Security
Your confidential data isn't going anywhere it shouldn't — especially not through our AI.
We built myDiscovery around one rule: nothing leaves your case unless you decide it does. Here's exactly what that means — storage, access, and the AI itself.
AI analysis security
The part people ask about most.
And the part we're most specific about — not a general privacy policy, but exactly what happens the moment a document is handed to the AI.
Your documents never train the model
AI processing runs under Anthropic's zero-data-retention Data Processing Addendum. Documents are never stored by Anthropic and never used to train AI models — not yours, not anyone else's.
Sensitive identifiers are masked before AI sees them
Every document is automatically scanned for identifiers like Social Security numbers and EINs. Those are masked in what gets sent to the AI — the full, unmasked document stays intact in your case for you to review.
AI never writes anything that goes in front of a judge
There's a public database tracking close to 1,900 court cases where a lawyer got sanctioned over AI-hallucinated citations. We're not that. myDiscovery reads, tags, and organizes documents your client already handed you — it doesn't draft filings. You still do the lawyering.
We operate like the review firms you already use
myDiscovery is a litigation support vendor, the same category as traditional document review firms — not a self-serve AI tool. Every case is processed under a signed Service & Confidentiality Agreement.
Infrastructure & access
The everyday layer, done right.
Encrypted everywhere
Case data sits on encrypted servers. Every connection — to the platform and between our own servers and storage — runs over encrypted (TLS) channels.
Private storage, not public links
Documents live in private cloud storage with no public access. Viewing a file generates a time-limited, single-use secure link, never a permanent public URL.
Two-factor login, role-based access
Every user authenticates with a password plus a one-time email code. Access within a case is role-based — each role sees only what it requires.
Encrypted database
Case information sits in a managed, encrypted database requiring SSL connections. Unencrypted access is not permitted at any layer.
VPN-only staff access
All personnel access client data exclusively over VPN — no exceptions made for convenience.
Protective-order matters
We've handled cases under court-ordered confidentiality and can accommodate the added handling requirements those matters call for.
Plaintiff-side only, always
We never work with opposing counsel or defense-side firms.
There's no scenario where your case data ends up accessible to an adverse party through us. No exceptions, no gray areas.
Every security precaution we know how to take has been taken.
Have a security question specific to your matter? We'll walk you through it directly.
Plaintiff-side only · Invitation required · [email protected]
