Security & Data Handling

Summit6 is built to handle sensitive legal documents with strong confidentiality and security controls. Deposition transcripts and related artifacts are processed only for the purpose of generating cite-verified summaries and audit materials. We use encryption in transit and at rest, least-privilege access controls, and organizational isolation between customers.

This page summarizes our technical and operational security practices. Formal attestations require documented policies, contracts, and third-party audits beyond what is described here.

We engage established third-party providers for core infrastructure and services, including cloud hosting, authentication, database and object storage, payment processing, AI model inference, and transactional email. A current list of subprocessors is available to customers under NDA or as part of our Data Processing Addendum. We do not use customer data to train models.

Access to customer data is restricted to authorized personnel and is logged. Within each organization, users only see the matters and jobs they have permission to access. Data in active processing is held in short-lived scratch storage that is automatically purged. Completed artifacts are retained according to the retention schedule in your subscription agreement, with legal-hold support and configurable encryption at rest.

See also our Privacy Policy.

Application logs capture operational metrics such as token usage and job status. No deposition content, prompts, or model outputs are written to logs. Automated redaction is applied to any error paths that might surface identifiers. AI processing occurs through commercial API endpoints under terms that prohibit use of customer data for model training.

Summit6 is designed to align with the SOC 2 Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy. Our primary infrastructure providers maintain their own SOC 2 reports. Customers subject to HIPAA should request our Business Associate Agreement; certain subprocessors offer BAAs on qualifying plans.

You are responsible for ensuring you have the legal right to upload and process materials through the service and to share them with the subprocessors we engage. Always review AI-generated output and supporting audit materials before relying on them in legal proceedings. Maintain the confidentiality of your credentials and do not commit sensitive artifacts to public repositories.

For security inquiries or to report a vulnerability, contact the operator listed in your engagement letter. We maintain an incident response process and will notify affected customers in accordance with our Data Processing Addendum.