← Back to homepage
Bar Ethics Brief →
Security & Data Handling
Last updated: June 2026 · Questions? ramtekintelligence@gmail.com
✓ Encrypted in Transit (TLS 1.2+)
✓ No Training on Your Data
✓ httpOnly Cookies
✓ No Persistent AI Storage
How Your Data Is Handled
Ramtek Intelligence processes legal documents, client communications, and firm data exclusively to provide the services you request. We do not sell, share, or monetize your data in any form.
Encryption & Transmission
- All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Authentication tokens are stored in httpOnly, Secure cookies — never in localStorage — making them inaccessible to JavaScript and resistant to XSS attacks.
- Our database (PostgreSQL) uses encrypted connections for all queries.
AI Processing
Ramtek Intelligence uses a commercial AI inference API to power its tools. Here is what that means for your firm's data:
- No training on your inputs. Per our AI provider's usage policy, data submitted via the API is not used to train AI models. Your documents and client information do not become part of any training dataset.
- No long-term storage by the AI. Prompts and responses are processed in real time. The AI provider may retain API data for a limited period (up to 30 days) solely for trust-and-safety monitoring, after which it is deleted — it is never used for training.
- Inputs are processed, not stored, by the model. Each request is stateless — the AI has no memory of prior sessions or other firms' data.
Data Storage & Retention
- Firm data (users, documents, workflows, contacts) is stored in our database and retained for the duration of your subscription.
- Upon cancellation, you may request full data deletion by emailing ramtekintelligence@gmail.com. Deletion is completed within 30 days.
- We do not retain copies of documents you submit for AI analysis beyond what is stored in your account.
Access Controls
- Each firm's data is isolated by firm ID — users at one firm cannot access another firm's data.
- Passwords are hashed using bcrypt before storage. We never store plaintext passwords.
- Team member access is managed by the firm admin. Removed users immediately lose all access.
- Rate limiting and CSRF protection are enforced on all authenticated endpoints.
ABA 1.6 Compliance & Vendor Assessment
Attorneys using cloud-based AI tools must exercise reasonable due diligence under ABA Model Rule 1.6 (Confidentiality) and Rule 5.3 (Supervision of Non-Lawyer Assistance). The following answers the questions your bar counsel or malpractice carrier will ask:
- Does the AI use client data for training? No. Our AI provider's usage policy prohibits use of API inputs to train models. Documents are processed in real time and retained by the provider only briefly (up to 30 days, for trust-and-safety monitoring) before deletion.
- Is data encrypted in transit and at rest? Yes. TLS 1.2+ in transit. Our database provider encrypts data at rest and is SOC 2 Type II certified with a formal Data Processing Agreement available.
- Can we get a DPA? Yes. Email ramtekintelligence@gmail.com to request a Data Processing Agreement. If your matters involve protected health information, contact us to discuss your compliance requirements before uploading any PHI.
- Does an attorney review the output? Yes — by design. Every tool surfaces a mandatory attorney-review disclaimer. The platform generates work product; attorney supervision remains with your firm at all times.
- Is a written vendor assessment available? Yes. This page, our Bar Ethics brief, and the subprocessor list below constitute our vendor assessment documentation — suitable for your firm's vendor file to satisfy the Rule 1.1 competence review.
Subprocessors
- AI Inference Provider — Processes AI queries only. Data is not retained for training. Full provider details available in our DPA on request.
- Database Provider — PostgreSQL database hosting. SOC 2 Type II certified. Full provider details available in our DPA on request.
- Application Hosting Provider — Data processed in the United States. Full provider details available in our DPA on request.
- Payment Processor — PCI DSS Level 1 certified. Ramtek never stores card numbers. Full provider details available in our DPA on request.
- Email Delivery Provider — Transactional email delivery (password resets, invitations). Full provider details available in our DPA on request.
Attorney-Client Privilege
Ramtek Intelligence is a software tool, not a legal service provider. We are not a party to the attorney-client relationship. Data you submit through our platform remains under your firm's control. We recommend against submitting highly sensitive client information (e.g., sealed case materials, grand jury matters) through any cloud-based platform without first consulting your malpractice carrier.
For the full ABA ethics analysis (Formal Opinion 477R, 512, Florida Bar 24-1), see our Bar Ethics & Compliance brief →
Incident Response
In the event of a data security incident, we will notify affected firms within 72 hours of discovery via the email address on file. We will provide a clear description of what occurred, what data was affected, and the steps taken to remediate.
This document is provided for informational purposes and does not constitute a Data Processing Agreement (DPA). Firms requiring a formal DPA for compliance purposes should contact us at ramtekintelligence@gmail.com.