FeaturesDemoAboutFAQContact
Dashboard Request Early Access
FeaturesDemoAboutFAQContact
Dashboard Request Early Access
inSession / Legal / Compliance

Compliance & Trust

SectionsXXI Last updatedAugust 15, 2026 Legal questions[email protected]
§ Index of Sections
I. Our Approach to Compliance II. Case-Specific Data III. Responsible Use of Artificial Intelligence in Legal Practice IV. Attorney-Client Privilege and Confidentiality V. SOC 2 VI. HIPAA VII. California Privacy VIII. International Users and GDPR IX. Educational Institutions and FERPA X. Payment Security XI. U.S.-Based Case Data Infrastructure XII. Service Providers and Subprocessors XIII. Government and Legal Requests XIV. Security Controls XV. Advertising and Case Data XVI. AI Governance XVII. Enterprise Compliance Reviews XVIII. Additional Enterprise Requirements XIX. Accessibility XX. Our Commitment to Transparency XXI. Compliance Questions

inSession is built for an environment where confidentiality, professional responsibility, data protection, and trust matter.

Legal professionals may use inSession to work with sensitive case information, attorney work product, litigation strategy, witness information, evidence, and other confidential materials. Law firms, law schools, and other organizations may also have their own regulatory, contractual, ethical, and information-security requirements.

Our approach is to be transparent about the safeguards and compliance practices we have in place today, while avoiding claims to certifications or regulatory status that inSession has not independently obtained.

I.

Our Approach to Compliance

§ 01

inSession is operated by First Chair, Inc.

We design and operate the platform with consideration for privacy laws, information-security practices, professional-responsibility requirements, and the particular confidentiality concerns associated with legal information.

Our compliance program will continue to evolve as the platform grows, regulations change, and additional independent assessments and certifications become appropriate.

II.

Case-Specific Data

§ 02

Information relating to an actual or simulated legal matter submitted to inSession is treated as Case-Specific Data.

This may include legal documents, case facts, evidence, litigation strategies, attorney work product, witness information, transcripts, recordings, simulation materials, and related information.

Users retain ownership of their Case-Specific Data.

inSession does not sell Case-Specific Data.

inSession does not use Case-Specific Data to train artificial intelligence models.

Our service providers are not permitted to use Case-Specific Data processed on behalf of inSession to train their artificial intelligence models.

Case-Specific Data is processed as necessary to provide the services and functionality requested by the user.

III.

Responsible Use of Artificial Intelligence in Legal Practice

§ 03

Artificial intelligence can provide powerful tools for litigation preparation, simulation, strategy, and legal education, but it does not replace professional judgment.

inSession is designed to support responsible use of AI by legal professionals.

Attorneys remain responsible for complying with applicable professional obligations, including requirements concerning:

  • Competence
  • Confidentiality
  • Attorney-client privilege
  • Supervision
  • Candor to courts and tribunals
  • Verification of legal authorities and factual information
  • Client communication and consent where required
  • Court rules governing artificial intelligence
  • Applicable state bar rules and guidance
  • Other professional-responsibility requirements

AI-generated information can be inaccurate or incomplete. Users should independently evaluate and verify information material to legal decisions or court proceedings.

inSession does not provide legal advice and does not replace an attorney's independent professional judgment.

IV.

Attorney-Client Privilege and Confidentiality

§ 04

inSession is designed with safeguards intended to protect the confidentiality of Case-Specific Data.

However, the existence of technical and contractual safeguards does not itself determine whether information is protected by attorney-client privilege, work-product protection, or another legal doctrine.

Users remain responsible for evaluating the privilege, confidentiality, ethical, contractual, and legal implications of submitting particular information to any technology service.

We do not represent that uploading information to inSession independently creates, preserves, expands, or waives attorney-client privilege or work-product protection.

V.

SOC 2

§ 05

inSession uses established technology and infrastructure service providers that maintain SOC 2 compliance or applicable SOC 2 assurance for services used by inSession.

These providers support areas such as cloud infrastructure, data storage, artificial intelligence processing, voice and avatar technology, security, and other platform functionality.

