myDiscovery

Security

Your confidential data isn't going anywhere it shouldn't — especially not through our AI.

We built myDiscovery around one rule: nothing leaves your case unless you decide it does. Here's exactly what that means — storage, access, and the AI itself.

ENCRYPTED UBS_00018408.pdf
Connection TLS 1.3
Storage AES-256, private
Access link expires in 2:00:00
AI retention zero
Accessible to your case team only

AI analysis security

The part people ask about most.

And the part we're most specific about — not a general privacy policy, but exactly what happens the moment a document is handed to the AI.

Your documents never train the model

AI processing runs under Anthropic's zero-data-retention Data Processing Addendum. Documents are never stored by Anthropic and never used to train AI models — not yours, not anyone else's.

Sensitive identifiers are masked before AI sees them

Every document is automatically scanned for identifiers like Social Security numbers and EINs. Those are masked in what gets sent to the AI — the full, unmasked document stays intact in your case for you to review.

AI never writes anything that goes in front of a judge

There's a public database tracking close to 1,900 court cases where a lawyer got sanctioned over AI-hallucinated citations. We're not that. myDiscovery reads, tags, and organizes documents your client already handed you — it doesn't draft filings. You still do the lawyering.

We operate like the review firms you already use

myDiscovery is a litigation support vendor, the same category as traditional document review firms — not a self-serve AI tool. Every case is processed under a signed Service & Confidentiality Agreement.

Infrastructure & access

The everyday layer, done right.

Encrypted everywhere

Case data sits on encrypted servers. Every connection — to the platform and between our own servers and storage — runs over encrypted (TLS) channels.

Private storage, not public links

Documents live in private cloud storage with no public access. Viewing a file generates a time-limited, single-use secure link, never a permanent public URL.

Two-factor login, role-based access

Every user authenticates with a password plus a one-time email code. Access within a case is role-based — each role sees only what it requires.

Encrypted database

Case information sits in a managed, encrypted database requiring SSL connections. Unencrypted access is not permitted at any layer.

VPN-only staff access

All personnel access client data exclusively over VPN — no exceptions made for convenience.

Protective-order matters

We've handled cases under court-ordered confidentiality and can accommodate the added handling requirements those matters call for.

Plaintiff-side only, always

We never work with opposing counsel or defense-side firms.

There's no scenario where your case data ends up accessible to an adverse party through us. No exceptions, no gray areas.

Every security precaution we know how to take has been taken.

Have a security question specific to your matter? We'll walk you through it directly.

Plaintiff-side only · Invitation required · [email protected]