Supreme Mind AISupreme Mind
SecuritiesAntitrustSample BriefWalkthroughPricingAbout
Sign InStart Free

Security & Trust

Supreme Mind is built for privileged legal work. Matter content is handled as confidential material end to end: where the model runs, where data is stored, and what is ever written to a log. This page summarizes our security posture in plain terms; it is consistent with, and governed by, our Privacy Policy and Terms of Service.

Accounts & access

  • Passwordless sign-in. Access uses a magic link sent to your work email and is tied to a named individual, so there is no password to phish, reuse, or manage. An optional per-user access code is available as a fallback.
  • Firm accounts and administration. Firms get a firm-admin role with self-service team management to add, remove, and manage users. Sessions work across multiple devices.

How the model runs

  • Server-side only. The AI model runs server-side. The browser never holds an API key.
  • US-pinned, Zero-Data-Retention inference. Model calls are pinned to US inference geography and routed only through Zero-Data-Retention-eligible endpoints. Features that are not Zero-Data-Retention eligible are not used on matter content.
  • No third-party model training. We do not use your matter content to train third-party foundation models.

Where your data lives

  • Per-firm isolation, US region. Firm matter content (matters, generated briefs, and grounding results) is stored in a US-region PostgreSQL database with per-firm isolation.
  • US-region document store. Uploaded documents are stored in a US-region file store, and serverless compute is pinned to a US region.
  • Encrypted in transit and at rest. Every connection to the application and to the model runs over TLS. The database and the document store encrypt at rest under our infrastructure providers’ managed keys; we do not operate our own key management, and we do not offer customer-managed keys.

Who else touches it

Seven subprocessors, named individually rather than described as a category, in section 4 of the Privacy Policy. Four can touch matter content: Anthropic for model processing, Vercel for hosting and serverless compute, Neon for the database, and Resend for sign-in emails. Three cannot: Stripe, which takes card details directly so they never reach our servers, and Google Analytics and Slack, both of which run on this marketing site only. We will tell you before adding a subprocessor that would process matter content.

Certifications, stated plainly

SOC 2 Type II is in progress. It is not finished, and we would rather say so here than let you discover it in a questionnaire. We are not ISO 27001 certified and have not commissioned a third-party penetration test. If your firm requires either before a pilot, tell us and we will give you a date rather than an assurance.

What exists today is architectural rather than certified: the model runs under Zero-Data-Retention terms, matter content never enters a log, storage is per-firm, and a deletion is a real deletion. Those are checkable now. A certification is somebody else checking them, and that is underway.

If something goes wrong

We will notify affected firms without undue delay on becoming aware of a breach of security leading to unauthorised access to matter content, with what we know, what we do not yet know, and what we are doing. Supreme Mind is one person today, so that notice comes from a named individual rather than a status page.

Logging & audit

  • Metadata-only audit records. Each model call writes a metadata-only audit record (who, when, which task, which model and region). Privileged content is never written to these logs.

Retention & deletion

  • 30-day deletion. Deleting a matter hides it immediately and permanently deletes it (database rows and stored documents) after a 30-day recovery window. Individual documents delete immediately.
  • Demo sessions stay local. Demo-session data lives only in your browser and is not stored on our servers.

Pilots & enterprise

Under a pilot or enterprise agreement, we add SSO, role-based access control (RBAC), immutable audit logging, and a signed Anthropic data processing addendum (DPA) plus a Zero-Data-Retention addendum.

Contact

Security questions: richard@suprememind.ai. For how we handle personal information and matter content, see the Privacy Policy. If you are evaluating a pilot, that page sets out how an engagement is structured, including the data processing and zero-retention addenda available with one.

This page is provided for general information and does not constitute legal advice. Where this summary and the Privacy Policy differ, the Privacy Policy controls.

Supreme Mind AISupreme Mind
The opposing expert’s report,
before they write it.
Practice Areas
  • Securities
  • Antitrust
  • Mass Tort
  • Personal Injury
  • Commercial Litigation
  • All Practice Areas
Product
  • Read a Sample Brief
  • Watch the Walkthrough
  • Pricing
  • FAQ
  • Pilots
  • Security & Trust
  • Talk to Sales
  • Start Free
Company
  • About
  • The Fourth Institution
  • LinkedIn
© 2026 Supreme Mind AI, Inc. All rights reserved.
Terms of ServicePrivacy Policy