August maintains ISO 27001:2022, SOC 2 Type II (unqualified opinion, zero exceptions), and CASA Verified status. Annual surveillance audits and penetration testing are performed regularly.
Security and Privacy Overview
August is an enterprise-grade AI platform built specifically for law firms and in-house legal teams, with security and confidentiality designed into every layer of the architecture.
August Trust Center
Enterprise-grade security certifications and attestations.
Data residency • Zero training • End-to-end encryption
ISO 27001:2022 SOC 2 Type II CASA Verified TLS 1.2+ AES-256 SSO + MFA
Security Feature | Status |
|---|---|
Zero training on customer data | ✅ Verified |
End-to-end encryption | ✅ Verified |
Single-tenant architecture | ✅ Verified |
Data residency pinning | ✅ Verified |
Ethical walls / Matter isolation | ✅ Verified |
99.9% uptime SLA | ✅ Verified |
Independent Certifications
August maintains the most stringent security certifications for legal work:
ISO 27001:2022 Certified — A full Information Security Management System (ISMS) across all August operations.
SOC 2 Type II — Independent audit with an unqualified opinion and zero exceptions.
CASA Verified — Cloud Security Alliance Security, Trust, Assurance, and Risk (STAR) verification.
Annual Penetration Testing — Black-box and grey-box testing with rapid remediation.
Data Isolation and Confidentiality
August uses a single-tenant, siloed architecture that keeps each firm's data completely separate:
Private Tenant per Client — Compute, storage, and network isolation means one firm's information never mixes with another's environment.
User Profile Siloing — Within a firm, user profiles are fully siloed unless users proactively share chats or create shared workspaces.
No Visibility into User Data — August does not have visibility into user inputs, uploads, or outputs.
Data Residency Pinning — Data is pinned to your selected geographic region at the infrastructure level.
Ethical Walls and Matter Isolation
August's Personas feature enforces hard client and matter-level walls with role-based access controls. Data is segregated not only between tenants but between matters within your organization.
Zero Training on Your Data
Your legal work product is never used to improve AI models:
Documents, prompts, outputs, metadata, and derived data are never used for model training, fine-tuning, analytics, or product improvement.
August has contractual agreements with each language model provider (Llama, Anthropic, and OpenAI) prohibiting training on or retention of user content.
Foundation model providers process data ephemerally — they do not store, log, review, or reuse your content.
Encryption and Key Management
All data is protected with enterprise-grade encryption:
Encryption in Transit — TLS 1.2+ for all data moving between your device and August.
Encryption at Rest — AES-256 encryption for all stored documents, database records, and backups.
Key Protection — All encryption keys are protected by Hardware Security Modules (HSMs) and rotated annually.
Model-Agnostic Secure Gateway — Policy enforcement, routing controls, and full auditability across all AI model interactions.
AI Model Security
August secures AI model interactions at every layer:
Zero Model Provider Retention — Foundation model providers do not retain your data after processing.
Bring Your Own Key (BYOK) — For certain model providers (including Anthropic via AWS Bedrock), you can use your own encryption keys for additional control.
Secure Gateway — All model interactions pass through a secure gateway with policy enforcement and full auditability.
Access Controls and Identity
August integrates with enterprise identity systems:
SSO with MFA — Single sign-on via SAML, OIDC, and OAuth2 with multi-factor authentication enforced.
SCIM Integration — Automated user provisioning and deprovisioning.
Role-Based Access Controls (RBAC) — Granular permissions based on user roles.
Ethical Walls — Matter-level access controls via Personas to enforce conflicts and confidentiality boundaries.
Quarterly Access Reviews — Regular audits of access permissions.
Audit Trails
Comprehensive audit trails log all system activity: user actions, AI outputs, document access, and administrative changes. Every action is attributable to a specific user. Retention is configurable from 1 to 10 years, with logs protected against tampering.
Internal Access Controls
August maintains strict controls on employee access to production systems:
Zero Customer Data on Employee Devices — Customer documents are never stored on employee workstations.
