Client confidentiality is
not negotiable.
We built Obiter knowing that law firms hold some of the most sensitive personal and commercial data in the economy. Security isn't a feature โ it's the foundation everything else sits on.
UK Data Hosting
All data stored in AWS eu-west-2 (London). Your client data is hosted in the UK.
Encryption
Data is encrypted in transit (TLS) and at rest. OAuth tokens are encrypted at rest.
Isolated databases
Each firm's data lives in its own separate database โ no shared tables between firms.
UK GDPR by design
The platform is designed to support your firm's obligations under UK GDPR and the Data Protection Act 2018.
Built for SRA-regulated firms
Designed around the confidentiality obligations of SRA-regulated practice in England & Wales.
Audit trail
System actions โ human and AI โ are recorded in an audit trail your firm can review.
We describe here what Obiter actually does today. We don't list certifications we don't hold โ as we complete independent audits and certifications, we'll publish them on this page.
"Can I trust AI with my clients' data?"
It's the right question to ask. Solicitors have professional obligations under the SRA Code of Conduct to keep client information confidential โ and those obligations don't pause because you're using software.
Here's our answer: Obiter does not use your client data to train AI models. When Obiter sends email content to an AI provider to generate a draft reply, it does so through the provider's business API, under terms that do not permit your data to be used for model training.
And your firm's data is stored in the UK: our infrastructure runs in AWS eu-west-2 (London). Every fee earner remains in control โ no AI output is sent to a client without a human approving it.
How we protect your firm's data
Six architectural decisions that make Obiter appropriate for a regulated profession.
Database-per-firm isolation
Every law firm gets its own completely separate database. There are no shared tables and no risk of one firm's queries touching another firm's data. This is a deliberate architectural choice for a regulated sector.
Database-per-tenant architecture (not row-level security). Separate database credentials per tenant.
Encryption in transit and at rest
All traffic between your browser and Obiter is encrypted with TLS. Data is encrypted at rest on our infrastructure.
TLS enforced for all connections. Encryption at rest on AWS-managed storage.
OAuth-only email connectivity
Obiter never stores your email password. Microsoft 365 and Google Workspace connections use delegated OAuth tokens with the minimum scopes required to read and send email on behalf of your firm's mailboxes. Tokens are encrypted at rest.
Microsoft Graph and Google OAuth with least-privilege mail scopes. Tokens stored encrypted, per tenant, and revocable at any time.
AI data boundaries
Your client data is not used by Obiter to train AI models. When Obiter sends content to an AI provider for processing, it does so via their business APIs, which are not used to train their models under the providers' terms.
AI processing via provider APIs under business terms. No model training on your content by Obiter.
Audit trail
Actions taken in Obiter โ by a human or by AI โ are written to an audit trail. You can see who did what, when, and what the system decided.
Activity logging across the platform, including AI actions and fee-earner approvals.
Role-based access control
Granular permissions mean each team member can only see what their role requires. Partners, fee earners, support staff, and accounts staff each have appropriate access boundaries.
Role-based access control with per-role permission sets.
Designed to support your data protection obligations
Law firms are both data controllers (for their own clients) and users of data processors (when they use tools like Obiter). We've designed the platform to support both roles under UK GDPR and the Data Protection Act 2018.
Our lawful basis for processing your account data is contractual necessity โ we process data to deliver the service you've contracted for. For your clients' data, your firm remains the controller and Obiter acts as your processor.
Request our DPADesigned for UK GDPR
The platform is designed to support your firm's obligations under UK GDPR โ it is a tool that helps you meet them, not a substitute for your own compliance programme.
Data Portability
You can export your firm's data (matters, contacts, records) โ your data is yours.
Right to Erasure
Structured data deletion on request, subject to the retention obligations that apply to legal-sector records.
Breach Notification
If we become aware of a personal data breach affecting your firm, we will notify you without undue delay, in line with UK GDPR.
Data Processing Agreement
We act as a data processor for your client data. A DPA is available on request before you sign up.
Sub-processors
We use a small number of sub-processors (such as AWS for hosting and AI providers for language processing), listed in our DPA.
Responsible disclosure
If you discover a security vulnerability in Obiter, please report it to security@obiteros.com. We will investigate promptly and keep you informed.
We ask that you do not publicly disclose vulnerabilities before we have had an opportunity to investigate and remediate.
Security questions before you sign up?
Talk to us before you trial โ we'll walk through your requirements in detail and answer honestly, including about what we don't yet have.