Has anyone here opened your client's file?
It is the first question a managing partner asks and the one security pages answer least. Ours is 6 times last quarter, across 1,847 live matters, every one of them approved by the firm first. The whole log is below, including the 2 we asked for and were refused.
Every access, Q2 2026
Generated by the access system, not written by hand. 2 of the 6 involved reading a document; the rest saw file names and error codes.
8
requests made
6
approved by the firm
2
refused by the firm
19 min
average session
Support engineer. Upload of a 2 GB bundle stalled at 94 per cent. Needed file sizes and checksums, not contents.
Support engineer. Reported that a clause was cited with the wrong locator. Reproducing it required the document.
Support engineer. Scanned Arabic annexes failing extraction. Page-level error codes were enough to diagnose.
Reliability engineer. Index rebuild after a storage fault. Required object listings to verify nothing was lost.
Support engineer. Follow-up to ACC-0418 after the fix, to confirm the locator now resolved correctly.
Support engineer. An answer omitted a document the partner expected. Diagnosing retrieval needed both.
The firm declined. We could not reproduce it, so the matter was re-indexed without anyone reading it and the partner re-ran the question. That took four days instead of an afternoon, and it was their call to make.
Support engineer. Billing discrepancy on document counts. Needed counts per matter, no contents.
Engineering. Requested a redacted sample of failing scans to improve Arabic extraction generally.
Refused, and correctly. This was our benefit, not theirs — a product improvement dressed up as support. It should not have been asked for, and the request is on the log so that it cannot quietly become normal.
113 minutes in three months. The refusals matter more than the total: a control nobody has ever exercised is not a control, it is a paragraph. Both are on the log, including the one we should not have asked for.
What "delete the matter" removes
Everyone offers deletion. The question is what it reaches — because a system that deletes the file and keeps the extracted text has deleted nothing that matters.
Embeddings are the one people leave behind. They are numbers rather than words, which makes them feel like a different category, and they can be inverted back toward the text they came from. They go with everything else.
- Document storage Immediately The uploaded files themselves, removed on the delete call rather than flagged as hidden.
- Extracted text Immediately The parsed layer the index is built from. Deleting the original and keeping this is the usual sleight of hand.
- Search index Immediately Removed and the index rebuilt, so the matter cannot surface in a later search.
- Vector embeddings Immediately The numeric representations. They are derived from the text and can leak it back, so they go with it.
- Encrypted backups Within 30 days Backups roll on a thirty-day cycle. We will not restore a deleted matter from one, and it ages out.
- Access audit log Retained The record of who opened what survives the thing it describes — on purpose. A log you can delete is not evidence, and the whole point of the ledger above is that it cannot be edited after the fact. It holds identifiers and reasons, never document contents.
One row does not clear, and it is the one worth arguing about. The access ledger outlives the matter it describes, because a log you can delete is not evidence of anything.
Who holds the key
The strongest version of everything above is the one where our good behaviour is not required.
- Encrypted in transit and at rest
- The unremarkable part, and table stakes. Worth stating only so its absence would be noticeable.
- A separate key per firm
- Matters for one firm are encrypted under that firm's key. A key compromise does not widen beyond it.
- Customer-held keys, if you want them
- You can hold the key yourself. Revoke it and the data is unreadable to us within the hour — including to anyone who might otherwise have appeared on the ledger.
- The trade that comes with it
- Holding your own key means we cannot recover anything if you lose it. Firms that take this option should read that sentence twice, because there is no second path.
Where it all sits
Storage, index, embeddings and the model that reads them are in Jeddah, with Riyadh available. Nothing about a request leaves the country, including the parts that are easy to forget — logs, error traces and the queue a document waits in before it is processed.
The request path, drawn4 companies touch it besides us
Four, all inside the Kingdom, covering hosting, inference, transactional email and error monitoring. They are named — with what each one touches and the contract that binds it — in the security pack that goes with the agreement, and to any firm that asks before signing. They are not listed here, because a marketing page is the wrong place to publish somebody else's infrastructure and we would rather answer the question properly.
If it goes wrong, this is the clock
Committed in the agreement, not on this page. A page can be edited.
-
1 hour
You are told, if your data is involved. Before we know the cause, and before it is convenient.
-
24 hours
A written account of what happened, what was reached and what was not.
-
72 hours
Regulator notification where the law requires it, with your counsel in the loop rather than informed afterwards.
-
10 days
A published write-up. Not a status page colour — the actual sequence, including what we got wrong.
Four things this page cannot do
Including the one where the real risk is not us.
- This log is ours to keep honest
- It is generated by the access system rather than typed by a person, and it is append-only. That is a design, not a proof: you are still taking our word that the pipe is wired to the page. Firms that need more than our word should take the customer-held key.
- The biggest risk is on your side
- Across every incident we have seen, no document has left through us. They leave through a forwarded email, a personal device, a departing associate. Nothing on this page addresses that, and it is where your exposure actually is.
- Certification is in progress, not complete
- We hold no completed third-party audit yet. Saying so is more useful than a logo, and we will publish the report itself when there is one rather than the badge.
- Residency is not immunity
- Keeping data in the Kingdom answers where it sits and who has jurisdiction over it. It does not make it unreachable, and any vendor implying otherwise is selling geography as if it were cryptography.
Ask us the awkward version of any of this
The security pack — sub-processors named, the access-control design, the contract terms behind the clock above — goes to any firm evaluating us, before signing anything.