Trust & security

Trust you can verify.

Most platforms ask you to trust a badge. Constat is built the other way around: the protections are inspectable in the product itself, advice by advice. This page sets out the evidence, the data protections behind it, exactly who processes what, and what we do not claim yet.

The evidence

Verification is the product, not a policy.

A verification certificate with every advice

On release, the verification state is frozen and a certificate is issued: every cited authority, its source, licence and good-law status at that moment. You can hand it to a client or an insurer.

An append-only, hash-chained audit trail

Every consequential action is recorded in a tamper-evident chain; certificates are anchored to it. Nothing is silently editable, including by us.

Citations cannot render unverified

A reference that fails verification against its public source is technically impossible to display. There is no flag to ignore.

Monitoring after release

Cited case law is re-checked after your advice ships; the firm is alerted if an authority is later overruled or narrowed.

A conformity dossier, on demand

Any firm can download its own AI-governance evidence file at any moment: oversight, releases, certificates and the live-verified audit chain, generated deterministically — no model involved. Built for the EU AI Act's documentation expectations.

See it live

Any of the above can be demonstrated on the real platform in a twenty-minute call.

Coverage

Dutch civil law, including the European law that governs it.

The jurisdiction is Dutch civil practice. European law is not a separate add-on: where EU law governs a practice area, it sits in the same verified corpus and passes the same render gate.

Dutch legislation and case law

Verified against wetten.overheid.nl and rechtspraak.nl, per practice area, counsel-ratified.

EU legislation

Regulations and directives that govern the covered practice areas (consumer, contract, labor, business) are verified against EUR-Lex, exactly like a Dutch statute.

Court of Justice case law

CJEU judgments in the covered areas are cited and verified against their EUR-Lex source with the same guarantee as a Hoge Raad judgment.

Honest boundary: no other member state's national law (Belgium and Germany are planned, not live), and no ECHR/Strasbourg case law. EU law enters through the door of Dutch civil practice, not as a standalone research jurisdiction.

Data protection

Built for privileged data.

Per-record envelope encryption (AES-256-GCM); the firm holds the keys, on EU-owned key infrastructure outside the application cloud.

DPIA completed with counsel of record and the DPO (July 2026); records-of-processing maintained.

Client data never appears in logs; the public intake stores submissions sealed and encrypted.

Automated retention: released dossiers and audit events are erased after the configured horizon, with no orphan copies.

Transport security end to end, including certificate-verified database connections.

Multi-AZ database with encrypted backups; key-loss and restore procedures are drilled, not theoretical.

Single sign-on (OIDC), capability-based authorization, an enforced strict content-security policy, and a WAF with rate limiting and a bot challenge on the public surfaces.

Site analytics are first-party only: aggregated from our own server logs with anonymised IP addresses — no cookies, no third-party trackers, no client identifiers.

Who processes what

Sub-processors, honestly.

The complete list. A new sub-processor is added here before it processes anything.

Mistral AIEU (France)Language-model inference, zero-data-retention, enforced in code. EU endpoints only.
ScalewayEU (France)Custody of the firm's encryption keys (KEK), on EU-owned infrastructure. Sees keys, never content.
Amazon Web ServicesEU (Frankfurt, eu-central-1)Application hosting, database and backups. Client content rests there ciphertext-only; the keys that could open it are held outside AWS (documented sovereignty exception).
CloudflareUS/globalTurnstile bot-check on the public intake form only. Sees the visitor's browser challenge, never dossier content.

Telephony (in-app calling) is in onboarding with an EU trunk provider; it will be added to this list, with its data-processing agreement, before the first live call.

Responsible disclosure

Found a vulnerability?

Report it to info@legal2u.ai and we will respond within two business days. Good-faith research on the public surfaces is welcome; do not access data that is not yours, and give us reasonable time to fix before disclosure. A machine-readable contact lives at /.well-known/security.txt.

Documents

The paper trail.

The DPIA memorandum, the internal security-audit record, and architecture notes are available to firms and their advisers under NDA: request at info@legal2u.ai. The AI & privacy notice for clients is public.

What we do not claim yet

The honest list.

No ISO/IEC 27001 certification yet. It is on the roadmap for the multi-firm stage; the substance the certificate audits is described above and inspectable today.

No external penetration test yet. The internal security-audit sweep (blockers fixed, record kept) is available under NDA.

In-app calling is not yet live; it launches only after the trunk provider's data-processing agreement is on this page.