Built for confidential, privileged legal work. Here is how we keep your clients' confidences safe, the controls behind it, and the documentation your security review will need.
Last reviewed June 2026Data processed in the United StatesOpen source codebase
Daymark is a private, governed AI workspace for law firms. Your data is isolated to your firm, never used to train AI, and processed under zero-data-retention terms on the model path. The posture below summarizes our controls.
Zero data retentionOn the model-provider path, prompts and outputs are used only to answer your request, then discarded, not retained by the provider.
No model trainingYour inputs, outputs, and uploaded documents are never used to train any AI model, not ours and not the providers'.
EncryptedEncrypted at rest and in transit (TLS), across every service.
Per-firm isolationEach firm runs in its own dedicated instance, with its own database and keys. Your matters are never commingled with another firm's.
Audit loggingCompliance-grade audit logging: an exportable record of workspace activity, built to support your reasonable-efforts and recordkeeping obligations.
US data residencyYour data is stored and processed in the United States.
Compliance
Our security posture rests on independently audited cloud infrastructure.
Daymark runs on enterprise cloud infrastructure that maintains independent, third-party security programs, including SOC 2 Type II (and HIPAA where enabled). Daymark inherits those controls, and our full data-processing architecture is available for your security team to review.
Data security
Encryption, retention & deletion
Encryption at rest
Encryption in transit (TLS) across all services
Zero data retention on the model-provider call path
Never used to train any AI model
Designed multi-system deletion with a completion certificate
Tamper-evident, metadata-only deletion manifests
Access control
Isolation & access
Each firm runs in its own dedicated instance and database
Server-enforced firm and matter access
Daymark staff don't access your matter content in routine operations; emergency access uses a break-glass process that is authorized, time-limited, and logged
Multi-factor authentication required on administrative access
Securely designed credential scoping per firm
Role-based admin for seats, retention, and legal hold
Infrastructure
Hosting & resilience
US-hosted on enterprise cloud infrastructure
Managed key vault for per-firm secrets
Governed gateway in front of every model call
Backups and point-in-time recovery
Secrets injected from the environment, never logged
AI governance
The model layer
Every model call routes through a governed gateway
No ungoverned model calls
No-training and zero-retention enforced, with contractual flow-down to providers
Answers are generated only from your firm's own documents, not the open web
Pinpoint citations verified server-side before they're shown
Audit & monitoring
The record
Audit logs capture system and account activity across your workspace
Your firm's workspace keeps its own encrypted history of queries and answers, isolated to your firm and under your retention, legal-hold, and export controls
Records are exportable for your own file and reasonable-efforts record
Data privacy
Your data, your control
Firm-configurable retention period (admin-set)
Per-matter legal hold overrides automated deletion
Your data is yours, and you can export it on request
Professional responsibility
Daymark is built around the rules you practice under.
§Confidentiality: Rule 1.6 + ABA Opinion 512. No-training, zero-retention, and per-firm isolation address the "open, self-learning AI" risk that ABA 512 and 2026 state guidance flag. ABA Model Rule 1.6 · ABA Formal Op. 512 (2024)
§Competence: Rule 1.1 and the AI-hallucination cases. Pinpoint citations to source and page, verified server-side; each answer carries a Source Trail you can open and check, and you verify before you rely. Courts have sanctioned lawyers for filing AI-fabricated citations. ABA Model Rule 1.1 · Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023)
Subprocessors
Daymark works with a small, vetted set of subprocessors, each bound by contract to no-training and zero-retention terms and selected for US data handling. We share the current subprocessor list and data locations with your security team on request.
For firms that work with PHI, HIPAA handling is available as a paid add-on.
Legal & governance
Contracts & obligations
Written data-processing commitments in your customer agreement: no-training, limited use, and subprocessor flow-down
Security-incident notification protocols in place
Data export and documented deletion on termination
Open source under AGPL
Documents
Shared with your reviewer on request, as part of a security review.
Have a security question for your review, or think you've found a vulnerability? Email security@daymarklaw.com. We read every report and respond quickly. To begin a full review, request access.
Trust is the product
Bring your security review.
Tell us about your firm, and we'll walk your security team through our architecture, share our subprocessor list and data-processing terms, and answer whatever your review needs.