Security Built for Litigation Teams
Ares is built with security at its core so your clients' privileged information and case data stay protected.
How we protect your case data
HIPAA Compliant
All PHI processed under executed Business Associate Agreements with technical and organizational safeguards meeting HIPAA requirements.
No Model Training
Your data is never used to train AI models. We maintain zero-data-retention agreements with all AI providers. Your files remain yours.
AES-256 Encryption
All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Keys are managed with AWS KMS with regular rotation.
Zero Data Retention
AI providers retain no customer prompts, case data, or outputs after processing. Your privileged and confidential information flows through. It never stays behind.
Role-Based Access
Granular permissions ensure team members only see what they need. Every action is logged with full audit trails for compliance.
SOC 2 In Progress
We are actively pursuing SOC 2 Type II certification with a leading audit firm. Hosted on HIPAA-compliant AWS infrastructure.
Security questions
Answers to the security, privacy, and compliance questions we hear most from litigation teams.
All PHI is encrypted at rest and in transit with strict access controls, audit logging, and role-based permissions. PHI is stored in HIPAA-compliant AWS environments with zero-data-retention AI processing.
No. We maintain zero-data-retention agreements with our AI providers. Your data is never used for model training, fine-tuning, or any purpose beyond processing your request.
AES-256 encryption for data at rest and TLS 1.2+ for data in transit. Encryption keys are managed through AWS Key Management Service with regular key rotation.
All data is hosted in HIPAA-compliant AWS data centers in the United States. We use geographically distributed infrastructure for reliability and maintain strict access controls on all production systems.
Upon termination of services, we securely delete all customer data according to our data retention policy. You can request data deletion at any time by contacting support@ares.legal.
Yes. We maintain comprehensive audit logs for all data access, modifications, and transfers. These logs support accountability, compliance reporting, and incident investigation.
In the event of a data breach, Ares notifies affected users within 72 hours. We provide details on the nature of the breach, affected data, and mitigation measures. We work with law enforcement and regulatory bodies as required.