Trust Center
datum is the evidence-controlled case workspace for construction claims and arbitration. This page is the single place for our security documentation, subprocessors and compliance posture - with every item marked live, documented, or roadmap. We never publish a claim we cannot evidence; it is the same discipline the product enforces on claims.
TLS in transit; AES-256 at rest via managed keys; encrypted, restore-verified backups.
Contractual and architectural. Org-scoped learning only; nothing crosses tenants.
Per-organisation row-level security at the database; append-only audit log on every human override and deletion.
Control-by-control posture in the launch compliance checklist; UAE counsel sign-off is a launch gate.
Certification is a funded post-revenue milestone. We publish the honest state instead of a claim.
Shared by email, under NDA where appropriate. Drafts are labelled as drafts - you will never receive a document presented as more final than it is.
Every service that touches any datum data, what it does, where it runs, and what it can see. Changes to this list are notified to clients in advance.
| Vendor | Role | Region | Data exposure |
|---|---|---|---|
| Anthropic | LLM inference (extraction, drafting, verification) | US | Case text at inference time only; no training on API data; zero-data-retention terms on enterprise tier |
| Fly.io | Application compute, database, queue | EU (Frankfurt) - me-central-1 planned pre-client | Case records and derived data, per-org isolated |
| Tigris Data | Object storage | Co-located with compute | Document originals and page images, encrypted at rest |
| Vercel | Website hosting and DNS | Global edge | No case records; public site and workspace UI shell only |
| Clerk | Authentication | US | Sign-in identities (name, email); no case records |
| Microsoft 365 | Business email | EU/UAE per tenant | Business correspondence; no case records by policy |
| GitHub | Source code hosting | US | Code only; never client data |
Running a vendor review? Send the questionnaire as-is - our standard answers document covers the common frameworks, and anything it does not cover gets a written answer within two business days.
Start a security review