Security Your Clients Deserve
ProvaLens is built from the ground up to protect sensitive legal and medical information. HIPAA compliant. Fully encrypted. Audit-logged. We'll sign a BAA before you upload your first document.
HIPAA
Compliant
256-bit
AES Encryption
SOC 2
Azure infrastructure
99.95%
Uptime SLA
BAA
Available
HIPAA Compliance Built In
Law firms handle sensitive client information daily - medical records, financial documents, privileged communications. ProvaLens is designed to meet HIPAA requirements from day one.
Business Associate Agreement
We sign a BAA with every customer during onboarding. No uploads are permitted until the agreement is in place. We take our responsibilities as a business associate seriously.
Complete Audit Logging
Every access to PHI is logged with user, action, timestamp, and IP address. The application only ever appends to the audit log - it has no code path that edits or deletes an entry - and records are retained for 6+ years. Available for compliance reviews on request.
PHI Detection
Documents containing protected health information are automatically detected and flagged. Medical records, insurance documents, and healthcare correspondence receive enhanced protection.
Security & Confidentiality
Law firms trust ProvaLens with highly sensitive case materials. We take that responsibility seriously.
Data Protection
- All documents are encrypted in transit and at rest
- Each firm's data is logically isolated
- Access is restricted to authorized users only
AI Usage & Data Ownership
- Your data is never used to train public or third-party models
- You retain full ownership of all uploaded content
- AI outputs are generated only from your documents
Auditability & Accuracy
- Every answer includes document citations
- If ProvaLens cannot find support in your files, it will not fabricate an answer
- Designed to support attorney review, not replace it
Your Control
- Upload, query, and delete documents at any time
- Export answers and citations for internal use
- Attorneys remain fully responsible for legal judgment
HIPAA & Sensitive Data
ProvaLens is built to handle sensitive records, including medical documentation, with HIPAA-aware safeguards and best practices.
Bottom line: ProvaLens reduces risk — it does not introduce it.
Encrypted In Transit and At Rest
Your data is encrypted at every stage of its journey. From the moment you upload a document to when you view search results, encryption protects your client's information.
In Transit
TLS 1.3 encryption for all data in motion. HTTPS only. No exceptions.
At Rest
AES-256 encryption for all stored documents, database fields, and backups.
Key Management
Azure Key Vault for secure key storage with automatic rotation.
Role-Based Permissions
Full access, user management, billing, integrations
Create matters, upload documents, run AI queries, export reports
View assigned matters, upload documents, basic search
Granular Access Control
Control exactly who can access what. Role-based permissions ensure team members only see the matters they're assigned to. Every firm's data is completely isolated.
Multi-Tenant Isolation - Every read and write is scoped to your firm's ID, and that scope is enforced in the application layer on every query, including document retrieval and AI search.
Secure Authentication
Two-Factor Authentication
Optional 2FA with TOTP apps like Google Authenticator or Authy. Add an extra layer of security.
Session Management
Automatic session timeouts. Secure JWT tokens with short expiration. Refresh token rotation.
Account Lockout
Automatic lockout after failed login attempts. Protection against brute force attacks.
Secure Password Reset
Email verification with time-limited tokens. Password strength requirements.
Enterprise-Grade Infrastructure
ProvaLens runs on Microsoft Azure, a platform trusted by healthcare organizations, financial institutions, and government agencies worldwide.
Azure Cloud
Hosted on Microsoft Azure with HIPAA BAA. SOC 1/2/3 certified data centers. Geographic redundancy for disaster recovery.
Automated Backups
Daily encrypted backups with 30-day retention. Point-in-time recovery available. Backups stored in separate geographic region.
DDoS Protection
Azure DDoS Protection Standard. Web Application Firewall. Rate limiting and bot protection at the edge.
24/7 Monitoring
Real-time infrastructure monitoring. Automatic alerting for anomalies. Auto-scaling to handle load spikes.
AI with Privacy in Mind
We've carefully selected AI partners who take data privacy as seriously as we do. Your documents are never used to train AI models.
Anthropic (Claude)
Called server-side through Anthropic's commercial API, under terms that prohibit training on our data. Anthropic maintains SOC 2 Type II certification. Our HIPAA procedure for this provider is under review. If your matter involves PHI, talk to us before you upload and we will scope it with you.
Azure OpenAI
Microsoft's enterprise AI, running in our Azure subscription and covered by Microsoft's Data Protection Addendum. Prompts and outputs are not used to train Microsoft's or OpenAI's models. A HIPAA-eligible Azure service.
No Training on Your Data
Every provider we use is called through a commercial API whose terms prohibit training on our data. No customer content ever reaches a consumer AI product. Your documents are not deleted after processing - we keep them, and the analysis derived from them, for as long as your account is active.
Your Data, Your Control
Data Export
Export all your data at any time. Documents, metadata, timelines, and research history. Your data belongs to you.
Complete Deletion
Request deletion of any matter or your entire account. Confirmed deletions are scheduled and processed within 30 days across our application database, document storage, and search index. Encrypted backups age out on their own 30-day rotation. Audit logs are retained for compliance.
Retention Policies
Your documents are retained as long as you need them. No automatic purging. When you cancel, you have 90 days to export before deletion.
Security Questions?
Is ProvaLens HIPAA compliant?
Yes. We sign a Business Associate Agreement with every customer. All technical safeguards required by HIPAA are in place, including encryption, access controls, and audit logging.
Where is my data stored?
Your data is stored in Microsoft Azure, in United States regions. Documents, extracted text, and database records are held in Azure, with backups in a separate US Azure region for disaster recovery. Our vector search index runs on a Qdrant instance we operate inside our own Azure subscription (US East 2).
Can I get a copy of your SOC 2 report?
ProvaLens does not hold its own SOC 2 report. Our infrastructure runs on Microsoft Azure, which is SOC 2 Type II certified, and we can provide our security questionnaire responses under NDA.
Is my data used to train AI models?
No. Every AI call is made server-side to commercial APIs whose terms prohibit training on our data, and no customer content is ever sent to a consumer AI product like a public chatbot. Your documents and the analysis built from them are not discarded after processing, though - they stay in your account so the work remains available to you, until you delete them.
What happens if there's a data breach?
We have an incident response plan in place. In the unlikely event of a breach, we will notify affected customers within 72 hours as required by HIPAA and applicable state laws.
Can I do a security review before signing up?
Absolutely. Contact our security team to schedule a review. We're happy to answer your security questionnaire, provide documentation, and discuss our practices in detail.
Ready to Protect Your Client Data?
Start your free trial or schedule a security review with our team.
Questions? Email our security team at security@provalens.ai