Security Overview

Your agreements never leave your control

M&A documents are some of the most sensitive materials your organization handles. Statuteharbor is designed from the ground up for that standard of confidentiality, not retrofitted with security as an afterthought.

Abstract security and data protection concept visualization

Data Handling

How we handle your documents

Every decision about how agreement data moves through Statuteharbor starts from what a corporate legal team's document handling policy would require. These are the answers that matter before a general counsel signs a vendor agreement.

Encryption at rest and in transit

All uploaded documents are encrypted using AES-256 at rest. Every connection between your browser and Statuteharbor's servers uses TLS 1.3. There is no unencrypted path for your agreements.

No training on your data

Your uploaded purchase agreements are never used to train, fine-tune, or evaluate any model, including Statuteharbor's own review system. Processing runs in isolated compute environments with no data retention after review completion.

US-based data processing

All document processing occurs in US data centers. No cross-border data transfer for document content. Infrastructure is hosted on US-region cloud instances with no cross-region replication of document data.

Automatic and on-demand deletion

Agreements are deleted from Statuteharbor systems 30 days after review completion. You can delete any agreement at any time from your account. Deletion is immediate and permanent with no backup retention.

Privilege Considerations

Designed with attorney-client privilege in mind

Using AI tools on privileged M&A documents raises legitimate questions about waiver risk and third-party access. Statuteharbor is designed so that the data flows that matter for attorney-client privilege analysis stay under your organization's control, not ours.

Access scoped to your organization

Document access is strictly scoped to the users in your Statuteharbor account. Statuteharbor staff do not have access to your uploaded documents during or after review. Administrative access is logged and auditable.

Detailed audit logs

Every document upload, review run, export, and deletion generates an audit log entry with timestamp and user identity. Logs are available to account administrators and can be exported for your own records.

Data processing agreement available

A Data Processing Agreement is available for organizations conducting a formal AI governance review or vendor security assessment. It formalizes the data handling commitments described on this page and is suitable for inclusion in your legal department's vendor file.

Access Controls

Role-based access for your deal team

Not everyone on a deal team needs the same level of access to every agreement. Statuteharbor's access controls give you the granularity your practice requires.

Reviewer and admin roles

Assign reviewer access for deal team members who run reviews and see results. Admin access for account owners who manage users, billing, and retention settings.

Controlled sharing

Share a review result with specific team members without granting access to the underlying document. Recipients see the flag report only, not the original agreement text.

SSO integration (Enterprise)

Connect Statuteharbor to your organization's identity provider via SAML 2.0 or OIDC. Access provisioning and deprovisioning follows your existing IT workflows.

MFA required

Multi-factor authentication is required for all Statuteharbor accounts. TOTP authenticator apps and hardware security keys are supported.

Security questions

Talk to us about your requirements

If your firm has a vendor security assessment process or requires specific documentation, contact us. We will respond to every security inquiry from legal teams directly.