Protecting the confidentiality of legal information is fundamental to how we build inSession.
inSession is designed for attorneys, law firms, legal professionals, law students, and educational institutions that may work with sensitive and confidential information.
We recognize that legal professionals have security and confidentiality obligations that extend beyond those of many ordinary software users. Our security architecture is designed with those requirements in mind.
This page provides an overview of the safeguards we use to protect information processed through inSession.
Case-Specific Data submitted to inSession is not used to train artificial intelligence models.
inSession does not use your Case-Specific Data to train AI models, and our AI service providers are not permitted to use Case-Specific Data processed through inSession to train their models.
Case-Specific Data is processed only as necessary to provide the functionality requested by the user, such as simulations, analysis, transcription, scoring, reporting, and other platform features.
We do not sell Case-Specific Data.
inSession uses encryption to protect data both in transit and at rest.
Data in Transit. Data transmitted between users, inSession, and applicable infrastructure is protected using TLS 1.3 encryption.
Data at Rest. Stored Case-Specific Data is protected using AES-256 encryption at rest.
Encrypted storage and backup systems are used to reduce the risk of unauthorized access to stored information.
inSession uses established U.S.-based cloud infrastructure and storage providers selected with consideration for security, availability, redundancy, confidentiality, and data-protection requirements.
Our architecture may use different providers depending on operational, performance, availability, redundancy, or technical requirements.
Case-Specific Data is maintained within U.S.-based data infrastructure.
We intentionally do not publicly disclose detailed network architecture, storage configurations, database technologies, internal security configurations, or other information that could unnecessarily increase security risk.
inSession uses technology and infrastructure providers that maintain SOC 2 compliance or applicable SOC 2 assurance for the services used by inSession.
This includes providers supporting portions of our cloud, artificial intelligence, data, voice, avatar, and related technology infrastructure.
First Chair, Inc. and inSession are not currently represented as independently SOC 2 certified.
We believe this distinction is important. A service provider's SOC 2 compliance does not automatically make inSession SOC 2 certified.
As the platform and our security program mature, our compliance and independent assurance programs may evolve.
inSession uses vetted artificial intelligence, voice, avatar, transcription, and related technology providers to deliver platform functionality.
A current list of material service providers and subprocessors is available upon request by contacting [email protected].
These providers process information only as necessary to provide applicable services to inSession under the configurations and arrangements we use.
Our providers are not permitted to train their AI models on Case-Specific Data processed through inSession.
We evaluate vendors with particular attention to data security, confidentiality, data-handling practices, and the requirements associated with professional legal information.
inSession supports secure authentication methods that may include combinations of:
Multi-factor authentication is required for inSession accounts.
Available authentication methods may vary depending on account type, organization, and platform configuration.
Users are responsible for protecting their credentials and should immediately report suspected unauthorized account access.
Customer and Case-Specific Data is logically segregated to prevent unauthorized access between users, organizations, and matters.
Access controls are designed so that authenticated users can access only the information they are authorized to access.
Organizational permissions may allow authorized firm, school, or organizational administrators to access information associated with users under their administration where appropriate and authorized.
Access to production systems and Case-Specific Data is restricted.
Authorized developers and administrators may access production systems or information when reasonably necessary for purposes such as:
Access is controlled using role-based access controls designed to limit access according to job responsibilities and operational need.
Internal access does not authorize personnel to use Case-Specific Data for unrelated purposes.
inSession maintains separation between development/testing environments and production systems.
Real customer Case-Specific Data is not used for software development or testing.
Development and testing activities use non-production, synthetic, fictional, de-identified, or otherwise appropriate test information.
This separation is intended to reduce unnecessary exposure of sensitive legal information during the software-development process.
inSession may use analytics and advertising technologies such as Google Analytics and the Meta Pixel on our public-facing website.
These technologies are separated from the areas where users work with legal matters.
Google Analytics and the Meta Pixel are not used within authenticated member areas or case-related areas of inSession.
Case-Specific Data is not provided to Google Analytics or the Meta Pixel for advertising or marketing purposes.
We do not believe information concerning a user's legal matters should become advertising-tracking data.
inSession uses security monitoring and logging technologies designed to identify suspicious activity, unauthorized access attempts, technical anomalies, and potential threats.
Our security practices may include:
We continuously evaluate these controls as the platform develops and the threat environment changes.
inSession conducts security testing designed to identify potential vulnerabilities in the platform and infrastructure.
This includes vulnerability assessment and penetration testing.
Our current penetration-testing program is limited in scope and will continue to evolve as the platform and security program mature.
For security reasons, detailed testing methodologies, findings, system configurations, and remediation information are not publicly disclosed.
inSession maintains automated backups designed to support system resilience, recovery, and continuity.
Backups containing protected information are encrypted.
Backup retention periods may vary depending on operational, security, disaster-recovery, and technical requirements.
Deletion from active systems may not immediately remove information from encrypted backups, security logs, or disaster-recovery systems.
Users may have the ability to delete Case-Specific Data through available platform controls.
Users may also contact inSession to request deletion of eligible account or Case-Specific Data.
Deletion is subject to legitimate technical, security, backup, fraud-prevention, contractual, and legal requirements. Information removed from active systems may remain temporarily within encrypted backups or other protected systems until those systems are overwritten or expire through normal operational processes.
Additional information regarding retention and deletion is available in our Privacy Policy.
Case-Specific Data processed and stored as part of the inSession platform is maintained using U.S.-based data infrastructure.
Third-party technology providers may maintain their own operational or support infrastructure. Where Case-Specific Data is processed on our behalf, we configure and select services consistent with our security and data-handling requirements.
Legal matters may contain medical records, health information, and other sensitive information.
Certain infrastructure and technology providers used by inSession maintain HIPAA-compliant or HIPAA-capable services and security controls.
However:
inSession is not currently represented as a HIPAA-compliant service.
Users should not rely on the HIPAA status of an underlying infrastructure provider as establishing that inSession itself is HIPAA compliant.
Users who are subject to HIPAA or other specialized regulatory requirements are responsible for determining whether their intended use of inSession is appropriate for their regulatory obligations.
We expect our compliance capabilities to continue evolving as the platform develops.
We distinguish between ordinary website information and Case-Specific Data.
Our public marketing website may use conventional analytics technologies. Authenticated legal-work areas are designed to operate separately from advertising and marketing tracking.
Similarly, Case-Specific Data is processed for the purpose of providing inSession functionality rather than advertising, data brokerage, or AI model training.
This separation is a core part of our approach to legal-data privacy.
We welcome responsible reports from security researchers and others who believe they have identified a potential vulnerability affecting inSession.
Please report suspected security vulnerabilities to [email protected].
When reporting a potential vulnerability, please provide enough information for us to understand and reproduce the issue.
We ask security researchers to:
Submission of a vulnerability report does not create an entitlement to payment or participation in a bug-bounty program.
No internet-connected platform can guarantee absolute security.
Security is an ongoing process involving technology, architecture, people, policies, monitoring, testing, and continuous improvement.
As inSession grows, we expect our security controls, independent testing, compliance programs, and organizational safeguards to continue evolving.
We will update this page as material security capabilities and certifications change.
For security-related questions or to responsibly report a potential vulnerability:
First Chair, Inc. dba inSession
Security: [email protected]
Website: inSession.law
For privacy-related inquiries: [email protected]
For legal inquiries: [email protected]