Security & trust
World-class security, held to international standards.
Trovato protects the firms with the most to lose. Security is engineered into every layer — hosted on Microsoft Azure and Google Cloud, with bank-grade encryption, governed access and a full audit of every action — and built to international standards including ISO/IEC 27001, SOC 2 and GDPR.*
The posture
Zero training on your data — and control you can prove.
Defence in depth across infrastructure, encryption, access, governance, tenant isolation and the AI layer itself — every one built so you can prove control, not just assert it.
Trusted infrastructure
Microsoft Azure & Google Cloud
Built on hyperscale infrastructure, under its physical, network and platform security.
Regional data residency
Hosted in the jurisdiction you choose; data stays in-region.
Resilience & recovery
Redundancy, encrypted backups and monitored availability.
Encryption & data handling
Bank-grade encryption
AES-256 at rest and TLS 1.2+ in transit — encrypted end to end.
Zero training on your data
Your content is never used to train shared or public models.
Tenant isolation
Each firm's data is isolated; no cross-tenant access.
Access control
SSO / SAML
Single sign-on with your identity provider.
RBAC
Role-based access, per-firm roles and permissions.
IP allow-listing
Restrict access to known networks.
Governance
Policy that enforces
Export, publication, model-usage and source-entitlement policy, each set to advisory, blocking, or blocking-unless-approved — with a real approval queue behind the last.
Ethical walls bind everyone
A wall blocks the lawyer as well as the agent, is checked live on every request, and cannot be switched off by a firm setting.
Budgets and central administration
Recurring monthly spend caps that actually stop work, and one place to manage roles, access, policy and usage.
Tenant isolation
Four independent layers
Database row-level security, index-level access filtering, service-layer authorisation, and a response-level assertion — any one of which catching a bug prevents a leak.
Red-teamed on every merge
A cross-tenant test seeds a unique token into one firm's corpus and queries it as another; it must return nothing, and it blocks any change touching isolation.
Private stays private
Personal workbench documents are reachable only by their owner, and knowledge-base content only by grant holders — enforced at the index, not just the interface.
AI-specific controls
Documents never leave the boundary
Parsing and OCR run inside your deployment. No customer document is sent to a third-party extraction service during ingestion.
PII redaction on every model call
Personal data is detected before a prompt goes to a provider, in advisory or enforcing mode, and re-hydrated in the answer you see.
No default jurisdiction
Every legal-analysis prompt carries the matter's or the firm's jurisdiction and a standing rule against assuming one — so analysis never quietly falls back to another country's law.
Audit & retention
Append-only audit of every action
A complete, exportable trail of every query and action, written once and never edited — including by us.
Per-query usage metering
Token usage tracked per query for review.
Retention & deletion
Configurable retention; deletion on request.
Compliance & standards
ISO/IEC 27001 & SOC 2*
Certification actively underway; controls built to both frameworks.
GDPR & POPIA aligned
Built for the privacy regimes our buyers operate under.
Independently assessed
Third-party review — we publish each mark only once it's held.
Deployment & data residency
Azure or Google Cloud, in the region your rules require.
Choose Microsoft Azure or Google Cloud — by preference, or by where your data must live — and we deploy in the cloud region your jurisdiction requires. Data stays in-region to meet GDPR and other regimes, POPIA-aligned for South-Africa-based teams. Deployment and residency are a configuration choice, not a special case.
Choice of cloud
Microsoft Azure or Google Cloud — by preference or by region.
Data residency
Deployed in the region your jurisdiction requires; data stays in-region.
Managed & isolated
Fully managed, multi-tenant, with per-firm isolation.
Sub-processors
Who touches the data.
We maintain a current list of sub-processors and the model providers a firm has entitled.
Trust centre
Documentation on request.
Security documentation, the data-handling overview, and deployment guidance are available to firms in a demo or evaluation. A public trust centre follows.
Request security documentation