L
Obiter
Security & Data Protection

Client confidentiality is not negotiable.

We built Obiter knowing that law firms hold some of the most sensitive personal and commercial data in the economy. Security isn't a feature โ€” it's the foundation everything else sits on.

UK-hosted Encrypted in transit & at rest Isolated database per firm Role-based access Audit trail

UK Data Hosting

All data stored in AWS eu-west-2 (London). Your client data is hosted in the UK.

Encryption

Data is encrypted in transit (TLS) and at rest. OAuth tokens are encrypted at rest.

Isolated databases

Each firm's data lives in its own separate database โ€” no shared tables between firms.

UK GDPR by design

The platform is designed to support your firm's obligations under UK GDPR and the Data Protection Act 2018.

Built for SRA-regulated firms

Designed around the confidentiality obligations of SRA-regulated practice in England & Wales.

Audit trail

System actions โ€” human and AI โ€” are recorded in an audit trail your firm can review.

We describe here what Obiter actually does today. We don't list certifications we don't hold โ€” as we complete independent audits and certifications, we'll publish them on this page.

"Can I trust AI with my clients' data?"

It's the right question to ask. Solicitors have professional obligations under the SRA Code of Conduct to keep client information confidential โ€” and those obligations don't pause because you're using software.

Here's our answer: Obiter does not use your client data to train AI models. When Obiter sends email content to an AI provider to generate a draft reply, it does so through the provider's business API, under terms that do not permit your data to be used for model training.

And your firm's data is stored in the UK: our infrastructure runs in AWS eu-west-2 (London). Every fee earner remains in control โ€” no AI output is sent to a client without a human approving it.

Technical security

How we protect your firm's data

Six architectural decisions that make Obiter appropriate for a regulated profession.

Database-per-firm isolation

Every law firm gets its own completely separate database. There are no shared tables and no risk of one firm's queries touching another firm's data. This is a deliberate architectural choice for a regulated sector.

Database-per-tenant architecture (not row-level security). Separate database credentials per tenant.

Encryption in transit and at rest

All traffic between your browser and Obiter is encrypted with TLS. Data is encrypted at rest on our infrastructure.

TLS enforced for all connections. Encryption at rest on AWS-managed storage.

OAuth-only email connectivity

Obiter never stores your email password. Microsoft 365 and Google Workspace connections use delegated OAuth tokens with the minimum scopes required to read and send email on behalf of your firm's mailboxes. Tokens are encrypted at rest.

Microsoft Graph and Google OAuth with least-privilege mail scopes. Tokens stored encrypted, per tenant, and revocable at any time.

AI data boundaries

Your client data is not used by Obiter to train AI models. When Obiter sends content to an AI provider for processing, it does so via their business APIs, which are not used to train their models under the providers' terms.

AI processing via provider APIs under business terms. No model training on your content by Obiter.

Audit trail

Actions taken in Obiter โ€” by a human or by AI โ€” are written to an audit trail. You can see who did what, when, and what the system decided.

Activity logging across the platform, including AI actions and fee-earner approvals.

Role-based access control

Granular permissions mean each team member can only see what their role requires. Partners, fee earners, support staff, and accounts staff each have appropriate access boundaries.

Role-based access control with per-role permission sets.

UK GDPR

Designed to support your data protection obligations

Law firms are both data controllers (for their own clients) and users of data processors (when they use tools like Obiter). We've designed the platform to support both roles under UK GDPR and the Data Protection Act 2018.

Our lawful basis for processing your account data is contractual necessity โ€” we process data to deliver the service you've contracted for. For your clients' data, your firm remains the controller and Obiter acts as your processor.

Request our DPA

Designed for UK GDPR

The platform is designed to support your firm's obligations under UK GDPR โ€” it is a tool that helps you meet them, not a substitute for your own compliance programme.

Data Portability

You can export your firm's data (matters, contacts, records) โ€” your data is yours.

Right to Erasure

Structured data deletion on request, subject to the retention obligations that apply to legal-sector records.

Breach Notification

If we become aware of a personal data breach affecting your firm, we will notify you without undue delay, in line with UK GDPR.

Data Processing Agreement

We act as a data processor for your client data. A DPA is available on request before you sign up.

Sub-processors

We use a small number of sub-processors (such as AWS for hosting and AI providers for language processing), listed in our DPA.

Responsible disclosure

If you discover a security vulnerability in Obiter, please report it to security@obiteros.com. We will investigate promptly and keep you informed.

We ask that you do not publicly disclose vulnerabilities before we have had an opportunity to investigate and remediate.

Security questions before you sign up?

Talk to us before you trial โ€” we'll walk through your requirements in detail and answer honestly, including about what we don't yet have.