Encryption
Platform data and backups are encrypted at rest. Data sent through external APIs is encrypted in transit, and API access requires authentication.
Security & trust
Heirs’ property work involves personal information, family records, and professional work product. Our platform uses encryption, restricted access, and security monitoring to support the teams handling that information.
The technology platform
Platform matters can include names, addresses, family information, and uploaded records. These safeguards apply to the technology platform.
Platform data and backups are encrypted at rest. Data sent through external APIs is encrypted in transit, and API access requires authentication.
Multifactor authentication and role-based permissions restrict access to platform data. Production access is highly restricted. Client administrators can manage their organization’s users and permissions.
The access model is designed around the user, role, organization, and matter. It is designed to separate organizations’ files and keep community intake participants from accessing attorney work product and communications.
Developers use synthetic data for development and testing, while access to production data remains restricted.
GCP-native intrusion monitoring and detailed API and database logs support security investigations. Audit logging is designed to show who viewed or changed information, what changed, and when.
We maintain written test plans and test logs, conduct vulnerability testing, and perform regular penetration testing. Backup access also requires authentication through restricted administrative controls.
AI and client information
The platform uses Gemini for document parsing and Anthropic models for contextual evaluation of document content.
Extracted facts, research leads, ownership scenarios, and draft documents require professional review. Attorneys and underwriters remain responsible for the decisions within their roles.
Client information is used for AI fine-tuning only with the client organization’s agreement and agreement from the clients it represents.
Client-specific models and improvements remain segregated. Each client’s model is improved using its own data, for its own benefit.
Discuss AI processing, providers, and the permissions applicable to your engagement before onboarding.
Incident response
When a breach is verified, we notify affected parties while the investigation proceeds, then provide updates as the scope and impact become clearer.
Use monitoring and logs to confirm what occurred and begin assessing the impact.
Communicate the confirmed breach while root cause analysis is still underway.
Identify the vulnerability, determine which information is affected, and provide targeted updates.
Address the issue and test the response. Share detailed findings with the appropriate parties involved in resolution.
Data access and continuity
Client data can be made available in separate archives, together with uploaded documents.
At the end of an agreed pilot, any continued platform access is agreed separately. Your organization can receive a final data extract and deletion confirmation for pilot records and uploads.
Confirm export, retention, deletion, and transition arrangements as part of your engagement, including how they apply to backups.
This page describes the technology platform. General website inquiries are sent through HubSpot, as explained in our website privacy notice.
For a Heirship Diligence Report, agree on the channel for transferring records and the handling of matter information before sending the file.
Please keep website forms to general business inquiries. Do not include client names, confidential details, identification numbers, or documents.
Your organization’s review
Contact us about access controls, AI processing, security testing, incident communication, or data handling before a pilot or implementation.