Most platforms ask you to trust a badge. Constat is built the other way around: the protections are inspectable in the product itself, advice by advice. This page sets out the evidence, the data protections behind it, exactly who processes what, and what we do not claim yet.
On release, the verification state is frozen and a certificate is issued: every cited authority, its source, licence and good-law status at that moment. You can hand it to a client or an insurer.
Every consequential action is recorded in a tamper-evident chain; certificates are anchored to it. Nothing is silently editable, including by us.
A reference that fails verification against its public source is technically impossible to display. There is no flag to ignore.
Cited case law is re-checked after your advice ships; the firm is alerted if an authority is later overruled or narrowed.
Any firm can download its own AI-governance evidence file at any moment: oversight, releases, certificates and the live-verified audit chain, generated deterministically — no model involved. Built for the EU AI Act's documentation expectations.
Any of the above can be demonstrated on the real platform in a twenty-minute call.
The jurisdiction is Dutch civil practice. European law is not a separate add-on: where EU law governs a practice area, it sits in the same verified corpus and passes the same render gate.
Verified against wetten.overheid.nl and rechtspraak.nl, per practice area, counsel-ratified.
Regulations and directives that govern the covered practice areas (consumer, contract, labor, business) are verified against EUR-Lex, exactly like a Dutch statute.
CJEU judgments in the covered areas are cited and verified against their EUR-Lex source with the same guarantee as a Hoge Raad judgment.
Honest boundary: no other member state's national law (Belgium and Germany are planned, not live), and no ECHR/Strasbourg case law. EU law enters through the door of Dutch civil practice, not as a standalone research jurisdiction.
Per-record envelope encryption (AES-256-GCM); the firm holds the keys, on EU-owned key infrastructure outside the application cloud.
DPIA completed with counsel of record and the DPO (July 2026); records-of-processing maintained.
Client data never appears in logs; the public intake stores submissions sealed and encrypted.
Automated retention: released dossiers and audit events are erased after the configured horizon, with no orphan copies.
Transport security end to end, including certificate-verified database connections.
Multi-AZ database with encrypted backups; key-loss and restore procedures are drilled, not theoretical.
Single sign-on (OIDC), capability-based authorization, an enforced strict content-security policy, and a WAF with rate limiting and a bot challenge on the public surfaces.
Site analytics are first-party only: aggregated from our own server logs with anonymised IP addresses — no cookies, no third-party trackers, no client identifiers.
The complete list. A new sub-processor is added here before it processes anything.
Telephony (in-app calling) is in onboarding with an EU trunk provider; it will be added to this list, with its data-processing agreement, before the first live call.
Report it to info@legal2u.ai and we will respond within two business days. Good-faith research on the public surfaces is welcome; do not access data that is not yours, and give us reasonable time to fix before disclosure. A machine-readable contact lives at /.well-known/security.txt.
The DPIA memorandum, the internal security-audit record, and architecture notes are available to firms and their advisers under NDA: request at info@legal2u.ai. The AI & privacy notice for clients is public.
No ISO/IEC 27001 certification yet. It is on the roadmap for the multi-firm stage; the substance the certificate audits is described above and inspectable today.
No external penetration test yet. The internal security-audit sweep (blockers fixed, record kept) is available under NDA.
In-app calling is not yet live; it launches only after the trunk provider's data-processing agreement is on this page.