Security by Design

How we protect client information, run our infrastructure, and approach trust for every legal AI system we build.

This page is maintained by Achilleon Labs to answer common security and privacy questions about our website and services. It describes the controls and practices we have in place today. For client-specific deployment details, please contact us directly.

Our Approach

Trust is engineered, not assumed.

Security for elite legal work means more than checklists. It means designing systems where confidentiality, ownership, and accountability are core architectural constraints.

Private by Design

Every bespoke system is architected to run in the firm's own environment. We do not commingle client data, train shared models on client material, or rely on multi-tenant access patterns that blur ownership boundaries.

Infrastructure You Control

Deployments are provisioned on infrastructure chosen by the firm — private cloud, VPC, or on-premise — with single-tenant isolation and full ownership of the resulting codebase, weights, and prompts.

Traceability

Agent actions, retrievals, and generated outputs are logged and auditable. This gives firms the transparency they need to review, justify, and govern AI-assisted work.

Role-Based Access

Permissions are scoped to roles, practice groups, and matters. The same privilege principles that protect client work product are embedded into the systems we build.

This Website

What we collect, how we handle it, and who can access it.

Contact form data

When you submit the contact form, we collect the information you provide — such as name, email, company, country, job title, and organisation type — so we can respond to your enquiry. This information is stored in our backend database and is not shared with third parties for marketing purposes.

Email notifications

We send transactional emails to confirm receipt of your enquiry and to notify our team. These emails are delivered through Lovable's managed email infrastructure and contain only the information required to handle your request.

Cookies and analytics

This site does not use third-party analytics or advertising cookies. We do not track visitors across the web or build advertising profiles from your visit.

Data in transit

Connections to this site and our backend are encrypted with TLS. Form submissions and email notifications travel over encrypted channels.

Report a vulnerability

If you believe you have discovered a security issue affecting this website or our services, please let us know. Include enough detail for us to reproduce and assess the issue responsibly.

Contact us to report an issue

Privacy requests

You can ask to access, update, or delete the personal information you have submitted through our contact form. We will handle your request in line with applicable data protection law.

Submit a privacy request

Questions about security for your firm?

Schedule a private briefing and we will walk you through our architecture, deployment options, and data handling practices.

Schedule a Call