Private beta open with select legal teams across Nigeria, Ghana, Kenya, and South Africa. Request access

Security and governance

Confidential work, accountable AI use.

Alvary is built for work where an answer must be checked, defended, and traced back to its source. We state clearly where we are certified, where we are aligned, and where work is still in progress.

Certifications and alignment

Where we stand today.

We publish our certification status rather than imply more than we hold. Updated as audits complete.

SOC 2 Type II

Continuous control monitoring in place; independent CPA audit to be engaged. Report available under NDA on completion.

ISO 27001

Control set implemented and mapped against Annex A; management-system formalisation in progress ahead of a certification audit.

GDPR

Customer data processed in the EU. Data Processing Addendum and transfer terms provided during procurement.

NDPA

Nigeria Data Protection Act alignment; §41 cross-border transfer controls in active development.

ISO 42001

AI governance controls aligned to the standard; formal Annex A control mapping in progress.

How the platform protects work

The controls behind the work.

No training on client data

Firm and client data stay out of model-training pipelines. We don't sell or share inputs back to model vendors for training under any default configuration.

Permissioned execution

Important actions are controlled by role, matter access, budget, and risk level. Deliverable exports and client-facing steps require explicit human review.

Source-linked outputs

Legal answers, findings, and drafts retain links to underlying documents, paragraph anchors, and authorities. Unsourced claims are marked — never silently rewritten.

Reviewable audit record

Important actions, exports, and permission decisions are recorded so your team can review what happened, who approved it, and why.

Data handling

Where your data lives and how it moves.

Encryption

TLS 1.2+ in transit; AES-256 at rest, with keys held in a managed key vault. Customer-managed keys on the enterprise roadmap.

Residency

Customer data is processed in the EU today. US and Africa regions available for enterprise engagements on request.

Retention

Customer-controlled retention windows per matter and per artifact class. Hard delete on request.

Access

SSO via OIDC; SCIM provisioning; per-matter access controls below the tenant boundary.

Logging

Audit logs can be exported to your security tools. Important AI and workspace actions carry a signed event id.

Reporting

Found something? Tell us.

Email security@alvary.ai. We acknowledge reports within three business days and triage within ten. Researchers acting in good faith under our disclosure policy have our commitment that we will not pursue or support legal action over their research. Contact details are also published at /.well-known/security.txt per RFC 9116.

For data-protection enquiries, including a copy of the Data Processing Addendum, email privacy@alvary.ai. Our subprocessor list is published and we give notice before it changes.

Want the full security package?

We send a security brief, sample DPA, and architecture overview to qualified firms and in-house teams under NDA.

Request the brief