Trust

Security & Trust

Last reviewed: TODO — not yet published

Empatine handles institutional knowledge and client relationship data for firms where confidentiality is the job, not a footnote. This page exists to answer the questions a managing partner, GC, or IT lead asks before a firm's data goes anywhere near a new system. Most of the specifics below are not yet filled in — the sections exist so they can be, honestly, as each is actually true.

Data residency

TODO (Erik): Where client data is stored and processed (region/provider), and whether a firm can choose or restrict that region.

Encryption in transit and at rest

TODO (Erik): Encryption standards used for data moving to/from Empatine and for data stored at rest, and key management approach.

Tenancy and isolation model

TODO (Erik): Whether tenancy is single- or multi-tenant, and how firm-level data is isolated from other firms on the platform.

Client and matter isolation within a firm

A firm that holds two competing brands, or a law firm acting for opposing parties, needs certainty that context from one client or matter never crosses into another inside the same account.

TODO (Erik): The actual isolation mechanism between client/matter scopes inside a single tenant — this needs to be described accurately by whoever built it, not drafted speculatively here.

Sub-processors

TODO (Erik): List of third parties (model providers, infrastructure, analytics) that process firm or client data on Empatine's behalf.

Certification status

Empatine is pre-launch and holds no certifications yet. Rather than imply otherwise, here is the honest state and the plan:

Security questionnaires

For a vendor security review or questionnaire, contact hello@empatine.com. TODO (Erik): consider a dedicated address (e.g. security@empatine.com) once it exists — using the general inbox for now rather than inventing one.