Return to Catalog/Legal & Regulatory Compliance

Enterprise Security Architecture

Comprehensive technical documentation regarding encryption standards, multi-tenant vault isolation, stateless AI processing, and infrastructure resilience.

Version 1.2 • Effective
September 10, 2026
AES-256 & TLS 1.3

Bank-grade encryption for all data at rest and in transit.

Stateless Inference

Sub-second inference with instantaneous in-memory prompt purge.

Cryptographic Vaults

Strict multi-tenant tenant-ID segregation on every query.

1. Encryption Standards

Data in Transit

All client-to-server and inter-service communications enforce modern Transport Layer Security (TLS 1.3) with perfect forward secrecy (PFS). Insecure cipher suites and HTTP fallback are strictly rejected with HTTP Strict Transport Security (HSTS) headers.

Data at Rest

All cloud vault databases, document snapshots, and user credentials are encrypted using industry-standard Advanced Encryption Standard with 256-bit keys (AES-256). User passwords are treated with PBKDF2/SHA256 with per-user cryptographic salts.

2. Multi-Tenant Data Isolation

JurisDraft implements strict tenant data partitioning:

  • Row-Level Tenant Authorization: Every database query, mutation, and PDF retrieval enforces non-bypassable ownership filters keyed to the authenticated user’s cryptographically signed JWT token.
  • Guest Draft Isolation: Unauthenticated freemium drafting sessions reside strictly in client-side ephemeral state and are never committed to permanent vault storage until the user explicitly authenticates.

3. Sub-Second AI Pipeline Security

Our conversational intake assistant leverages high-throughput Cerebras fast inference through secure, isolated API gateways:

Zero Model Training & Zero Log Retention:

Contract variable extraction requests are processed via non-retained endpoints. Prompts are never cached in persistent disks by the inference engine and are strictly purged upon token delivery.

Deterministic Local Rule-Engine Fallback:

In situations where external network access is restricted or disabled, JurisDraft automatically switches to an in-process deterministic regex and rule-based paralegal engine, ensuring 100% operational autonomy without external data egress.

4. Vulnerability Management & Container Hardening

The JurisDraft deployment stack utilizes hardened, minimal multi-stage Docker containers (`node:20-slim` and `python:3.12-slim`), running with unprivileged system users, stripped compiler dependencies, and strict read-only filesystems wherever applicable.

5. Responsible Disclosure Program

Security researchers and enterprise compliance auditors can report findings directly to security@jurisdraft.io. We acknowledge all reports within 24 hours.