FeaturesDemoAboutFAQContact
Dashboard Request Early Access
FeaturesDemoAboutFAQContact
Dashboard Request Early Access
inSession / Legal / Security

Security

SectionsXX Last updatedAugust 15, 2026 Legal questions[email protected]
§ Index of Sections
I. Your Cases Are Not Training Data II. Encryption III. Cloud Infrastructure IV. SOC 2 and Service Provider Security V. Artificial Intelligence Providers VI. Authentication and Account Security VII. Data Isolation VIII. Internal Access Controls IX. Development and Production Separation X. No Advertising Tracking Inside Case Areas XI. Security Monitoring XII. Security Testing XIII. Encrypted Backups XIV. Data Deletion XV. U.S.-Based Data Infrastructure XVI. HIPAA and Health Information XVII. Privacy and Security by Separation XVIII. Responsible Vulnerability Disclosure XIX. Security Is an Ongoing Process XX. Security Questions

Protecting the confidentiality of legal information is fundamental to how we build inSession.

inSession is designed for attorneys, law firms, legal professionals, law students, and educational institutions that may work with sensitive and confidential information.

We recognize that legal professionals have security and confidentiality obligations that extend beyond those of many ordinary software users. Our security architecture is designed with those requirements in mind.

This page provides an overview of the safeguards we use to protect information processed through inSession.

I.

Your Cases Are Not Training Data

§ 01

Case-Specific Data submitted to inSession is not used to train artificial intelligence models.

inSession does not use your Case-Specific Data to train AI models, and our AI service providers are not permitted to use Case-Specific Data processed through inSession to train their models.

Case-Specific Data is processed only as necessary to provide the functionality requested by the user, such as simulations, analysis, transcription, scoring, reporting, and other platform features.

We do not sell Case-Specific Data.

II.

Encryption

§ 02

inSession uses encryption to protect data both in transit and at rest.

Data in Transit. Data transmitted between users, inSession, and applicable infrastructure is protected using TLS 1.3 encryption.

Data at Rest. Stored Case-Specific Data is protected using AES-256 encryption at rest.

Encrypted storage and backup systems are used to reduce the risk of unauthorized access to stored information.

III.

Cloud Infrastructure

§ 03

inSession uses established U.S.-based cloud infrastructure and storage providers selected with consideration for security, availability, redundancy, confidentiality, and data-protection requirements.

Our architecture may use different providers depending on operational, performance, availability, redundancy, or technical requirements.

Case-Specific Data is maintained within U.S.-based data infrastructure.

We intentionally do not publicly disclose detailed network architecture, storage configurations, database technologies, internal security configurations, or other information that could unnecessarily increase security risk.

IV.

SOC 2 and Service Provider Security

§ 04

inSession uses technology and infrastructure providers that maintain SOC 2 compliance or applicable SOC 2 assurance for the services used by inSession.

This includes providers supporting portions of our cloud, artificial intelligence, data, voice, avatar, and related technology infrastructure.

First Chair, Inc. and inSession are not currently represented as independently SOC 2 certified.

We believe this distinction is important. A service provider's SOC 2 compliance does not automatically make inSession SOC 2 certified.

As the platform and our security program mature, our compliance and independent assurance programs may evolve.

V.

Artificial Intelligence Providers

§ 05

inSession uses vetted artificial intelligence, voice, avatar, transcription, and related technology providers to deliver platform functionality.

A current list of material service providers and subprocessors is available upon request by contacting [email protected].

These providers process information only as necessary to provide applicable services to inSession under the configurations and arrangements we use.

Our providers are not permitted to train their AI models on Case-Specific Data processed through inSession.

We evaluate vendors with particular attention to data security, confidentiality, data-handling practices, and the requirements associated with professional legal information.

VI.

Authentication and Account Security

§ 06

inSession supports secure authentication methods that may include combinations of:

  • Email and password authentication
  • Single sign-on
  • Google authentication
  • Microsoft authentication
  • Magic links or similar secure authentication methods
  • Multi-factor authentication

Multi-factor authentication is required for inSession accounts.

Available authentication methods may vary depending on account type, organization, and platform configuration.

Users are responsible for protecting their credentials and should immediately report suspected unauthorized account access.

VII.

Data Isolation

§ 07

Customer and Case-Specific Data is logically segregated to prevent unauthorized access between users, organizations, and matters.

Access controls are designed so that authenticated users can access only the information they are authorized to access.

Organizational permissions may allow authorized firm, school, or organizational administrators to access information associated with users under their administration where appropriate and authorized.

VIII.

Internal Access Controls

§ 08

Access to production systems and Case-Specific Data is restricted.

Authorized developers and administrators may access production systems or information when reasonably necessary for purposes such as:

  • Maintaining platform functionality
  • Troubleshooting technical issues
  • Providing authorized support
  • Investigating security issues
  • Maintaining system reliability
  • Performing authorized administrative functions

Access is controlled using role-based access controls designed to limit access according to job responsibilities and operational need.

Internal access does not authorize personnel to use Case-Specific Data for unrelated purposes.

IX.

Development and Production Separation

§ 09

inSession maintains separation between development/testing environments and production systems.

Real customer Case-Specific Data is not used for software development or testing.

Development and testing activities use non-production, synthetic, fictional, de-identified, or otherwise appropriate test information.

This separation is intended to reduce unnecessary exposure of sensitive legal information during the software-development process.

X.

No Advertising Tracking Inside Case Areas

§ 10

inSession may use analytics and advertising technologies such as Google Analytics and the Meta Pixel on our public-facing website.