Least-Privilege, Just-In-Time Access — Production data access is limited to a defined set of engineers on a least-privilege, just-in-time basis. Every access event is logged and reviewed.
No Admin-Privileged Service Roles — No service roles have administrator privileges.
Short-Lived Credentials — Production access requires SSO, MFA, and short-lived credentials. No persistent tokens.
Engineering Workflows Use Anonymized Data — Real data access requires explicit approval.
Endpoint Security — All company-issued laptops run MDM, EDR with daily signature updates, and full-disk encryption.
Subprocessors
Each subprocessor is contractually bound to data use restrictions, including prohibition on using customer data for training.
Subprocessor | Role | Data Training |
|---|---|---|
Amazon Web Services | Infrastructure and hosting | Prohibited |
Anthropic (via AWS Bedrock) | Foundation model provider (BYOK) | Prohibited |
OpenAI LLC | Foundation model provider | Prohibited |
Microsoft Corporation | Office integration framework | Prohibited |
Google Cloud Platform | Compute services | Prohibited |
Weaviate | Vector storage | Prohibited |
Supabase | SQL solution | Prohibited |
Reducto | OCR provider | Prohibited |
Customers receive 30 days advance notice before a new subprocessor begins processing customer data.
SLA and Service Commitments
August provides enterprise-grade service level commitments:
99.9% Monthly Uptime — High availability commitment for the platform.
30-Minute Critical Issue Response — Rapid response for critical severity issues.
7-Day Critical CVE Remediation — Security vulnerabilities addressed within 7 days for critical CVEs.
Security Operations
August maintains robust security operations:
Secure SDLC Practices — Security built into the software development lifecycle.
Continuous Monitoring — Real-time threat detection and response.
Incident Response & BCDR — Tested plans for incident response and business continuity/disaster recovery.
Integrations Security
August integrates with your existing tools while maintaining security standards:
Microsoft Word and Outlook add-ins — Work seamlessly across Word, Outlook, and SharePoint/OneDrive.
SharePoint — Full SharePoint integration for enterprise document management.
Google Drive — Access and import documents directly from Google Drive.
Dropbox — Connect your Dropbox for document sync and access.
All integrations follow the same encryption and access control standards.
What This Means for Your Practice
When you use August for legal work:
Your client's documents and privileged information stay isolated and protected.
Nothing you upload, generate, or discuss is used to train AI models.
You control who within your organization can access shared workspaces.
August cannot see your legal work product.
Matter-level ethical walls protect confidentiality within your firm.
For questions about security certifications, data processing agreements, subprocessor documentation, or compliance documentation, contact your August account team or visit the legal documentation hub.
Security FAQ
What certifications does August hold?
Is August single-tenant or multi-tenant?
August uses a single-tenant, siloed architecture.Each client gets their own private tenant with compute, storage, and network isolation.
Can August see my legal work product?
No. August does not have visibility into user inputs, uploads, or outputs.
Will my data be used to train AI models?
No. Documents, prompts, outputs, metadata, and derived data are never used for model training, fine-tuning, analytics, or product improvement. This is contractually enforced with all model providers.
Where is my data stored?
Data is stored in your selected geographic region through data residency pinning. August supports both US and EU deployment options.
How is my data encrypted?
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are protected by HSMs and rotated annually.
What access controls are in place?
August enforces SSO with MFA, SCIM integration for automated provisioning, role-based access controls, ethical walls via Personas for matter-level isolation, and quarterly access reviews.
Can I use my own encryption keys?
Yes. For certain model providers, including Anthropic via AWS Bedrock, you can use Bring Your Own Key (BYOK) for additional control.
What is August's uptime commitment?
99.9% monthly uptime. Critical issues receive a 30-minute response time, and critical CVEs are addressed within 7 days.
How do I report a security vulnerability?
Contact your August account team through responsible disclosure. August maintains incident response and business continuity plans with continuous monitoring for threat detection.
Where can I find more security documentation?
Download the official August Security Whitepaper (v1.1, May 2026) and client matter documentation:
For data processing agreements, subprocessor documentation, or compliance questions, contact your August account team.