Home / Security
Security for documents that cannot leak.
What we protect, how the architecture works and what we cannot yet claim.
How we handle what you send
Customer documents are the files your company submits for analysis: contracts, proposals, amendments, policies and clauses.
Session content is the questions you ask and the answers the platform returns. Answers may derive from submitted documents, but are not the files themselves.
The distinction matters because retention, access and deletion rules apply differently to each, and both are set out in each customer agreement.
Data protection
Encrypted transport between your browser and the platform, and encryption of stored data.
Logical isolation per organization: one company's documents, history and settings are not accessible to another.
Minimal, named internal access, granted on need and revoked when the need ends.
Access and operation logs, protected against tampering.
[Confirm exact parameters with engineering before publication: algorithms, key management, retention periods and log retention.]
Model training
Documents your company submits are not used to train third-party models.
Any use of data for internal improvement depends on express contractual authorization and may be refused without affecting the service.
[Confirm final wording with legal and with model provider agreements.]
The architecture above the model
The platform runs on aiBlue Core, a cognitive governance layer that operates above language models, without modifying weights or depending on a single vendor.
In practice this means three things for security: reasoning follows declared constraints rather than improvisation; output is structured and verifiable rather than free text; and changing the underlying model does not require rewriting the governance rules.
The architecture's principles were designed with reference to recognized AI governance frameworks, including the NIST AI RMF, the EU AI Act and ISO/IEC 42001. Design reference is not certification, and this site claims no audited conformity with any of them.
Where the decision stays human
The platform organizes, surfaces and guides. It does not approve contracts, replace specialized judgment or hold approval authority.
This limit is architectural, not merely contractual: the Advancement Map output is a routing for assessment, always assigned to a human owner.
Certifications and audits
We do not yet hold completed certifications. We would rather say so than imply otherwise.
What we provide today on request: data processing addendum, security addendum with binding obligations, architecture description and answers to vendor questionnaires.
What will be published once completed and audited by an independent third party: certification reports, penetration test summary and the subprocessor list.
Subprocessors and regions
We use infrastructure and model providers strictly necessary to operate the service, under contractual confidentiality and security obligations.
An up-to-date list, with purpose and processing region, is available to customers on request. [Publish the list before launch.]
Incident response
We maintain detection, containment, investigation and communication procedures. Affected customers are notified without undue delay, with what is known, what is still under investigation and the measures taken.
[Define and publish the contractual notification deadline.]
Talk to security
Vendor questionnaires, risk assessments and documentation requests: [security@jurisdify.com].
Vulnerability reports from independent researchers are welcome and handled with priority through the same channel.
Architecture documentation
The aiBlue Core whitepaper, evaluation method and testing protocols are public.