Security & Governance

Built for confidential legal work

Juroth is designed from the ground up for regulated industries and sensitive matters. Security and governance are core platform primitives — not add-ons.

SOC 2 Type IIGDPRISO 27001-alignedHIPAA-ready

Encryption

AES-256 at rest, TLS 1.3 in transit. Per-matter encryption keys with optional customer-managed keys.

Compliance

SOC 2 Type II, GDPR, and ISO 27001-aligned controls. Independent audits available under NDA.

Audit Logs

Every action — every user, every matter — captured in an immutable audit log with export support.

Access Controls

SSO via SAML/OIDC, SCIM provisioning, role-based and matter-level permissions.

Authentication

Enforced MFA, session policies, device controls, and IP allowlists.

Data Residency

Configurable data residency in US, EU, and UK regions. Regional isolation for regulated workloads.

Governance

Retention policies, legal holds, and granular data handling rules per workspace.

Privacy

Customer data is never used to train shared models. Full data-processing addenda available.

Trust & transparency

Our security overview, sub-processor list, DPA, and incident response policies are available on request. We're happy to walk your security team through our architecture.