com.
This page describes current system design and controls and does not constitute a
certification, warranty, or legal advice. It is maintained directly by Clientlyy
while our Vanta-hosted Trust Center is being set up.