Mediation and settlement communications are confidential — protected by rule or statute in nearly every state, and central to how these cases resolve. DétenteIQ was designed from the first line to keep them that way, so the tool you prepare in never becomes the weak link. Your matter data stays yours, encrypted with a key we don't hold.
The open question was never whether mediation is confidential — it's whether the software you prepare in honors that. DétenteIQ was built so it does at the architecture level, not as a policy you take on faith. Here's what that means in practice:
Every record is encrypted at rest with AES-256, and every connection is TLS. A stolen database or backup file is unreadable ciphertext. This is the baseline — no configuration required.
Switch it on and matter data is encrypted and decrypted in your browser, with a key derived from your firm's credentials that never reaches our servers. We hold ciphertext only. There is no server-side copy of your key to steal, subpoena, or misuse.
No hand-waving. Here is the lifecycle of a single valuation or settlement figure with end-to-end encryption enabled.
A firm encryption key is derived on your device from your firm's credentials. It is never transmitted to or stored by DétenteIQ.
The figure is encrypted locally. What travels to our servers is ciphertext plus a searchable label (case name / number / mediator).
Our database holds the ciphertext. Nothing in our systems — logs, backups, support tools — can turn it back into a number.
When an authorized user at your firm opens the matter, their browser decrypts it with the firm key. We are never in the loop.
| Data | To DétenteIQ, it is… |
| Case name / number / mediator (searchable labels) | visible |
| Valuations, reserves, settlement authority | encrypted |
| Offers, demands, brackets, final settlements | encrypted |
| Parties, attorneys, adjusters, carriers | encrypted |
| Strategy, game plans, notes, drafts | encrypted |
| AI prompts & answers about a matter | never transit us |
The searchable labels exist so the app can list and open matters without decrypting them. If even a case caption is too sensitive, name matters by internal code — the label is whatever you type.
We cannot reset your users' passwords or sign in as them. On a zero-knowledge firm we couldn't read the data even if we did — there is no key on our side.
Any support access is scoped and written to your firm's audit trail. You see what was touched, and when.
Every query is scoped to your firm. No interface returns another firm's records — every firm is walled off from every other firm on the platform, at the data layer, not just the UI.
The Assistant runs browser-direct to the model provider you configure, or fully on-device. Nothing case-related transits our servers, and party names can be redacted on-device before a prompt is sent.
AES-256 at rest · TLS in transit · optional end-to-end (zero-knowledge) encryption · no operator backdoor · audited support access · strict tenant isolation · SSO · browser-direct or on-device AI.
A third-party penetration test and a SOC 2 examination are on our roadmap. We'll post each here, with the date, as it's completed.
We'll answer the security questionnaire, sign the NDA, and walk your reviewers through exactly how the encryption works.