Enterprise-grade security. Clear data controls.
Legal intelligence requires strong confidentiality. Caleto applies organization-scoped access controls, encryption, and audit logging to sensitive legal data. Security boundaries and deployment commitments are documented for each production environment.

Documented operational controls
Caleto is building a formal controls program and does not currently claim SOC 2 certification. We document implemented security policies, operational procedures, and data-management controls for customer diligence.
Automated security checks and internal control reviews support the program. Independent audit evidence will be shared only after the relevant assessment is completed.
Privacy controls and customer obligations
Caleto provides product controls intended to support customer privacy obligations, including GDPR and CCPA workflows. Customers remain responsible for assessing their own legal requirements.
Available controls include account deletion and export workflows, access controls, encryption, and contractual data-processing terms. Hosting and data-location commitments are confirmed in the applicable customer agreement.
Model-provider data handling
Caleto routes AI workloads through configured enterprise API providers and applies access controls around prompts, documents, and generated outputs. Provider scope and customer-data handling commitments are documented in the applicable agreement.
Caleto’s production-provider settings and contractual terms are reviewed for customer-data use. Specific retention and isolation commitments are documented during enterprise diligence and in the applicable agreement.
Safeguard Layer
Technical Implementation
Enterprise Benefit
Data Encryption
Provider-managed encryption at rest; TLS for data in transit.
Reduces the risk of interception and unauthorized access.
Network Isolation
Tenant isolation and deployment controls are documented during enterprise review.
Organization-scoped controls are designed to keep workspace assets separated.
Access Control
Email and password authentication, optional MFA, and workspace role controls.
Workspace roles and sharing controls govern access; finer-grained document permissions are still being hardened.
Vulnerability Scanning
Automated dependency and code scanning; independent penetration testing remains a pre-enterprise launch gate.
Proactively flags and remediates system vulnerabilities before code is deployed.
Built for the realities of modern institutional law
Legal operations require careful security controls. Caleto combines monitoring, access controls, audit logging, and encryption while formal external assessments and additional resilience work remain tracked readiness gates.
