Trust & Security
Built for legal-grade trust.
Your case is some of the most sensitive content you'll ever put in a SaaS. Advottic treats it that way. Every section below describes what we do today, in plain language.
Last reviewed: 2026-08-10
Encrypted everywhere
TLS 1.2+ in transit, AES-256 at rest. Per-row access enforced server-side, not in the client.
Your story stays yours
Bella and Advottic Review send your case content to our processing partners only to produce the answer you asked for.
You control access
Viewer, editor, attorney, witness, and represented-client roles. Revoke any collaborator at any time. Fine-grained sharing is the default, not the exception.
Case content safety
How we keep your case content safe
In transit
At rest
- Database: Postgres on Supabase, AES-256 encrypted at rest. Per-row access is enforced by Row-Level Security (RLS) policies tied to your user ID, not by application code.
- Files: exhibit uploads live in a private storage bucket with path-scoped policies, so users only see files for cases they own or were invited into.
- Secrets: API keys and webhook secrets are stored as encrypted environment variables on Vercel. Service-role credentials never reach the browser.
Backups
Account protection
How we protect your account
Authentication
- Sign in via Google OAuth, Microsoft OAuth, or email magic link, issued by Supabase Auth. We never see or store your password.
- Session cookies are SameSite=Lax, so a browser will not send them along with a cross-site request.
- Sign-out invalidates the session immediately, on every device where you are signed in, and clears auth cookies in the browser.
Multi-factor authentication
Ending a session
Controls
Controls that keep you in control
Role-based sharing
Invite collaborators as viewer, editor, attorney, witness, or represented client. Each role sees only what they need.
Per-case audit trail
Firm owners and admins can review collaborator activity on a matter.
Self-serve data export
Download every case, exhibit, and review you've created at any time, for any reason.
Delete on demand
Permanent account deletion from your profile.
Data handling
Your data. Your eyes only.
What we collect
Assistant features
Where it lives
Retention
Sub-processors
Who we trust with what
These are the parties that process data on our behalf, and what each one receives.
| Sub-processor | Purpose | Region |
|---|---|---|
| Vercel | Application hosting, edge network | USA |
| Supabase | Auth, Postgres database, file storage | USA |
| Anthropic | Natural-language processing for Bella + Advottic Review: case titles and descriptions, exhibit text, your queries | USA |
| OpenAI | Transcription of audio and video exhibits: the uploaded media file itself and its filename | USA |
| Stripe | Subscription billing + customer portal | USA |
| Resend | Transactional email (sign-in, invites) | USA |
| Twilio | Safe Witness SMS: recipient phone number, alert text, location link, verification PIN | USA |
| Google Maps | Geocoding and map images: place names drawn from case evidence, and Safe Witness coordinates | USA |
| OpenStreetMap (Nominatim) | Reverse geocoding: latitude and longitude only | EU |
| Microsoft Graph | Calendar sync for firms that connect it: meeting subjects, times, attendees | USA |
| Zoom | Meeting creation for firms that connect it: meeting topic and time | USA |
| Cloudflare | Turnstile bot check: challenge token and requesting IP address | USA |
| Apple / Google / Mozilla push services | Browser push notifications: routing endpoint plus an encrypted payload they cannot read | USA |
| RevenueCat | Mobile purchase records: user identifier and entitlement status | USA |
| CourtListener | Case-law lookup: the search query text only | USA |
We will email account owners at least 30 days before adding a sub-processor that handles case content.
Disclosure
Found a vulnerability?
Please report it directly to security@advottic.com with the subject [security]. We aim to acknowledge within 2 business days. Please give us a reasonable window to investigate and fix before public disclosure. We do not currently run a paid bug bounty, but we recognize meaningful reports publicly with permission.
Common questions
You have questions. We have answers.
What happens to my case content when I use Bella or Advottic Review?
Can my attorney see my case without an Advottic account?
What happens to my data if I cancel?
Are you SOC 2 / HIPAA / ISO 27001 certified?
Where is my data stored?
Have a security or compliance question we didn't cover?
Email security@advottic.com and we'll respond within 2 business days.
