← Back to homepage
Bar Ethics Brief →
Security & Data Handling
Last updated: August 2026 · Questions? ramtekintelligence@gmail.com
✓ Encrypted in Transit (TLS 1.2+)
✓ No Training on Your Data
✓ httpOnly Cookies
✓ No Persistent AI Storage
✓ Optional Two-Factor Authentication
How Your Data Is Handled
Ramtek Intelligence processes legal documents, client communications, and firm data exclusively to provide the services you request. We do not sell, share, or monetize your data in any form.
Encryption & Transmission
- All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Authentication tokens are stored in httpOnly, Secure cookies — never in localStorage — making them inaccessible to JavaScript and resistant to XSS attacks.
- Our database (PostgreSQL) uses encrypted connections for all queries.
AI Processing
Ramtek Intelligence uses a commercial AI inference API to power its tools. Here is what that means for your firm's data:
- No training on your inputs. Per our AI provider's usage policy, data submitted via the API is not used to train AI models. Your documents and client information do not become part of any training dataset.
- No long-term storage by the AI. Prompts and responses are processed in real time. The AI provider may retain API data for a limited period (up to 30 days) solely for trust-and-safety monitoring, after which it is deleted — it is never used for training.
- Inputs are processed, not stored, by the model. Each request is stateless — the AI has no memory of prior sessions or other firms' data.
Data Storage & Retention
- Firm data (users, documents, workflows, contacts) is stored in our database and retained for the duration of your subscription.
- After cancellation, firm data is retained for 30 days so you can resubscribe or export it, then permanently deleted from production. Your firm administrator is emailed a reminder before the deadline, and resubscribing at any point beforehand keeps your data intact.
- You may request immediate deletion at any time by emailing ramtekintelligence@gmail.com.
- We do not retain copies of documents you submit for AI analysis beyond what is stored in your account.
Access Controls
- Each firm's data is isolated by firm ID — users at one firm cannot access another firm's data.
- Passwords are hashed using bcrypt before storage. We never store plaintext passwords.
- Optional two-factor authentication (authenticator app / TOTP) is available on every account, enabled from Account Settings.
- Team member access is managed by the firm admin. Removed users immediately lose all access.
- Rate limiting and CSRF protection are enforced on all authenticated endpoints.
- Billing webhooks are cryptographically signature-verified — a request claiming to be from our payment processor is rejected unless the signature proves it.
Ongoing Monitoring
Beyond point-in-time security controls, we run automated checks against our own production systems every day — verifying billing configuration, database connectivity, and core access controls (like unauthenticated requests correctly being rejected) are still behaving as intended. Failures alert our team immediately rather than being discovered by a customer first.
ABA 1.6 Compliance & Vendor Assessment
Attorneys using cloud-based AI tools must exercise reasonable due diligence under ABA Model Rule 1.6 (Confidentiality) and Rule 5.3 (Supervision of Non-Lawyer Assistance). The following answers the questions your bar counsel or malpractice carrier will ask:
- Does the AI use client data for training? No. Our AI provider's usage policy prohibits use of API inputs to train models. Documents are processed in real time and retained by the provider only briefly (up to 30 days, for trust-and-safety monitoring) before deletion.
- Is data encrypted in transit and at rest? Yes. TLS 1.2+ in transit. Our database provider encrypts data at rest and is SOC 2 Type II certified with a formal Data Processing Agreement available.
- Can we get a DPA? Yes. Email ramtekintelligence@gmail.com to request a Data Processing Agreement. If your matters involve protected health information, contact us to discuss your compliance requirements before uploading any PHI.
- Does an attorney review the output? Yes — by design. Every tool surfaces a mandatory attorney-review disclaimer. The platform generates work product; attorney supervision remains with your firm at all times.
- Is a written vendor assessment available? Yes. This page, our Bar Ethics brief, and the subprocessor list below constitute our vendor assessment documentation — suitable for your firm's vendor file to satisfy the Rule 1.1 competence review.
Subprocessors
- AI Inference Provider — Processes AI queries only. Data is not retained for training. Full provider details available in our DPA on request.
- Database Provider — PostgreSQL database hosting. SOC 2 Type II certified. Full provider details available in our DPA on request.
- Application Hosting Provider — Data processed in the United States. Full provider details available in our DPA on request.
- Payment Processor — PCI DSS Level 1 certified. Ramtek never stores card numbers. Full provider details available in our DPA on request.
- Email Delivery Provider — Transactional email delivery (password resets, invitations). Full provider details available in our DPA on request.
Attorney-Client Privilege
Ramtek Intelligence is a software tool, not a legal service provider. We are not a party to the attorney-client relationship. Data you submit through our platform remains under your firm's control. We recommend against submitting highly sensitive client information (e.g., sealed case materials, grand jury matters) through any cloud-based platform without first consulting your malpractice carrier.
For the full ABA ethics analysis (Formal Opinion 477R, 512, Florida Bar 24-1), see our Bar Ethics & Compliance brief →
Incident Response
In the event of a data security incident, we will notify affected firms within 72 hours of discovery via the email address on file. We will provide a clear description of what occurred, what data was affected, and the steps taken to remediate.
This document is provided for informational purposes and does not constitute a Data Processing Agreement (DPA). Firms requiring a formal DPA for compliance purposes should contact us at ramtekintelligence@gmail.com.