Security Overview
Your agreements never leave your control
M&A documents are some of the most sensitive materials your organization handles. Statuteharbor is designed from the ground up for that standard of confidentiality, not retrofitted with security as an afterthought.
Data Handling
How we handle your documents
Every decision about how agreement data moves through Statuteharbor starts from what a corporate legal team's document handling policy would require. These are the answers that matter before a general counsel signs a vendor agreement.
Encryption at rest and in transit
All uploaded documents are encrypted using AES-256 at rest. Every connection between your browser and Statuteharbor's servers uses TLS 1.3. There is no unencrypted path for your agreements.
No training on your data
Your uploaded purchase agreements are never used to train, fine-tune, or evaluate any model, including Statuteharbor's own review system. Processing runs in isolated compute environments with no data retention after review completion.
US-based data processing
All document processing occurs in US data centers. No cross-border data transfer for document content. Infrastructure is hosted on US-region cloud instances with no cross-region replication of document data.
Automatic and on-demand deletion
Agreements are deleted from Statuteharbor systems 30 days after review completion. You can delete any agreement at any time from your account. Deletion is immediate and permanent with no backup retention.
Privilege Considerations
Designed with attorney-client privilege in mind
Using AI tools on privileged M&A documents raises legitimate questions about waiver risk and third-party access. Statuteharbor is designed so that the data flows that matter for attorney-client privilege analysis stay under your organization's control, not ours.
Access scoped to your organization
Document access is strictly scoped to the users in your Statuteharbor account. Statuteharbor staff do not have access to your uploaded documents during or after review. Administrative access is logged and auditable.
Detailed audit logs
Every document upload, review run, export, and deletion generates an audit log entry with timestamp and user identity. Logs are available to account administrators and can be exported for your own records.
Data processing agreement available
A Data Processing Agreement is available for organizations conducting a formal AI governance review or vendor security assessment. It formalizes the data handling commitments described on this page and is suitable for inclusion in your legal department's vendor file.
Access Controls
Role-based access for your deal team
Not everyone on a deal team needs the same level of access to every agreement. Statuteharbor's access controls give you the granularity your practice requires.
Reviewer and admin roles
Assign reviewer access for deal team members who run reviews and see results. Admin access for account owners who manage users, billing, and retention settings.
Controlled sharing
Share a review result with specific team members without granting access to the underlying document. Recipients see the flag report only, not the original agreement text.
SSO integration (Enterprise)
Connect Statuteharbor to your organization's identity provider via SAML 2.0 or OIDC. Access provisioning and deprovisioning follows your existing IT workflows.
MFA required
Multi-factor authentication is required for all Statuteharbor accounts. TOTP authenticator apps and hardware security keys are supported.
Security questions
Talk to us about your requirements
If your firm has a vendor security assessment process or requires specific documentation, contact us. We will respond to every security inquiry from legal teams directly.