First Chair, Inc. and inSession are not currently represented as independently SOC 2 certified.

A service provider's SOC 2 status does not automatically provide SOC 2 certification to inSession.

As our platform and compliance program mature, independent assessments and certifications may be added.

VI.

HIPAA

§ 06

Legal matters may include medical records and health-related information.

Certain infrastructure and technology providers used by inSession offer services designed to support HIPAA-regulated environments.

However:

inSession is not currently represented as a HIPAA-compliant service.

The HIPAA status or capabilities of an underlying infrastructure provider do not independently establish HIPAA compliance for inSession.

inSession does not currently enter into Business Associate Agreements for use of the platform.

Organizations subject to HIPAA should evaluate whether their intended use of inSession is appropriate before submitting protected health information.

VII.

California Privacy

§ 07

inSession is designed to support applicable California privacy requirements, including rights that may apply under the California Consumer Privacy Act and California Privacy Rights Act.

The applicability of particular statutory requirements depends on factors established by applicable law.

Where California privacy rights apply, individuals may contact us to exercise applicable rights concerning access, correction, deletion, or other treatment of their personal information.

inSession does not sell personal information or Case-Specific Data.

Privacy requests may be submitted to [email protected].

Additional information is available in our Privacy Policy.

VIII.

International Users and GDPR

§ 08

inSession may be accessed by users located outside the United States, including users in the European Economic Area and United Kingdom.

Privacy and data-protection requirements differ among jurisdictions.

We recognize that international use may implicate requirements under laws such as the European Union General Data Protection Regulation and United Kingdom data-protection law.

inSession does not currently represent that the platform has completed a comprehensive independent GDPR compliance certification or assessment.

Organizations with specific European or international data-protection requirements should contact us before submitting regulated or sensitive information so that applicable requirements can be evaluated.

IX.

Educational Institutions and FERPA

§ 09

inSession may be used by law schools, universities, professors, instructors, students, and legal-training organizations.

However:

inSession is not currently represented as independently FERPA compliant.

Educational institutions with FERPA obligations or other institutional privacy requirements should evaluate their intended use of the platform and contact us regarding applicable requirements before using inSession to process regulated student education records.

X.

Payment Security

§ 10

Payments for inSession subscriptions and services may be processed through Stripe.

Payment-card information is ordinarily provided directly to the payment processor rather than stored by inSession.

Payment processors maintain their own security and payment-industry compliance programs.

inSession does not represent that use of a PCI-compliant payment processor independently establishes PCI DSS certification for First Chair, Inc. or inSession.

XI.

U.S.-Based Case Data Infrastructure

§ 11

Case-Specific Data processed and stored as part of the inSession platform is maintained using U.S.-based data infrastructure.

We use established cloud and technology service providers selected with consideration for security, availability, confidentiality, and data-protection requirements.

Additional information regarding our security architecture and safeguards is available on our Security page.

XII.

Service Providers and Subprocessors

§ 12

inSession uses third-party providers for functions such as:

  • Cloud infrastructure
  • Data storage
  • Artificial intelligence processing
  • Voice and avatar technology
  • Security
  • Authentication
  • Payment processing
  • Communications
  • Other technical services necessary to operate the platform

We evaluate material providers with consideration for security, privacy, confidentiality, and their handling of Case-Specific Data.

Providers processing Case-Specific Data on behalf of inSession are not permitted to sell that information or use it to train their artificial intelligence models.

A current list of material service providers and subprocessors is available upon request by contacting [email protected].

XIII.

Government and Legal Requests

§ 13

inSession may receive requests for information from courts, law-enforcement agencies, regulators, or other governmental authorities.

We require requests for user information to be made through legally valid processes and evaluate requests consistent with applicable law.

Where legally permitted and appropriate, we may seek to limit requests that we believe are invalid, overbroad, or inconsistent with applicable legal requirements.

Nothing in this section prevents inSession from responding to an emergency or other circumstance where disclosure is permitted or required by applicable law.

XIV.

