wakilii Legal Intelligence

Security & Privacy

Built for the confidentiality the law demands.

Wakilii handles sensitive legal work, so security and data privacy are part of how the platform is built — not an afterthought.

Data protection

Your data is encrypted on the wire and at rest, and your credentials are stored so that even we cannot read them.

Encryption in transit

All traffic is served over HTTPS with modern TLS. HTTP Strict Transport Security (HSTS) is enforced so browsers refuse to connect insecurely.

Encryption at rest

Application data is stored on managed infrastructure that encrypts data at rest. Backups inherit the same protection.

Hashed credentials

Passwords are hashed with scrypt — a deliberately slow, memory-hard algorithm. We never store plaintext passwords, and password hashes are excluded from data exports.

Protected sessions

Session cookies are HttpOnly, Secure and SameSite-scoped; the token itself is stored only as a hash, so a database leak exposes no usable session.

Application security

The application is hardened against the common web attack classes by default.

Strict security headers

A nonce-based Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options, a restrictive Permissions-Policy and Cross-Origin-Opener-Policy ship on every response.

CSRF protection

Every state-changing request is checked against its Origin and Referer, so a malicious site cannot act on your behalf.

Rate limiting & lockout

Failed sign-ins are rate-limited and locked out per account and per IP address, blunting credential-stuffing and brute-force attempts.

Bot & abuse protection

Public forms are guarded by an invisible CAPTCHA and a content-delivery layer that absorbs DDoS and filters automated abuse.

Data privacy & AI

Your work product stays yours. We are deliberate about what leaves the platform and what it is used for.

No training on your data

We do not use your questions, documents, or results to train or fine-tune AI models.

Grounded, auditable answers

Wakilii is built on a "no claim without a source" principle: every answer is traceable to the primary authority that supports it, so you can review the reasoning and verify each citation before you rely on it. This is the same grounding engine behind our Veritas citation-verification tooling.

Regional hosting

The platform is hosted in the European Union (Frankfurt) region, giving your data a stable, single-region home rather than moving it across jurisdictions.

Subprocessors

We keep the list of third parties that process platform data short and transparent:

ProviderPurposeRegion
AnthropicAI support.US
RenderApplication hosting & infrastructureEU (Frankfurt)
CloudflareDNS, CDN, TLS, DDoS & bot protectionGlobal edge

Search relevance and embeddings run on models we host ourselves, so the text of your corpus queries is not sent to a third-party embedding service.

Your data, your control

You can see, take, and delete your data at any time.

Right of access & portability

Download a complete machine-readable copy of everything tied to your account from your account page.

Right to erasure

Permanently delete your account and all associated history yourself, instantly, from your account page — no support ticket required.

Defined retention

We retain account and history data for as long as your account is active; deleting your account removes it. Details are in our Privacy Policy.

Least-privilege access

Access to the platform is invite-gated, administrative functions are separated from ordinary accounts, and security-relevant events are logged for review.

Compliance & certifications

We build to recognised standards. The formal, independently-audited certifications below are part of our standards.

SOC 2 Type IISecurity, availability & confidentiality controls — independent audit Pending
ISO/IEC 27001Information security management system Pending
ISO/IEC 27701Privacy information management extension Pending
ISO/IEC 42001AI management system governance Pending
GDPR alignmentEU-region hosting plus access & erasure rights are live; formal DPA on request In force
Independent penetration testingThird-party application security assessment Planned

Report a vulnerability

We welcome good-faith security research. If you believe you have found a vulnerability, please tell us before disclosing it publicly, and don't access data that isn't yours.

Email [email protected]  ·  Policy: /.well-known/security.txt

Wakilii provides legal research assistance, not legal advice. This page describes our security and privacy practices; it is informational and does not itself form a contract. For binding terms see our Terms of Use and Privacy Policy.