Trust Center

Security & trust at Daymark.

Built for confidential, privileged legal work. Here is how we keep your clients' confidences safe, the controls behind it, and the documentation your security review will need.

Last reviewed June 2026Data processed in the United StatesOpen source codebase

Overview

Daymark is a private, governed AI workspace for law firms. Your data is isolated to your firm, never used to train AI, and processed under zero-data-retention terms on the model path. The posture below summarizes our controls.

Zero data retentionOn the model-provider path, prompts and outputs are used only to answer your request, then discarded, not retained by the provider.
No model trainingYour inputs, outputs, and uploaded documents are never used to train any AI model, not ours and not the providers'.
EncryptedEncrypted at rest and in transit (TLS), across every service.
Per-firm isolationEach firm runs in its own dedicated instance, with its own database and keys. Your matters are never commingled with another firm's.
Audit loggingCompliance-grade audit logging: an exportable record of workspace activity, built to support your reasonable-efforts and recordkeeping obligations.
US data residencyYour data is stored and processed in the United States.

Compliance

Our security posture rests on independently audited cloud infrastructure.

Daymark runs on enterprise cloud infrastructure that maintains independent, third-party security programs, including SOC 2 Type II (and HIPAA where enabled). Daymark inherits those controls, and our full data-processing architecture is available for your security team to review.

Data security

Encryption, retention & deletion

  • Encryption at rest
  • Encryption in transit (TLS) across all services
  • Zero data retention on the model-provider call path
  • Never used to train any AI model
  • Designed multi-system deletion with a completion certificate
  • Tamper-evident, metadata-only deletion manifests

Access control

Isolation & access

  • Each firm runs in its own dedicated instance and database
  • Server-enforced firm and matter access
  • Daymark staff don't access your matter content in routine operations; emergency access uses a break-glass process that is authorized, time-limited, and logged
  • Multi-factor authentication required on administrative access
  • Securely designed credential scoping per firm
  • Role-based admin for seats, retention, and legal hold

Infrastructure

Hosting & resilience

  • US-hosted on enterprise cloud infrastructure
  • Managed key vault for per-firm secrets
  • Governed gateway in front of every model call
  • Backups and point-in-time recovery
  • Secrets injected from the environment, never logged

AI governance

The model layer

  • Every model call routes through a governed gateway
  • No ungoverned model calls
  • No-training and zero-retention enforced, with contractual flow-down to providers
  • Answers are generated only from your firm's own documents, not the open web
  • Pinpoint citations verified server-side before they're shown

Audit & monitoring

The record

  • Audit logs capture system and account activity across your workspace
  • Your firm's workspace keeps its own encrypted history of queries and answers, isolated to your firm and under your retention, legal-hold, and export controls
  • Records are exportable for your own file and reasonable-efforts record

Data privacy

Your data, your control

  • Firm-configurable retention period (admin-set)
  • Per-matter legal hold overrides automated deletion
  • Your data is yours, and you can export it on request

Professional responsibility

Daymark is built around the rules you practice under.

Subprocessors

Daymark works with a small, vetted set of subprocessors, each bound by contract to no-training and zero-retention terms and selected for US data handling. We share the current subprocessor list and data locations with your security team on request.

For firms that work with PHI, HIPAA handling is available as a paid add-on.

Documents

Shared with your reviewer on request, as part of a security review.

PolicyPrivacy policy
View
ContractCustomer agreement & data-processing terms
Request access
ReferenceSubprocessor list & data locations
Request access
SourceApplication source code (AGPL)
Request access

Contact

Have a security question for your review, or think you've found a vulnerability? Email security@daymarklaw.com. We read every report and respond quickly. To begin a full review, request access.

Trust is the product

Bring your security review.

Tell us about your firm, and we'll walk your security team through our architecture, share our subprocessor list and data-processing terms, and answer whatever your review needs.

Request Access