Law firms run on trust and confidentiality. Parker is engineered so your client data stays private, isolated, and under your control at every step. Here is how we protect it.
On this page
1. Encryption everywhere
- In transit: all traffic to and from Parker is encrypted with TLS 1.2+.
- At rest: customer content and backups are encrypted using AES-256.
- Secrets & keys are stored in a managed key-management service with strict rotation and access policies.
2. Access controls
- Least privilege. Access to systems and data is granted on a need-to-know basis and reviewed regularly.
- Authentication. Single sign-on (SSO) and multi-factor authentication are supported for firm accounts.
- Role-based permissions. Administrators control who at your firm can see and act on which matters.
- Audit logs. Sensitive actions are logged so you have a record of who did what.
3. Data isolation
Every firm runs on its own dedicated, isolated instance — not a shared multi-tenant pool — so one customer can never access another's content, matters, or credentials. Each firm's secrets are encrypted with a firm-scoped key, and Parker only accesses the integrations and scopes you explicitly authorize, and only for the tasks you direct.
Your customer content is yours. We do not sell it, we do not use it for advertising, and we do not use it to train general-purpose AI models.
4. Responsible AI
- No training on your content. We use enterprise AI providers under agreements that prohibit training on the data we send for inference.
- Human in the loop. Parker produces drafts and work product for attorney review — a licensed professional stays responsible for every filing and decision.
- Scoped processing. Only the content needed for a given task is sent to a model to complete that task.
5. Infrastructure
Parker runs on leading cloud infrastructure with hardened, redundant environments. We separate development, staging, and production; automate configuration; and apply security patches promptly. Regular encrypted backups support recovery.
6. Monitoring & incident response
We continuously monitor for anomalous activity and maintain a documented incident-response plan. If an incident affects your data, we will investigate, contain it, and notify affected customers without undue delay in line with our obligations and your customer agreement.
7. People & process
- Employees complete security and confidentiality training and are bound by confidentiality obligations.
- Access to production data is limited to personnel who need it and is logged.
- We follow secure development practices, including code review and dependency scanning.
8. Compliance
We build to align with the expectations of firms handling privileged and regulated data, and we design our controls with frameworks such as SOC 2 in mind. For current certifications, subprocessor lists, or to request a Data Processing Addendum, contact [email protected].
9. Report a vulnerability
We welcome responsible disclosure. If you believe you have found a security issue, please email [email protected] with details so we can investigate. Please give us a reasonable window to remediate before any public disclosure.