Current
Users authenticate through Clerk and work within an active organization. Protected pages and APIs check the session and organization rather than relying on navigation alone.
- Organization roles and product entitlements limit administrative, billing, export, and paid-product actions.
- Customer and billing records are separated from the shared legal-source corpus through independent database boundaries and credentials.
- Customer records are scoped to the active organization; server-owned identity fields come from the authenticated request.
- Signed Clerk and Stripe webhooks are verified before identity or entitlement state changes.
- Customer inputs are constrained by field, type, and length before persistence.
- Secrets and provider credentials are supplied through the deployment environment rather than client-side code.
Practice updates preserve source links and identify the underlying authority. Proposed-update records support organization scoping, history, review state, and soft deletion where the workflow requires it.
Proposed updates are not treated as approved client communications. Review and approval remain separate actions performed by an authorized user, and sharing or publishing remains a separate team decision.
Configurable
Clerk provides identity and organization membership. Stripe provides payment and subscription services. Infrastructure, database, communications, and AI providers depend on the deployment.
Provider, retention, confidentiality, data-residency, and procurement requirements should be documented in the applicable order and deployment configuration. We address the current provider set and available contractual controls during security review.
Planned
A deployment-specific subprocessor register, retention and deletion schedule, and security-evidence package are pilot-readiness work. They are not represented as currently available until the applicable documents and controls are verified.
Open requirements receive an owner and status during pilot review. A roadmap item is not a contractual commitment unless it appears in the applicable agreement.
Not currently offered or claimed
This page does not claim a certification, service level, recovery objective, enterprise identity feature, customer-managed encryption key, audit-logging capability, or contractual commitment that has not been confirmed for the applicable deployment.
Current subprocessors, deployment-specific controls, retention and deletion terms, and contractual commitments are provided only when current and applicable. Open requirements are treated as decisions to resolve, not as marketing claims.
Customer responsibilities
- Keep organization membership, roles, and billing administrators current.
- Use available strong-authentication controls and protect account credentials.
- Review professional, client, privilege, and data-residency requirements before submitting content.
- Verify authorities, citations, dates, and generated conclusions before use.
- Report suspected account compromise or data exposure promptly.
Security review and reporting
To report a suspected vulnerability or request current security documentation, email hello@ofcounsel.ai. Include a concise description and a safe way to reproduce the issue. Do not access another customer’s data or degrade the service while testing.
We will distinguish controls available now from deployment choices and unresolved requirements during the review.