Security, privacy & confidentiality

Built for privacy, security, and confidentiality.

Mediation and settlement communications are confidential — protected by rule or statute in nearly every state, and central to how these cases resolve. DétenteIQ was designed from the first line to keep them that way, so the tool you prepare in never becomes the weak link. Your matter data stays yours, encrypted with a key we don't hold.

Short version: everything is encrypted at rest with AES-256. Turn on the end-to-end option and your matter data is encrypted in your browser with a key we never receive — we store only ciphertext, and we cannot read it or produce it in readable form to a subpoena served on us.
Confidentiality

Designed around the confidentiality your matters already require.

The open question was never whether mediation is confidential — it's whether the software you prepare in honors that. DétenteIQ was built so it does at the architecture level, not as a policy you take on faith. Here's what that means in practice:

DétenteIQ is built to support your confidentiality obligations, not to give legal advice about them — how privilege and the mediation-confidentiality rules apply to a given matter remains your firm's call.
Encryption

Two layers, and you choose the second.

On for every firm

AES-256 at rest

Every record is encrypted at rest with AES-256, and every connection is TLS. A stolen database or backup file is unreadable ciphertext. This is the baseline — no configuration required.

Optional · your key

End-to-end (zero-knowledge)

Switch it on and matter data is encrypted and decrypted in your browser, with a key derived from your firm's credentials that never reaches our servers. We hold ciphertext only. There is no server-side copy of your key to steal, subpoena, or misuse.

Zero-knowledge, concretely

How the end-to-end option actually works.

No hand-waving. Here is the lifecycle of a single valuation or settlement figure with end-to-end encryption enabled.

01 · Key

Derived in your browser

A firm encryption key is derived on your device from your firm's credentials. It is never transmitted to or stored by DétenteIQ.

02 · Encrypt

Before it leaves

The figure is encrypted locally. What travels to our servers is ciphertext plus a searchable label (case name / number / mediator).

03 · Store

Ciphertext only

Our database holds the ciphertext. Nothing in our systems — logs, backups, support tools — can turn it back into a number.

04 · Decrypt

Only in your browser

When an authorized user at your firm opens the matter, their browser decrypts it with the firm key. We are never in the loop.

Transparency

With end-to-end on, here is exactly what we can — and can't — see.

DataTo DétenteIQ, it is…
Case name / number / mediator (searchable labels)visible
Valuations, reserves, settlement authorityencrypted
Offers, demands, brackets, final settlementsencrypted
Parties, attorneys, adjusters, carriersencrypted
Strategy, game plans, notes, draftsencrypted
AI prompts & answers about a matternever transit us

The searchable labels exist so the app can list and open matters without decrypting them. If even a case caption is too sensitive, name matters by internal code — the label is whatever you type.

Controls & isolation

No backdoor, no bleed between firms.

Enforced

No operator backdoor

We cannot reset your users' passwords or sign in as them. On a zero-knowledge firm we couldn't read the data even if we did — there is no key on our side.

Logged

Support is on the record

Any support access is scoped and written to your firm's audit trail. You see what was touched, and when.

Enforced

Strict tenant isolation

Every query is scoped to your firm. No interface returns another firm's records — every firm is walled off from every other firm on the platform, at the data layer, not just the UI.

Your account

Your AI, your provider

The Assistant runs browser-direct to the model provider you configure, or fully on-device. Nothing case-related transits our servers, and party names can be redacted on-device before a prompt is sent.

Access & ownership

Your firm's data, your firm's controls.

What's live, and what's next

In place today — and on the roadmap.

In place today

Live now

AES-256 at rest · TLS in transit · optional end-to-end (zero-knowledge) encryption · no operator backdoor · audited support access · strict tenant isolation · SSO · browser-direct or on-device AI.

On the roadmap

Independent validation

A third-party penetration test and a SOC 2 examination are on our roadmap. We'll post each here, with the date, as it's completed.

Security is a moving target and this page is a snapshot, not a contract. For a security questionnaire, a data-processing addendum, or a technical deep-dive with your IT team, reach out and we'll walk your reviewers through the architecture directly.

Have your IT team put it to the test.

We'll answer the security questionnaire, sign the NDA, and walk your reviewers through exactly how the encryption works.