NO BLACK-BOX AI · FULLY AUDITABLE

G
GAAS LAWDefence. Strategy. Outcomes.
Why GAAS LAWFrameworkImplementationTrust
Sign InRequest Demo
TL.05Trust Layer · Confidentiality

Privileged. Confidential. Client Work Product.

Every matter on the Platform is treated as privileged, confidential client work product. Confidentiality is the default posture, not a configurable option.

Document Metadata

Reference
TL.05
Document
Confidentiality
Version
v1.0
Effective
01 June 2025
Owner
GAAS LAW · Compliance

Trust Documents

Privacy PolicyTL.01Terms of ServiceTL.02AI Use PolicyTL.03Responsible AITL.04ConfidentialityTL.05Procurement FAQTL.06

Principle — Default posture

All matter data, all derived analytics, and all user-generated content are treated as privileged, confidential, and the exclusive property of the Customer firm (and, where applicable, the underlying client or panel insurer).
§ 01

Tenancy isolation

GAAS LAW is a multi-tenant platform with strict logical isolation enforced at every layer: database, application, API, and model inference.

  • No query, prompt, output, or data object crosses a tenant boundary under any circumstance.
  • Per-tenant encryption keys are managed in a dedicated KMS. No cross-tenant key reuse.
  • Tenant boundaries are tested by independent penetration testing at least annually.
  • Shared infrastructure is limited to non-data components (load balancing, monitoring, authentication routing).
§ 02

Access controls

Access to matter data is governed by a layered control set:

AuthenticationEmail + password with enterprise SSO support (SAML / OIDC)
Session bindingHttpOnly, SameSite-restricted, time-bound JWT
AuthorisationRole-based (partner, fee earner, paralegal, supervisor, finance, insurer, admin)
Matter-level scopeUsers see only matters they are assigned to or explicitly shared with
Insurer viewRestricted to contractually defined data fields and aggregation levels
Administrative accessRequires dual authorisation; action is audit-logged
§ 03

Audit logging

Every read, write, and state change is logged. The audit log records:

  • Actor identity and actor type (human user or AI).
  • Action taken and the target entity.
  • Before-state and after-state values.
  • Source document or event referenced, where applicable.
  • Timestamp to millisecond precision.

Logs are append-only and cannot be edited or deleted by any user, including GAAS LAW staff. Logs are exportable by the Customer at any time.

§ 04

Privilege preservation

The Platform is designed to preserve legal professional privilege at every interaction point.

  • Privileged material is clearly marked in both the UI and in generated artefacts (e.g. invoice PDFs carry “Privileged · Confidential · Client Work Product” in the footer).
  • AI-generated suggestions are internally marked as draft work product. They are never exposed to a counterparty route, an external email, or an insurer portal without explicit human approval.
  • Disclosure exports can be filtered to exclude attorney work product.
§ 05

Staff access

GAAS LAW personnel do not access Customer matter data except in two narrowly defined circumstances:

  • Authorised support. A Customer raises a support request and explicitly grants temporary, scoped access. Access is logged and revoked automatically.
  • Incident response. A security incident requires investigation. A defined incident commander authorises read-only access for the minimum team required. Every action is audit-logged and reported to the Customer.

All personnel with potential access are bound by employment confidentiality obligations and the Responsible AI Code of Conduct. Training is refreshed annually and verified.

§ 06

Cross-border transfers

Matter data does not leave the UK / EU region of the Customer’s tenancy. Support access that would require temporary extraction is subject to a documented data-transfer agreement and is never granted by default.

§ 07

Breach notification

In the event of a confirmed personal data breach affecting Customer matter data, affected Customers are notified without undue delay and in any event within 72 hours of discovery, consistent with UK GDPR requirements. Notification includes the nature of the breach, data affected, containment steps, and remediation plan.

Note — Artefact marking

Every generated artefact on the Platform — invoice PDF, portfolio report, audit export, disclosure bundle — carries the footer line: Privileged · Confidential · Client Work Product.

Questions or Requests

Contact the GAAS LAW Compliance Office at compliance@gaaslaw.com.

Data Subject Requests

Submit a GDPR request to privacy@gaaslaw.com. Responses within 30 days.

G
GAAS LAWDefence. Strategy. Outcomes.

AI-powered legal operations for insurance defence teams.

Product

Why GAAS LAWFrameworkWorkflowsImplementationWhy Now

Trust

Privacy PolicyTerms of ServiceAI Use PolicyResponsible AIConfidentialityProcurement FAQ

Company

Request DemoFAQ

© 2026 GAAS LAW. All rights reserved.

APeak Asset Investments LtdProduct