Built by lawyers who understand Rule 1.6

    Security and compliance are non-negotiable.

    Your clients trust you with their most sensitive information. We built Batesly to protect that trust with enterprise-grade security, transparent practices, and legal-specific compliance from the ground up.

    AES-256
    Encryption at rest
    TLS
    Encryption in transit
    MFA
    Required for all users
    Zero
    AI training on your data

    Defense in depth, not security theater.

    Every layer is built with intent. Where features are live, we tell you. Where they're on the roadmap, we're transparent about that too.

    Encryption & Transport

    • AES-256 encryption at rest (object storage & database)
    • TLS encryption in transit
    • ROADMAPCustomer-managed encryption keys
    • ROADMAPManaged key management service

    Data Isolation

    • Strict tenant isolation (every query scoped)
    • Zero-access architecture
    • US-based data centers
    • Presigned URLs with 1-hour expiry

    Access Control

    • Role-based access control (RBAC)
    • Matter-level permissions
    • Multi-factor authentication (MFA)
    • ROADMAPSSO integration (SAML/OIDC)
    • ROADMAPIP allowlisting

    Audit & Compliance

    • Comprehensive action logging with IP tracking
    • Audit log UI and CSV/JSON export
    • Append-only, tamper-proof log storage
    • ROADMAPSOC 2 Type II certification

    Ethical Walls

    • Matter-level conflict isolation
    • User/group exclusion from matters
    • Screening protocol support
    • ROADMAPTemporary access with auto-expiry

    Infrastructure

    • Modern, high-availability cloud architecture
    • Automated container isolation
    • Continuous managed database backups
    • Object storage versioning with clear disaster recovery protocols

    AI you can trust. Or turn off entirely.

    Our AI features use Anthropic's Claude models deployed exclusively through Amazon Web Services (AWS) Bedrock — never public consumer endpoints. Documents are processed inside the AWS perimeter, the result is returned, and no copy is retained. AI never makes final decisions — attorneys do.

    ZERO DATA TRAINING

    Neither AWS nor Anthropic will ever use your data to train public or foundational models. This is contractually guaranteed and verifiable in our DPA.

    Opt-in only
    All AI features are optional. Disable at the organization or matter level. Batesly works fully without AI.
    Zero data training
    Your documents are never used to train AI models. Neither AWS nor Anthropic will ever use your data to train public or foundational models.
    Process, return, delete
    Documents are sent for analysis inside the AWS perimeter and the result is returned. No copy is retained for training.
    AI suggests, attorneys decide
    The platform provides context-rich suggestions and relevance scores, but never acts on its own. Every AI recommendation is logged with clear reasoning for a human to review.
    Full auditability
    Every AI action is logged. Every human override is tracked. The attorney work product doctrine is preserved.
    DPA available
    We provide our Data Processing Agreement covering all AI provider relationships upon request.

    Enterprise compliance & security framework

    Batesly is engineered from the ground up to meet the rigorous security demands of the legal industry. Rather than routing your data through public consumer endpoints, our advanced AI features utilize Anthropic's Claude models deployed exclusively through Amazon Web Services (AWS) Bedrock.

    Compliance inherited from AWS Bedrock

    By architecture, our AI processing is built entirely inside the secure cloud perimeter of AWS. This environment inherently meets the world's most stringent compliance and regulatory standards:

    SOC 2 Type II Certified Infrastructure: Amazon Bedrock undergoes rigorous third-party audits to maintain SOC 1, 2, and 3 compliance. Independent Validation: Built on fully certified AWS foundations, Batesly has already entered active preparation for our own independent SOC 2 Type II audit to match our enterprise-grade security with verified third-party governance.

    HIPAA Eligibility: Amazon Bedrock is fully HIPAA-eligible. When managing protected legal or health information, our architecture aligns with HIPAA Security and Privacy Rules. Data is strictly managed under an active AWS Business Associate Addendum (BAA) and encrypted natively at rest and in transit.

    GDPR & Data Sovereignty: We fully support GDPR compliance guidelines. Because our Claude deployment runs entirely within AWS, your data never crosses international borders unexpectedly. All data processing and storage are tied to our localized, secure AWS region perimeters, governed by robust AWS Data Processing Addendums.

    Structural data protection

    Zero Model Training: Your case materials, contracts, litigation briefs, and prompts are entirely private. Neither AWS nor Anthropic will ever use your data to train public or foundational models.

    Strict Network Isolation: AI data transmission bypasses the public internet completely by using isolated virtual networks and AWS PrivateLink. Your data is never exposed to third-party networks during processing.

    Want to see these safeguards for yourself?

    We'll walk you through permissions, audit trails, and encryption in 30 minutes.

    Rather watch on your own time? Ask for a recorded walkthrough.

    Designed for your ethical obligations.

    The ABA and state bars have confirmed that attorneys may use cloud-based technology with appropriate safeguards. Batesly is designed with these requirements in mind — because our founder lives under the same rules you do.

    Model Rules 1.6 (confidentiality), 1.1 (competence, including technological competence per Comment 8), and 5.3 (supervision of technology) aren't optional. Batesly helps you meet all three.

    ABA Formal Opinion 477R (2017)
    Cloud services are permissible with reasonable safeguards for securing client information
    ABA Formal Opinion 498 (2021)
    Virtual practice and technology competence obligations
    ABA Model Rule 1.6(c)
    Duty to make reasonable efforts to prevent unauthorized disclosure of client information
    ABA Model Rule 1.1, Comment 8
    Duty of technological competence in choosing and using technology
    ABA Model Rule 5.3
    Duty to supervise nonlawyer assistants, including technology systems

    Security & compliance questions

    Who can access my client documents?
    Can Batesly employees see my documents?
    What about ethical walls within my organization?

    Have security questions?

    We understand that vetting legal technology is serious business.
    Let's walk through our security posture together.

    Email security@batesly.io