These technologies are separated from the areas where users work with legal matters.

Google Analytics and the Meta Pixel are not used within authenticated member areas or case-related areas of inSession.

Case-Specific Data is not provided to Google Analytics or the Meta Pixel for advertising or marketing purposes.

We do not believe information concerning a user's legal matters should become advertising-tracking data.

XI.

Security Monitoring

§ 11

inSession uses security monitoring and logging technologies designed to identify suspicious activity, unauthorized access attempts, technical anomalies, and potential threats.

Our security practices may include:

  • Centralized security and system logging
  • Automated security monitoring
  • Vulnerability scanning
  • Network and application security controls
  • Access monitoring
  • Cloud security controls
  • Automated threat detection
  • Other protective technologies appropriate to our infrastructure

We continuously evaluate these controls as the platform develops and the threat environment changes.

XII.

Security Testing

§ 12

inSession conducts security testing designed to identify potential vulnerabilities in the platform and infrastructure.

This includes vulnerability assessment and penetration testing.

Our current penetration-testing program is limited in scope and will continue to evolve as the platform and security program mature.

For security reasons, detailed testing methodologies, findings, system configurations, and remediation information are not publicly disclosed.

XIII.

Encrypted Backups

§ 13

inSession maintains automated backups designed to support system resilience, recovery, and continuity.

Backups containing protected information are encrypted.

Backup retention periods may vary depending on operational, security, disaster-recovery, and technical requirements.

Deletion from active systems may not immediately remove information from encrypted backups, security logs, or disaster-recovery systems.

XIV.

Data Deletion

§ 14

Users may have the ability to delete Case-Specific Data through available platform controls.

Users may also contact inSession to request deletion of eligible account or Case-Specific Data.

Deletion is subject to legitimate technical, security, backup, fraud-prevention, contractual, and legal requirements. Information removed from active systems may remain temporarily within encrypted backups or other protected systems until those systems are overwritten or expire through normal operational processes.

Additional information regarding retention and deletion is available in our Privacy Policy.

XV.

U.S.-Based Data Infrastructure

§ 15

Case-Specific Data processed and stored as part of the inSession platform is maintained using U.S.-based data infrastructure.

Third-party technology providers may maintain their own operational or support infrastructure. Where Case-Specific Data is processed on our behalf, we configure and select services consistent with our security and data-handling requirements.

XVI.

HIPAA and Health Information

§ 16

Legal matters may contain medical records, health information, and other sensitive information.

Certain infrastructure and technology providers used by inSession maintain HIPAA-compliant or HIPAA-capable services and security controls.

However:

inSession is not currently represented as a HIPAA-compliant service.

Users should not rely on the HIPAA status of an underlying infrastructure provider as establishing that inSession itself is HIPAA compliant.

Users who are subject to HIPAA or other specialized regulatory requirements are responsible for determining whether their intended use of inSession is appropriate for their regulatory obligations.

We expect our compliance capabilities to continue evolving as the platform develops.

XVII.

Privacy and Security by Separation

§ 17

We distinguish between ordinary website information and Case-Specific Data.

Our public marketing website may use conventional analytics technologies. Authenticated legal-work areas are designed to operate separately from advertising and marketing tracking.

Similarly, Case-Specific Data is processed for the purpose of providing inSession functionality rather than advertising, data brokerage, or AI model training.

This separation is a core part of our approach to legal-data privacy.

XVIII.

Responsible Vulnerability Disclosure

§ 18

We welcome responsible reports from security researchers and others who believe they have identified a potential vulnerability affecting inSession.

Please report suspected security vulnerabilities to [email protected].

When reporting a potential vulnerability, please provide enough information for us to understand and reproduce the issue.

We ask security researchers to:

  • Avoid accessing, modifying, downloading, or deleting another user's information
  • Avoid disrupting or degrading our services
  • Avoid social engineering of employees, contractors, or users
  • Avoid privacy violations
  • Limit testing to what is reasonably necessary to demonstrate the potential vulnerability
  • Give us a reasonable opportunity to investigate and address a reported issue before publicly disclosing it

Submission of a vulnerability report does not create an entitlement to payment or participation in a bug-bounty program.

XIX.

Security Is an Ongoing Process

§ 19

No internet-connected platform can guarantee absolute security.

Security is an ongoing process involving technology, architecture, people, policies, monitoring, testing, and continuous improvement.

As inSession grows, we expect our security controls, independent testing, compliance programs, and organizational safeguards to continue evolving.

We will update this page as material security capabilities and certifications change.

XX.

Security Questions

§ 20

For security-related questions or to responsibly report a potential vulnerability:

First Chair, Inc. dba inSession

Security: [email protected]

Website: inSession.law

For privacy-related inquiries: [email protected]

For legal inquiries: [email protected]

inSession

Our Trial Strategy Intelligence Platform transforms litigation practice with cutting-edge AI technology designed specifically for comprehensive trial support.

Services
FeaturesRequest DemoDashboard
Company
About UsContact
Legal
PrivacyTermsSecurityComplianceGDPR

inSession™, TrialLab™, TrialIQ™, and Trial Professor™ are trademarks of First Chair, Inc. inSession™ is the subject of a U.S. federal trademark application. Certain proprietary technologies used in inSession's Trial Simulator are patent pending. Neither inSession nor First Chair, Inc. is a law firm, and neither provides legal advice or predicts litigation outcomes.

© 2026 First Chair, Inc.

Powered byCG Intelligence