inSession is built for an environment where confidentiality, professional responsibility, data protection, and trust matter.
Legal professionals may use inSession to work with sensitive case information, attorney work product, litigation strategy, witness information, evidence, and other confidential materials. Law firms, law schools, and other organizations may also have their own regulatory, contractual, ethical, and information-security requirements.
Our approach is to be transparent about the safeguards and compliance practices we have in place today, while avoiding claims to certifications or regulatory status that inSession has not independently obtained.
inSession is operated by First Chair, Inc.
We design and operate the platform with consideration for privacy laws, information-security practices, professional-responsibility requirements, and the particular confidentiality concerns associated with legal information.
Our compliance program will continue to evolve as the platform grows, regulations change, and additional independent assessments and certifications become appropriate.
Information relating to an actual or simulated legal matter submitted to inSession is treated as Case-Specific Data.
This may include legal documents, case facts, evidence, litigation strategies, attorney work product, witness information, transcripts, recordings, simulation materials, and related information.
Users retain ownership of their Case-Specific Data.
inSession does not sell Case-Specific Data.
inSession does not use Case-Specific Data to train artificial intelligence models.
Our service providers are not permitted to use Case-Specific Data processed on behalf of inSession to train their artificial intelligence models.
Case-Specific Data is processed as necessary to provide the services and functionality requested by the user.
Artificial intelligence can provide powerful tools for litigation preparation, simulation, strategy, and legal education, but it does not replace professional judgment.
inSession is designed to support responsible use of AI by legal professionals.
Attorneys remain responsible for complying with applicable professional obligations, including requirements concerning:
AI-generated information can be inaccurate or incomplete. Users should independently evaluate and verify information material to legal decisions or court proceedings.
inSession does not provide legal advice and does not replace an attorney's independent professional judgment.
inSession is designed with safeguards intended to protect the confidentiality of Case-Specific Data.
However, the existence of technical and contractual safeguards does not itself determine whether information is protected by attorney-client privilege, work-product protection, or another legal doctrine.
Users remain responsible for evaluating the privilege, confidentiality, ethical, contractual, and legal implications of submitting particular information to any technology service.
We do not represent that uploading information to inSession independently creates, preserves, expands, or waives attorney-client privilege or work-product protection.
inSession uses established technology and infrastructure service providers that maintain SOC 2 compliance or applicable SOC 2 assurance for services used by inSession.
These providers support areas such as cloud infrastructure, data storage, artificial intelligence processing, voice and avatar technology, security, and other platform functionality.
First Chair, Inc. and inSession are not currently represented as independently SOC 2 certified.
A service provider's SOC 2 status does not automatically provide SOC 2 certification to inSession.
As our platform and compliance program mature, independent assessments and certifications may be added.
Legal matters may include medical records and health-related information.
Certain infrastructure and technology providers used by inSession offer services designed to support HIPAA-regulated environments.
However:
inSession is not currently represented as a HIPAA-compliant service.
The HIPAA status or capabilities of an underlying infrastructure provider do not independently establish HIPAA compliance for inSession.
inSession does not currently enter into Business Associate Agreements for use of the platform.
Organizations subject to HIPAA should evaluate whether their intended use of inSession is appropriate before submitting protected health information.
inSession is designed to support applicable California privacy requirements, including rights that may apply under the California Consumer Privacy Act and California Privacy Rights Act.
The applicability of particular statutory requirements depends on factors established by applicable law.
Where California privacy rights apply, individuals may contact us to exercise applicable rights concerning access, correction, deletion, or other treatment of their personal information.
inSession does not sell personal information or Case-Specific Data.
Privacy requests may be submitted to [email protected].
Additional information is available in our Privacy Policy.
inSession may be accessed by users located outside the United States, including users in the European Economic Area and United Kingdom.
Privacy and data-protection requirements differ among jurisdictions.
We recognize that international use may implicate requirements under laws such as the European Union General Data Protection Regulation and United Kingdom data-protection law.
inSession does not currently represent that the platform has completed a comprehensive independent GDPR compliance certification or assessment.