Security Controls

§ 14

Our security program includes technical and organizational safeguards designed to protect information processed through inSession.

Current safeguards include measures such as:

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Required multi-factor authentication
  • Role-based access controls
  • Logical segregation of customer and case information
  • Separation of production and development environments
  • Prohibition on using real customer Case-Specific Data for development or testing
  • Encrypted backups
  • Security monitoring and logging
  • Vulnerability scanning
  • Security testing and penetration testing
  • Separation of public marketing analytics from authenticated case-related areas

More detailed information is available on our Security page.

XV.

Advertising and Case Data

§ 15

Google Analytics, the Meta Pixel, and similar marketing technologies may be used on public-facing portions of our website.

Advertising and marketing tracking technologies are not used within authenticated member areas or case-related areas of inSession.

Case-Specific Data is not provided to these technologies for advertising or marketing purposes.

XVI.

AI Governance

§ 16

Artificial intelligence regulation and professional standards are evolving rapidly.

inSession monitors developments relevant to our platform, including:

  • AI-related legislation and regulation
  • Court rules concerning artificial intelligence
  • State bar ethics opinions and guidance
  • Professional-responsibility requirements
  • Privacy and data-protection regulation
  • Emerging AI governance standards

We may modify platform functionality, policies, controls, or contractual requirements as these standards evolve.

inSession does not currently claim certification under a specific independent AI governance framework unless expressly stated otherwise.

XVII.

Enterprise Compliance Reviews

§ 17

We recognize that law firms, educational institutions, and enterprise organizations may conduct their own security, privacy, vendor-risk, and compliance reviews before adopting technology.

inSession is willing to participate in reasonable security and compliance reviews for prospective organizational and enterprise customers.

This may include responding to appropriate vendor-security questionnaires and providing additional information regarding relevant security and data-handling practices.

Certain information concerning internal security controls, infrastructure, testing, vendors, or other sensitive matters may be provided only under appropriate confidentiality protections.

XVIII.

Additional Enterprise Requirements

§ 18

Organizations may have contractual, security, privacy, retention, data-governance, or compliance requirements beyond those applicable to standard individual accounts.

Additional contractual protections or arrangements may be available for eligible organizational and enterprise accounts.

Availability and terms are determined on a case-by-case basis and must be expressly agreed to in writing by First Chair, Inc.

Contact [email protected] to discuss organizational requirements.

XIX.

Accessibility

§ 19

inSession seeks to provide a usable and accessible platform.

We are continuing to evaluate and improve accessibility as the platform develops.

Unless expressly stated otherwise, inSession does not currently claim independent certification or conformance with a particular accessibility standard.

XX.

Our Commitment to Transparency

§ 20

Trust in legal technology requires accurate representations about security and compliance.

We therefore distinguish between:

  • Controls implemented by inSession
  • Certifications and assurances maintained by our service providers
  • Independent certifications obtained directly by First Chair, Inc.
  • Regulatory frameworks we are working to support
  • Compliance statuses we do not currently claim

We will update our public materials as our compliance program, independent assessments, certifications, and platform capabilities evolve.

XXI.

Compliance Questions

§ 21

Organizations with security, compliance, privacy, procurement, or vendor-risk questions may contact:

First Chair, Inc. dba inSession

Legal & Compliance: [email protected]

Privacy: [email protected]

Website: inSession.law

inSession

Our Trial Strategy Intelligence Platform transforms litigation practice with cutting-edge AI technology designed specifically for comprehensive trial support.

Services
FeaturesRequest DemoDashboard
Company
About UsContact
Legal
PrivacyTermsSecurityComplianceGDPR

inSession™, TrialLab™, TrialIQ™, and Trial Professor™ are trademarks of First Chair, Inc. inSession™ is the subject of a U.S. federal trademark application. Certain proprietary technologies used in inSession's Trial Simulator are patent pending. Neither inSession nor First Chair, Inc. is a law firm, and neither provides legal advice or predicts litigation outcomes.

© 2026 First Chair, Inc.

Powered byCG Intelligence