top of page

Security & Data Handling

The short version, for lawyers doing vendor diligence:

  • We never train AI models on your confidential content — your playbooks, edits, comments, or intake context. Product improvement runs on public vendor documents and de-identified quality signals, never on the substance of your team's legal work.

  • Your playbook is your most confidential asset in our system — it never leaves your tenant, and no other customer can access it.

  • Most of what TermTrax processes is the vendor's public legal documents — terms of service, DPAs, privacy policies fetched from public URLs. In a typical review, you are not uploading your own contracts or client files.

  • Encryption everywhere: TLS 1.3 in transit, AES-256 at rest.

  • Every AI output is preserved unaltered alongside every human edit — a permanent, tamper-evident record of what the AI said and what your lawyers decided.

  • We are a small company and we say so plainly. Security questionnaires are welcome. Our Data Processing Agreement applies to every customer - no signature ceremony required.
     

What data TermTrax handles — and what it doesn't

What we process:

  1. Vendor legal documents — fetched from the public URLs you provide (terms of service, privacy policies, DPAs, acceptable use policies, and documents they cross-reference). These are the vendor's published terms, not your confidential material.

  2. Your playbooks — the review standards your team imports or configures. This is your organization's confidential work product and is treated as the most sensitive data in the system.

  3. Review context — the intake form you fill in (vendor name, purpose, concerns) and the findings, scores, comments, and edits your team produces.

  4. Account data — names, work email addresses, and authentication records for your users.

What we don't require: your executed contracts, client files, or privileged communications. TermTrax reviews the non-negotiable terms a vendor publishes — a materially lighter data footprint than contract-repository or CLM tools that ingest your entire agreement library.
 

AI and your data: the training question, answered precisely

  • We never train AI models on your confidential content. Your playbooks, your edits and comments, and your intake context are your team's legal work product. They are used for exactly one thing: providing the service to you.

  • How we do improve the product — stated plainly: the vendor documents we analyze are public materials, and we use them, along with de-identified quality signals (for example, how often findings are accepted or overridden), to make the analysis better over time. The substance of your team's legal work is never part of that.

  • AI analysis is performed via the Anthropic API. Under Anthropic's commercial API terms, API inputs and outputs are not used to train Anthropic's models.

  • Every AI finding cites the exact source language it is based on, so your lawyers verify against the document itself — never against the AI's memory.
     

Tenant isolation

Each customer organization operates in its own tenant. Tenant data — playbooks, reviews, documents, users — is logically separated with tenant-scoped access enforced on every query. No user from one organization can view, edit, or infer data belonging to another under any circumstance. We are a multi-tenant SaaS platform and describe our isolation model honestly: logical separation with strict enforcement, encryption at rest, and audit logging — not per-customer physical databases.

(For fractional or multi-company counsel: one email address can belong to multiple tenants, with authentication and tenant selection as separate steps — a consultant serving several companies keeps each company's world fully separate.)
 

Access control and authentication

  • Role-based access control within each tenant (Admin, Playbook Admin, Reviewer).

  • Google OAuth SSO available for all customers; verified email required.

  • Two-factor authentication can be enforced tenant-wide by your admin.

  • Password policy floors: 12+ characters with complexity requirements; passwords stored one-way hashed and salted (bcrypt/argon2).

  • Failed logins are rate-limited (lockout after repeated attempts) and logged with timestamp and IP.

  • Immediate account deactivation by your admin; all administrative actions are captured in the audit log.
     

The dual-layer record (why your audit trail is trustworthy)

TermTrax stores the AI's original analysis as an immutable layer — it can never be edited, by anyone. Your team's determinations, edits, and comments live in a separate human layer on top. The two are never merged. That means at any point — including years later — you can show exactly what the AI found, exactly what your lawyers changed, and who made every call. AI assistance with a defensible paper trail.
 

Retention and deletion

  • Your data is retained for as long as your account is active — your review history and audit trail stay available until you decide otherwise.

  • You control deletion. Deletion requests are honored in our production systems within 30 days; backup snapshots cycle out in the normal course of operations and never persist beyond 365 days. All deletions are logged.

  • When a tenant is deleted, all of its data — reviews, playbooks, documents, accounts, analysis — is deleted on the same schedule.

  • Exported packages you download are yours; retention of local copies is under your control.
     

Encryption and infrastructure

  • In transit: TLS 1.3.

  • At rest: AES-256.

  • Hosting: AWS, United States.

  • Backups: encrypted snapshots, with periodic restoration testing. [VERIFY the restoration-testing claim matches reality before publishing]

  • Dependency scanning and a regular security patching cadence are part of our engineering practice.
     

Compliance posture — the honest version

TermTrax's architecture was designed from day one against GDPR, ISO 27001, and SOC 2 Type 2 requirements: data minimization, admin-controlled deletion, access controls, audit logging, and encryption are foundational, not bolted on.

We do not yet hold a SOC 2 report or ISO certification. We're an early-stage company and won't pretend otherwise — audits are on our roadmap as we grow. In the meantime: our security questionnaire door is open, our DPA is public, and our founder answers security questions directly.
 

Subprocessors

  • Anthropic: Document Discovery and AI analysis (API; does not train on API data)

  • Amazon Web Services: (United States) Hosting, storage, and backups

  • Twilio SendGrid: Transactional email delivery

  • Google: Business email and support communications (Google Workspace); sign-in (Google OAuth)

  • Stripe: Payment processing

We will notify customers before adding subprocessors that process customer data.

 

Documents & contact

  • Data Processing Agreement (DPA): applies to all customers — Need a countersigned copy for your records? Ask.

  • Security questionnaires: send to security@axotrax.com.

  • Anything else: ask the founder directly — hello@axotrax.com. Small company; you'll get a real answer from the person who built it.

bottom of page