Organizations with specific European or international data-protection requirements should contact us before submitting regulated or sensitive information so that applicable requirements can be evaluated.
inSession may be used by law schools, universities, professors, instructors, students, and legal-training organizations.
However:
inSession is not currently represented as independently FERPA compliant.
Educational institutions with FERPA obligations or other institutional privacy requirements should evaluate their intended use of the platform and contact us regarding applicable requirements before using inSession to process regulated student education records.
Payments for inSession subscriptions and services may be processed through Stripe.
Payment-card information is ordinarily provided directly to the payment processor rather than stored by inSession.
Payment processors maintain their own security and payment-industry compliance programs.
inSession does not represent that use of a PCI-compliant payment processor independently establishes PCI DSS certification for First Chair, Inc. or inSession.
Case-Specific Data processed and stored as part of the inSession platform is maintained using U.S.-based data infrastructure.
We use established cloud and technology service providers selected with consideration for security, availability, confidentiality, and data-protection requirements.
Additional information regarding our security architecture and safeguards is available on our Security page.
inSession uses third-party providers for functions such as:
We evaluate material providers with consideration for security, privacy, confidentiality, and their handling of Case-Specific Data.
Providers processing Case-Specific Data on behalf of inSession are not permitted to sell that information or use it to train their artificial intelligence models.
A current list of material service providers and subprocessors is available upon request by contacting [email protected].
inSession may receive requests for information from courts, law-enforcement agencies, regulators, or other governmental authorities.
We require requests for user information to be made through legally valid processes and evaluate requests consistent with applicable law.
Where legally permitted and appropriate, we may seek to limit requests that we believe are invalid, overbroad, or inconsistent with applicable legal requirements.
Nothing in this section prevents inSession from responding to an emergency or other circumstance where disclosure is permitted or required by applicable law.
Our security program includes technical and organizational safeguards designed to protect information processed through inSession.
Current safeguards include measures such as:
More detailed information is available on our Security page.
Google Analytics, the Meta Pixel, and similar marketing technologies may be used on public-facing portions of our website.
Advertising and marketing tracking technologies are not used within authenticated member areas or case-related areas of inSession.
Case-Specific Data is not provided to these technologies for advertising or marketing purposes.
Artificial intelligence regulation and professional standards are evolving rapidly.
inSession monitors developments relevant to our platform, including:
We may modify platform functionality, policies, controls, or contractual requirements as these standards evolve.
inSession does not currently claim certification under a specific independent AI governance framework unless expressly stated otherwise.
We recognize that law firms, educational institutions, and enterprise organizations may conduct their own security, privacy, vendor-risk, and compliance reviews before adopting technology.
inSession is willing to participate in reasonable security and compliance reviews for prospective organizational and enterprise customers.
This may include responding to appropriate vendor-security questionnaires and providing additional information regarding relevant security and data-handling practices.
Certain information concerning internal security controls, infrastructure, testing, vendors, or other sensitive matters may be provided only under appropriate confidentiality protections.
Organizations may have contractual, security, privacy, retention, data-governance, or compliance requirements beyond those applicable to standard individual accounts.
Additional contractual protections or arrangements may be available for eligible organizational and enterprise accounts.
Availability and terms are determined on a case-by-case basis and must be expressly agreed to in writing by First Chair, Inc.
Contact [email protected] to discuss organizational requirements.
inSession seeks to provide a usable and accessible platform.
We are continuing to evaluate and improve accessibility as the platform develops.
Unless expressly stated otherwise, inSession does not currently claim independent certification or conformance with a particular accessibility standard.
Trust in legal technology requires accurate representations about security and compliance.
We therefore distinguish between:
We will update our public materials as our compliance program, independent assessments, certifications, and platform capabilities evolve.
Organizations with security, compliance, privacy, procurement, or vendor-risk questions may contact:
First Chair, Inc. dba inSession
Legal & Compliance: [email protected]
Privacy: [email protected]
Website: inSession.law