Security

Where your matter data sits, and who can reach it.

Diligence instructions are often more sensitive than the findings. This page states plainly how the platform is built. It does not claim certifications we do not hold.

Access model

Every matter belongs to a user and to that user's firm. Access is enforced in the database itself with row-level security, not only in the application: a query issued on behalf of one firm cannot return another firm's rows, whatever the interface asks for.

Firm administrators can see matters opened by their own firm. CheckRisk platform administrators can see all matters for operational and support purposes, and every such access path runs through functions that record activity to an append-only trail.

Encryption

All traffic runs over TLS. Matter records, uploaded prior reports and generated reports are stored on managed infrastructure with encryption at rest provided by that platform. Uploaded files are held in a private bucket that is not publicly readable and is reachable only through authenticated, matter-scoped requests.

Authentication

Sign-in is by emailed link or by Google, with a password option for firms whose IT policy expects one. There is no shareable no-login report link: a report opens only inside an authenticated session tied to the email that ordered it.

Audit trail

Each matter carries an append-only log: acceptable-use screening decisions, payment, each research and drafting stage, delivery, and every source-inquiry status change. Entries are written, never edited or removed. This is the record if a report is ever challenged.

AI processing

Research and drafting use third-party large language models with web search. Matter instructions, subject details and any prior report text you upload are sent to that model provider as part of the research prompt. Do not upload material you are not permitted to disclose to a processor.

Retention

Matters, reports and uploaded prior reports are retained for as long as the account is open, so that counsel can return to the file. Write to us to have a specific matter or an entire account deleted, and we will do so, subject to any records we are required to keep for accounting purposes.

Reporting a vulnerability

If you believe you have found a security issue, write to security@checkrisk.io with enough detail to reproduce it. Please do not test against other firms' data, and give us a reasonable window to respond before disclosing publicly.

What we do not claim

CheckRisk holds no SOC 2, ISO 27001, HIPAA or PCI attestation, and this page should not be read as one. If your firm requires a formal security review before instructing us, write to us and we will answer your questionnaire directly.