Principle — Default posture
Tenancy isolation
GAAS LAW is a multi-tenant platform with strict logical isolation enforced at every layer: database, application, API, and model inference.
- No query, prompt, output, or data object crosses a tenant boundary under any circumstance.
- Per-tenant encryption keys are managed in a dedicated KMS. No cross-tenant key reuse.
- Tenant boundaries are tested by independent penetration testing at least annually.
- Shared infrastructure is limited to non-data components (load balancing, monitoring, authentication routing).
Access controls
Access to matter data is governed by a layered control set:
Audit logging
Every read, write, and state change is logged. The audit log records:
- Actor identity and actor type (human user or AI).
- Action taken and the target entity.
- Before-state and after-state values.
- Source document or event referenced, where applicable.
- Timestamp to millisecond precision.
Logs are append-only and cannot be edited or deleted by any user, including GAAS LAW staff. Logs are exportable by the Customer at any time.
Privilege preservation
The Platform is designed to preserve legal professional privilege at every interaction point.
- Privileged material is clearly marked in both the UI and in generated artefacts (e.g. invoice PDFs carry “Privileged · Confidential · Client Work Product” in the footer).
- AI-generated suggestions are internally marked as draft work product. They are never exposed to a counterparty route, an external email, or an insurer portal without explicit human approval.
- Disclosure exports can be filtered to exclude attorney work product.
Staff access
GAAS LAW personnel do not access Customer matter data except in two narrowly defined circumstances:
- Authorised support. A Customer raises a support request and explicitly grants temporary, scoped access. Access is logged and revoked automatically.
- Incident response. A security incident requires investigation. A defined incident commander authorises read-only access for the minimum team required. Every action is audit-logged and reported to the Customer.
All personnel with potential access are bound by employment confidentiality obligations and the Responsible AI Code of Conduct. Training is refreshed annually and verified.
Cross-border transfers
Matter data does not leave the UK / EU region of the Customer’s tenancy. Support access that would require temporary extraction is subject to a documented data-transfer agreement and is never granted by default.
Breach notification
In the event of a confirmed personal data breach affecting Customer matter data, affected Customers are notified without undue delay and in any event within 72 hours of discovery, consistent with UK GDPR requirements. Notification includes the nature of the breach, data affected, containment steps, and remediation plan.
Note — Artefact marking
Questions or Requests
Contact the GAAS LAW Compliance Office at compliance@gaaslaw.com.
Data Subject Requests
Submit a GDPR request to privacy@gaaslaw.com. Responses within 30 days.