Your security comes first.
Juriton is built for legal work where confidentiality is not optional. Here is how we protect your matters, in plain terms.
How Juriton protects your matters. The short version of our security white paper, section by section.
Where your data lives
Your database records, uploaded files, transcripts and backups are stored in Sydney, Australia, on AWS's ap-southeast-2 region. The application servers that handle your requests run in Sydney too. AI processing of document content takes place outside Australia with named providers under no-training terms.
Encryption
AES-256 at rest with keys held in validated hardware security modules, TLS 1.2 or higher in transit and backups encrypted to the same standard. Connected third-party credentials are encrypted a second time at the application layer. Files are only ever served through signed links that expire within minutes.
Keeping each firm's data separate
Every workspace is a separate tenant. Every request is resolved to a workspace at the server before any data is read, and Row Level Security in the database enforces the same boundary underneath. There is no cross-tenant data sharing of any kind.
Sign-in and access
Sign-in is passwordless: a one-time code by email, or your Google, Apple or Microsoft account. Multi-factor authentication is available to every user and mandatory for Juriton's own administrators. Access within a workspace is role-based, and Juriton staff do not read customer content as a routine matter.
How we use AI
Every provider we use is contractually barred from training on your content. Content sent for processing is held only for a fixed abuse-monitoring window of 30 to 55 days depending on the provider, then deleted. No model has internet access or any tool that could send your content elsewhere. Every output carries a citation to the source page so you can check the model's work.
How we build
Changes ship through pull requests with a preview reviewed before merge. Dependency advisories are reviewed and patched, with high-severity fixes shipped within days. Three internal security reviews ran in 2026 and every finding was tracked to closure. An external penetration test is the next item on our roadmap.
If something goes wrong
A documented incident plan with four severity tiers. Any exposure of customer data is paged immediately and affected customers are told within hours. Our contractual commitment is notification within 72 hours of a personal-data breach, and sooner where customer data is exposed. Australian breach obligations, Commonwealth, NSW and Queensland, are built into the plan.
Backups
Daily encrypted backups, retained seven days in Sydney. Recovery targets of four hours to restore service and a 24-hour recovery point. Backups cover the database; uploaded documents are stored separately in Sydney with their own redundancy.
Your data, your call
Deleting a matter removes its records, index, drafts and audit trail immediately. Workspace and account deletion on request within 30 days, with backups ageing out seven days after that. Generated artefacts can be exported and source documents downloaded at any time.
Built for Australian litigation
Privilege is the headline risk in our design. Nothing leaves the boundary except to named processors under confidentiality, the audit log records events not content, and every output is a drafting aid with its sources shown. Our witness workflow is built around the Supreme Court of NSW's Practice Note on generative AI and witness evidence.

Security white paper
Request the security white paper.
The full document runs to fourteen sections plus a section on Australian litigation, and names every provider we rely on and where it operates. We answer SIG Lite and CAIQ questionnaires on request.