Security & Compliance

Built for trusted work.

Last updated: May 1, 2026 · Version 2.1

On this page
  1. Security overview
  2. Per-client data isolation
  3. Encryption
  4. Access controls
  5. ABA compliance
  6. Infrastructure
  7. Incident response
  8. Audit & logging
  9. DPA & legal
  10. Contact security team

Security overview

DVLP Studio builds AI products for law firms and operations teams. Our products handle sensitive information — client documents, case files, project data, and internal communications. Every design decision in our infrastructure prioritizes data isolation, confidentiality, and auditability.

This page describes our current security posture. It is reviewed quarterly and updated as our infrastructure evolves. For any specific question not answered here, contact our security team directly.

For prospective customers: We are happy to complete vendor security questionnaires, sign mutual NDAs, and provide our SOC 2 readiness report on request. Email info@dvlpstudio.com with "Security review" in the subject.

Per-client data isolation

Every customer receives a dedicated, isolated environment for their data. This is the most important security property of our products and is non-negotiable.

Encryption

All data is encrypted both at rest and in transit using industry-standard cryptographic algorithms.

Access controls

Customer data is accessed only by authorized personnel under explicit need-to-know circumstances.

ABA compliance for legal customers

For our Legal Intelligence customers, our security posture is designed around ABA Model Rule 1.6 (confidentiality), ABA Formal Opinion 512 on generative AI (July 2024), and state bar guidance where stricter.

Model Rule 1.6 — Confidentiality

Information relating to your firm's representation of clients is held in strict confidence. We do not access, view, share, or analyze your firm's documents except as required to provide the service and respond to support requests with your explicit authorization.

Opinion 512 — Generative AI

Engagement letter language

We provide standard engagement letter language for AI disclosure to clients, designed to satisfy ABA Rule 1.4 and applicable state bar guidance. Available on request.

Infrastructure providers

We operate on a small set of audited, enterprise-grade infrastructure providers.

Incident response

We maintain a documented incident response plan that defines roles, communication procedures, and escalation paths in the event of a security incident.

Audit & logging

Comprehensive logging is maintained for all access, queries, and changes to customer data.

Data Processing Agreement & legal terms

We provide a standard Data Processing Agreement (DPA) for all customers handling regulated or confidential data. The DPA covers GDPR controller/processor relationships, data residency, subprocessor management, and incident notification obligations.

For customers handling protected health information (PHI), we sign Business Associate Agreements (BAAs) on a case-by-case basis. Note that our standard products are not configured for HIPAA-regulated workloads — please contact us before processing PHI on our platform.

Contact our security team

For security questions, vendor reviews, vulnerability reports, or incident disclosures:

Need to talk to us about security?
Vendor questionnaires, custom DPAs, BAA requests, and security architecture reviews.
info@dvlpstudio.com