Security

Your client documents are confidential. We build PleadFlow accordingly.

🔐

AES-256 encryption

All case documents, conversations, and uploaded files encrypted at rest and in transit with TLS 1.3. Nothing stored in plaintext.

🚫

No training on your data

Your case facts, uploaded documents, and generated drafts are never used to train AI models — ours or anyone else's. Professional privilege preserved.

Cloudflare R2 storage

All documents stored on Cloudflare R2 with private access. Files accessible only to you — never publicly reachable.

🔑

Secure authentication

Passwords hashed with bcrypt (12 rounds). JWT session tokens with expiration. Rate limiting on all auth endpoints.

🛡

Backend-only AI calls

All AI API calls made from backend servers. API keys never exposed to the browser or client-side code.

📋

Immutable audit logs

All administrative actions logged with timestamps and IP addresses. Read-only. Cannot be deleted.

Report a security vulnerability

care@pleadflow.com

Acknowledged within 24 hours