Trust
Built for the data your firm actually handles.
Discover Docket is designed from the infrastructure up around the security and compliance posture that protected health information, attorney-client privilege, and ethical walls actually require.
Compliance & certifications
Discover Docket was architected from day one around the posture that protected health information, attorney-client privilege, and ethical walls actually require.
SOC 2 Type II
SOC 2 Type II compliant.
Discover Docket is SOC 2 Type II compliant. Customer data is stored, processed, and transmitted through infrastructure under continuous independent SOC 2 Type II audit at the enterprise tier. The compliance posture is not aspirational — it is the operating environment we run inside, every day, for every customer.
HIPAA-aligned architecture
PHI handled per the Security Rule.
The platform is built to handle protected health information consistent with the HIPAA Security Rule. This is non-negotiable infrastructure for any law firm that touches medical malpractice, personal injury, workers' compensation, employment claims, or family law matters involving health records. Every PHI handling pathway in Discover Docket — uploads, OCR, document review, AI processing, audit logging — operates inside the same controlled environment.
TLS 1.3 / AES-256
Encrypted in transit and at rest.
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. All access is logged. All key management is handled at the infrastructure layer with hardware security modules. There is no unencrypted moment in the data path from your browser to our database to JILL's processing back to your screen.
Ethical walls
Enforced at the database layer.
Ethical walls are not implemented at the application layer. They are enforced at the database layer through row-level security policies that fire on every read and write. This means an ethical-walled user attempting to access a screened matter encounters a hard wall at the database — not a UI restriction that could be bypassed. The wall is structural.
Operational security posture
Role-based access control
Every user role in your firm — managing partner, partner, associate, paralegal, legal assistant, administrative staff — has a permission set scoped to what that role legitimately needs to see. The matter team for any given case is explicit. Cross-team access requires an audit-logged elevation. The principle of least privilege is the default, not an option.
Audit logs on every read and write
Every read and write to every matter is logged: who accessed what, when, from where, and what action they performed. The log is queryable by you, the firm administrator. It is also the same log that DDEAS uses to make JILL's AI outputs defensible — meaning the firm-level audit trail and the AI-output audit trail are unified into a single system of record.
US-based infrastructure
Customer data is stored in US-based data centers. No customer data leaves US jurisdiction. This matters for state bar requirements in jurisdictions with data residency expectations, for ABA Formal Opinion 512 confidentiality compliance, and for any matter involving a client whose contract or industry requires US data handling.
No third-party AI training on firm data
Customer matters, documents, communications, and AI sessions are never used to train third-party models. JILL operates inside a closed environment with no data flowing out to model providers' training pipelines. This is contractually enforced and architecturally enforced. The work JILL does on your matters stays on your matters.
Annual security review
Discover Docket undergoes annual independent security review covering application security, infrastructure security, access controls, and incident response. Reports are available to enterprise customers under NDA.
How AI outputs are validated and recorded is covered in the DDEAS framework.
Privacy posture
Discover Docket's privacy posture is a public commitment. The marketing site does not use cookies, tracking pixels, third-party analytics, or any other behavioral tracking software. We do not sell, share, or otherwise distribute email addresses or contact information. Customer data inside the platform is never used to train third-party AI models. These commitments are reflected in our Privacy Policy and operationalized in the technical architecture.
The work gets done. You get to be the lawyer.
Join the waitlist. California firms first.