Loading...

Loading...

Security Your Clients Deserve

ProvaLens is built from the ground up to protect sensitive legal and medical information. HIPAA compliant. Fully encrypted. Audit-logged. We'll sign a BAA before you upload your first document.

HIPAA

Compliant

256-bit

AES Encryption

SOC 2

Azure infrastructure

99.95%

Uptime SLA

BAA

Available

HIPAA Compliance Built In

Law firms handle sensitive client information daily - medical records, financial documents, privileged communications. ProvaLens is designed to meet HIPAA requirements from day one.

Business Associate Agreement

We sign a BAA with every customer during onboarding. No uploads are permitted until the agreement is in place. We take our responsibilities as a business associate seriously.

Complete Audit Logging

Every access to PHI is logged with user, action, timestamp, and IP address. The application only ever appends to the audit log - it has no code path that edits or deletes an entry - and records are retained for 6+ years. Available for compliance reviews on request.

PHI Detection

Documents containing protected health information are automatically detected and flagged. Medical records, insurance documents, and healthcare correspondence receive enhanced protection.

Security & Confidentiality

Law firms trust ProvaLens with highly sensitive case materials. We take that responsibility seriously.

Data Protection

  • All documents are encrypted in transit and at rest
  • Each firm's data is logically isolated
  • Access is restricted to authorized users only

AI Usage & Data Ownership

  • Your data is never used to train public or third-party models
  • You retain full ownership of all uploaded content
  • AI outputs are generated only from your documents

Auditability & Accuracy

  • Every answer includes document citations
  • If ProvaLens cannot find support in your files, it will not fabricate an answer
  • Designed to support attorney review, not replace it

Your Control

  • Upload, query, and delete documents at any time
  • Export answers and citations for internal use
  • Attorneys remain fully responsible for legal judgment

HIPAA & Sensitive Data

ProvaLens is built to handle sensitive records, including medical documentation, with HIPAA-aware safeguards and best practices.

Bottom line: ProvaLens reduces risk — it does not introduce it.

Encrypted In Transit and At Rest

Your data is encrypted at every stage of its journey. From the moment you upload a document to when you view search results, encryption protects your client's information.

In Transit

TLS 1.3 encryption for all data in motion. HTTPS only. No exceptions.

At Rest

AES-256 encryption for all stored documents, database fields, and backups.

Key Management

Azure Key Vault for secure key storage with automatic rotation.

Role-Based Permissions

Admin

Full access, user management, billing, integrations

Attorney

Create matters, upload documents, run AI queries, export reports

Paralegal

View assigned matters, upload documents, basic search

Granular Access Control

Control exactly who can access what. Role-based permissions ensure team members only see the matters they're assigned to. Every firm's data is completely isolated.

Multi-Tenant Isolation - Every read and write is scoped to your firm's ID, and that scope is enforced in the application layer on every query, including document retrieval and AI search.

Secure Authentication

Two-Factor Authentication

Optional 2FA with TOTP apps like Google Authenticator or Authy. Add an extra layer of security.

Session Management

Automatic session timeouts. Secure JWT tokens with short expiration. Refresh token rotation.

Account Lockout

Automatic lockout after failed login attempts. Protection against brute force attacks.

Secure Password Reset

Email verification with time-limited tokens. Password strength requirements.

Enterprise-Grade Infrastructure

ProvaLens runs on Microsoft Azure, a platform trusted by healthcare organizations, financial institutions, and government agencies worldwide.

Azure Cloud

Hosted on Microsoft Azure with HIPAA BAA. SOC 1/2/3 certified data centers. Geographic redundancy for disaster recovery.

Automated Backups

Daily encrypted backups with 30-day retention. Point-in-time recovery available. Backups stored in separate geographic region.

DDoS Protection

Azure DDoS Protection Standard. Web Application Firewall. Rate limiting and bot protection at the edge.

24/7 Monitoring

Real-time infrastructure monitoring. Automatic alerting for anomalies. Auto-scaling to handle load spikes.

AI with Privacy in Mind

We've carefully selected AI partners who take data privacy as seriously as we do. Your documents are never used to train AI models.

Anthropic (Claude)

Called server-side through Anthropic's commercial API, under terms that prohibit training on our data. Anthropic maintains SOC 2 Type II certification. Our HIPAA procedure for this provider is under review. If your matter involves PHI, talk to us before you upload and we will scope it with you.

Azure OpenAI

Microsoft's enterprise AI, running in our Azure subscription and covered by Microsoft's Data Protection Addendum. Prompts and outputs are not used to train Microsoft's or OpenAI's models. A HIPAA-eligible Azure service.

No Training on Your Data

Every provider we use is called through a commercial API whose terms prohibit training on our data. No customer content ever reaches a consumer AI product. Your documents are not deleted after processing - we keep them, and the analysis derived from them, for as long as your account is active.

Your Data, Your Control

Data Export

Export all your data at any time. Documents, metadata, timelines, and research history. Your data belongs to you.

Complete Deletion

Request deletion of any matter or your entire account. Confirmed deletions are scheduled and processed within 30 days across our application database, document storage, and search index. Encrypted backups age out on their own 30-day rotation. Audit logs are retained for compliance.

Retention Policies

Your documents are retained as long as you need them. No automatic purging. When you cancel, you have 90 days to export before deletion.

Security Questions?

Is ProvaLens HIPAA compliant?

Yes. We sign a Business Associate Agreement with every customer. All technical safeguards required by HIPAA are in place, including encryption, access controls, and audit logging.

Where is my data stored?

Your data is stored in Microsoft Azure, in United States regions. Documents, extracted text, and database records are held in Azure, with backups in a separate US Azure region for disaster recovery. Our vector search index runs on a Qdrant instance we operate inside our own Azure subscription (US East 2).

Can I get a copy of your SOC 2 report?

ProvaLens does not hold its own SOC 2 report. Our infrastructure runs on Microsoft Azure, which is SOC 2 Type II certified, and we can provide our security questionnaire responses under NDA.

Is my data used to train AI models?

No. Every AI call is made server-side to commercial APIs whose terms prohibit training on our data, and no customer content is ever sent to a consumer AI product like a public chatbot. Your documents and the analysis built from them are not discarded after processing, though - they stay in your account so the work remains available to you, until you delete them.

What happens if there's a data breach?

We have an incident response plan in place. In the unlikely event of a breach, we will notify affected customers within 72 hours as required by HIPAA and applicable state laws.

Can I do a security review before signing up?

Absolutely. Contact our security team to schedule a review. We're happy to answer your security questionnaire, provide documentation, and discuss our practices in detail.

Ready to Protect Your Client Data?

Start your free trial or schedule a security review with our team.

Questions? Email our security team at security@provalens.ai