Security & Trust
Last reviewed: TODO — not yet published
Empatine handles institutional knowledge and client relationship data for firms where confidentiality is the job, not a footnote. This page exists to answer the questions a managing partner, GC, or IT lead asks before a firm's data goes anywhere near a new system. Most of the specifics below are not yet filled in — the sections exist so they can be, honestly, as each is actually true.
Data residency
Encryption in transit and at rest
Tenancy and isolation model
Client and matter isolation within a firm
A firm that holds two competing brands, or a law firm acting for opposing parties, needs certainty that context from one client or matter never crosses into another inside the same account.
Sub-processors
Certification status
Empatine is pre-launch and holds no certifications yet. Rather than imply otherwise, here is the honest state and the plan:
- SOC 2 Type ITODO: target date
- SOC 2 Type IITODO: target date
- ISO 27001TODO: target date, if applicable
Security questionnaires
For a vendor security review or questionnaire, contact hello@empatine.com. TODO (Erik): consider a dedicated address (e.g. security@empatine.com) once it exists — using the general inbox for now rather than inventing one.