Security and data protection

Your client files stay on your device

Privileged matter content is stored in your browser and on your firm's own devices — never transferred to or stored on our servers, and we have no technical access to your client files.

Browser requirement. Automatic storage of case files on your device requires Chrome, Edge, Brave or Arc — on Windows or macOS. Safari and Firefox can run Avantwerk, but cannot keep case files on your device automatically; there, the app asks you to save a backup file instead.

Encrypted on the device — AES-256-GCM

Session data is sealed with AES-256-GCM in your browser; the wrapping key is unique to your firm and never leaves the device, including any AI-provider key on the Enterprise BYOK plan.

The privilege boundary is enforced

Every file is classified before any outbound action. Under UK legal professional privilege this is a confirm-first warning; where professional secrecy is non-waivable it is an absolute hard block against the AI provider, CRM, e-signature and outbound email.

Prompt injection — what the product does, and what it does not

A document sent by an opponent or a client can contain text intended to read to an AI not as content but as an instruction — phrases such as "ignore your previous instructions", "TO THE AI:", or "reveal your system prompt". The material most likely to carry such an attempt is the material you did not produce: the other side's statement, a counter-party's contract, a client's upload from a third party. Solicitors processing those documents have, until recently, had no reason to know the risk existed.

The primary protection is delimiter wrapping. Every piece of untrusted text that reaches the model — client documents, transcripts, matter context, opposing-party correspondence — is enclosed in single-use markers generated fresh for each request in your browser. The markers carry a twelve-character random value created at the moment of the request; an attacker cannot know it in advance and cannot write text that appears to close the block early. Within the markers, an instruction in plain English states that everything enclosed is data to be analysed, not a command to obey. This wrapping runs at twelve call sites across the product: the scrutineer, evidence analysis, retrieval grounding, risk proposals, the review grid, intake fact-extraction, and the compliance playbook.

A detector also flags recognisable attempts. The product scans incoming text against twenty patterns across the five languages it serves, in both the familiar and the formal register — because a letter from opposing counsel is drafted formally. When a pattern is identified, you are told in three places: a banner above the chat composer as you type or paste; a flag on each affected document in the evidence list; and a notice in the client-update modal.

What the detector does not catch. The detector recognises crude, obvious attempts only. It is not a full classifier. A subtly phrased or novel attempt may pass undetected. The delimiter wrapping is the protection; the detector is an alert layer for the patterns it knows. A solicitor with reason to believe a document was constructed to manipulate an AI tool should treat it with the same adversarial caution applied to any document from the other side — and should consider obtaining and processing a verified copy through separate means before placing weight on AI analysis of it.

For the purposes of the SRA Code of Conduct, competent use of an AI tool includes understanding its limitations as well as its capabilities. Legal professional privilege attaches to the advice a solicitor gives and the work product they prepare; it does not prevent an opposing party from attempting to influence the analysis of documents submitted to a tool.

Dictation — transcription runs on your machine

Speech dictated into the product is converted to text by a model running inside your browser. There is no network call in the transcription path: your audio is not transmitted to any server, and the product has no speech-to-text sub-processor. The microphone is opened by the browser with your permission; the audio is held in memory and discarded once the text is produced.

The model file is fetched once, then cached. On first use, the product downloads the model file from a public model repository (huggingface.co) over ordinary HTTPS — 238 MB for the Standard model or 724 MB for the High Accuracy model. After that, dictation works with no internet connection. The audio itself is not part of that download; what downloads is the recognition software, not your speech. Clearing your browser's cached storage removes the model; it re-fetches on next use.

No account, no key, no third-party involvement in transcription. No API key, third-party account or subscription is required, and no per-minute or per-character charge is incurred. Because transcription runs entirely on the device, there is no sub-processor for speech-to-text purposes — a material distinction for any firm reviewing its controller-processor chain under UK GDPR Article 28. Where a solicitor dictates advice or correspondence covered by legal professional privilege, the product does not create any additional route by which that audio could reach an external party.

Read what was transcribed before using it. Automated transcription is an aid, not a final record. Accuracy varies with audio quality, microphone characteristics, technical vocabulary and speaker conditions; no accuracy figure is stated or warranted. For the purposes of the SRA Code of Conduct, competent use of an AI-assisted feature includes verifying its output before placing weight on it: the transcription should be read and corrected before the text enters any draft, note or client communication.

Your data does not train the model

Matter content sent to the AI is used only to answer your request and is never retained to train models — by us or by our AI provider. On the managed plan the AI provider is our named sub-processor; on Enterprise BYOK the key and contract are your own.

Hosted in the EU — Germany

The platform is hosted entirely in the European Union (Germany); any international transfer is listed with its safeguard in the sub-processor register.

Sub-processor register

Every third party that could touch data is named in our register — purpose, location, data category and transfer safeguard, in line with UK GDPR Article 28.

Sub-processorLocationTransfer
Hetzner Online GmbHDE (EU)
Anthropic PBCUSIDTA / UK Addendum
HighLevel Inc.USIDTA / UK Addendum
Documenso (self-hosted)DE (EU)
Stripe Inc.USIDTA / UK Addendum
Mailgun (Sinch)USIDTA / UK Addendum
Twilio Inc.USIDTA / UK Addendum
Google Ireland Ltd (GA4)IE (EU)IDTA / UK Addendum + DPF
Google Ireland Ltd (Google Workspace / Gmail)IE (EU)IDTA / UK Addendum + DPF
Microsoft Ireland Operations Ltd (Microsoft 365 / OneDrive)IE (EU)IDTA / UK Addendum + DPF
OpenAI, L.L.C. — AI provider, BYOK — plannedUSIDTA / UK Addendum
Google Ireland Ltd — Gemini API — AI provider, BYOK — plannedIE (EU)IDTA / UK Addendum + DPF
Microsoft Ireland Operations Ltd — Azure OpenAI Service — AI provider, BYOK — plannedRegion chosen by the firmIDTA unless the firm confirms an EU region
Amazon Web Services EMEA SARL — Amazon Bedrock (EU region) — AI provider, managed key — liveEU/EEANone — inference stays in the EEA

Infrastructure providers (no customer personal data processed): Gitea (self-hosted source-code repository, our VPS), Let's Encrypt (TLS certificate authority), Cloudflare Inc. (DNS resolution only — traffic does not pass through Cloudflare). These are not sub-processors within the meaning of UK GDPR Art. 28.

Authenticated access with mandatory MFA

Access is governed by a separate authentication layer, and multi-factor authentication is mandatory on every administrative console.

What we do not yet claim

We do not hold certifications we have not earned: independent ISO 27001 certification is planned for Q4 2026; until then we describe our current controls transparently, with open items identified.

Data protection and security channel

To exercise your rights as a data subject, report a security concern, or raise any data-protection question, contact us. legal@avantwerk.com