Security & Trust
Supreme Mind is built for privileged legal work. Matter content is handled as confidential material end to end: where the model runs, where data is stored, and what is ever written to a log. This page summarizes our security posture in plain terms; it is consistent with, and governed by, our Privacy Policy and Terms of Service.
Accounts & access
- Passwordless sign-in. Access uses a magic link sent to your work email and is tied to a named individual, so there is no password to phish, reuse, or manage. An optional per-user access code is available as a fallback.
- Firm accounts and administration. Firms get a firm-admin role with self-service team management to add, remove, and manage users. Sessions work across multiple devices.
How the model runs
- Server-side only. The AI model runs server-side. The browser never holds an API key.
- US-pinned, Zero-Data-Retention inference. Model calls are pinned to US inference geography and routed only through Zero-Data-Retention-eligible endpoints. Features that are not Zero-Data-Retention eligible are not used on matter content.
- No third-party model training. We do not use your matter content to train third-party foundation models.
Where your data lives
- Per-firm isolation, US region. Firm matter content (matters, generated briefs, and grounding results) is stored in a US-region PostgreSQL database with per-firm isolation.
- US-region document store. Uploaded documents are stored in a US-region file store, and serverless compute is pinned to a US region.
Logging & audit
- Metadata-only audit records. Each model call writes a metadata-only audit record (who, when, which task, which model and region). Privileged content is never written to these logs.
Retention & deletion
- 30-day deletion. Deleting a matter hides it immediately and permanently deletes it (database rows and stored documents) after a 30-day recovery window. Individual documents delete immediately.
- Demo sessions stay local. Demo-session data lives only in your browser and is not stored on our servers.
Pilots & enterprise
Under a pilot or enterprise agreement, we add SSO, role-based access control (RBAC), immutable audit logging, and a signed Anthropic data processing addendum (DPA) plus a Zero-Data-Retention addendum.
Contact
Security questions: [email protected]. For how we handle personal information and matter content, see the Privacy Policy.
This page is provided for general information and does not constitute legal advice. Where this summary and the Privacy Policy differ, the Privacy Policy controls.