Security
ClaireAI’s intake service handles information that law firms must protect. Our security approach combines access restrictions, tenant boundaries, protected integration paths, and operational controls. This page describes that approach and how to request supporting information. Contractual processing and security obligations are set out in the DPA and any separately executed security exhibit.
Security overview · Last updated: September 4, 2026 · Issued by Claire AI, LLC
Account and firm access
The portal uses authenticated access and server-side checks for roles and firm scope. Firm permissions differ from privileged ClaireAI operator permissions. Customers should limit authorized users, protect credentials, keep firm contact details current, and promptly revoke access that is no longer needed.
Service and integration boundaries
ClaireAI’s service uses cloud infrastructure, database and authentication services, AI providers, and communications providers. Integration paths include protections for credentials, callback validation, and restrictions on untrusted destinations. Available controls and supported integrations depend on the service. The Subprocessor List explains which providers participate and distinguishes systems a firm connects independently.
Operations and incident handling
Operational logging, controlled releases, and incident-response procedures support investigation and remediation. Access to diagnostic information is restricted to its operational purpose. If ClaireAI becomes aware of a Personal Data Breach involving data processed for a customer, notification and assistance follow the DPA. Keep your designated security and account contacts current so notices reach the right person.
Retention and professional records
Recording, transcript, and backup retention must be confirmed for the applicable service; this page does not promise a universal deletion interval. Return and deletion obligations are described in the DPA. Firms must maintain their own required records, archives, deadline processes, and legal holds. Intake summaries and recordings are not a substitute for professional review.
Security materials and contractual scope
Contact us for the security documentation relevant to your proposed deployment, including available provider, location, access, retention, and safeguard information. Sensitive materials may require an NDA. We do not claim a ClaireAI SOC 2 or ISO certification, universal staff MFA coverage, a particular penetration-testing cadence, or a uniform encryption specification through this page. A provider’s certification is not a certification of ClaireAI.
This overview is informational. Any specific service-level or additional security commitment must be expressly agreed in the applicable contract. HIPAA-regulated processing requires a supported configuration and a separately executed BAA; neither this page nor the public DPA creates one. Our Privacy Policy explains the distinction between service information and website or business information.
Report a concern or request information
Contact info@theclaireai.com with “Security” in the subject. Describe the affected function and how to reproduce the concern using synthetic data; do not include credentials, caller recordings, or confidential case information in ordinary email. Coordinate any security testing with ClaireAI before accessing or testing systems beyond your authorization.
Claire AI, LLC · Attn: Privacy Officer4410 NW 5th Ave
Boca Raton, FL 33431, United States
info@theclaireai.com
+1 (954) 997-0065