Trust

European advice deserves European infrastructure.

Firms carry the confidentiality duty, not their suppliers. Constat is built so that duty is not quietly delegated to a processor on another continent.

Infrastructure

Processing
EU-owned, end to end
Language model
European (Mistral), zero data retention, enforced in code
US processors
None touch client or dossier data. The only non-EU service is Cloudflare's bot check on the public intake form, which sees a browser challenge and never content.
Encryption
Per-record envelope encryption, firm-held keys
Audit trail
Hash-chained, append-only
GDPR / DPIA
Completed with counsel and a DPO

Practices

Data minimisation

Uploaded originals are not retained after text extraction. The platform stores what the matter needs and states what it keeps.

Firm-held keys

Per-record envelope encryption means a record is readable only with the firm's key material, not by a blanket platform key.

Append-only audit

Every material action on a matter is written to a hash-chained log. Entries cannot be edited or removed after the fact, including by us.

Model discipline

Zero data retention is enforced in code at the integration boundary, not assumed from a contract term.

Data protection

Built for privileged data. The specifics.

  • Per-record envelope encryption (AES-256-GCM); the firm holds the keys, on EU-owned key infrastructure outside the application cloud.
  • DPIA completed with counsel of record and the DPO (July 2026); records of processing maintained.
  • Client data never appears in logs; the public intake stores submissions sealed and encrypted.
  • Automated retention: released consultations are erased after the configured horizon; audit entries keep their place in the tamper-evident chain with personal labels removed.
  • Transport security end to end, including certificate-verified database connections.
  • Multi-AZ database with encrypted backups; key-loss and restore procedures are drilled, not theoretical.
  • Single sign-on (OIDC), capability-based authorisation, an enforced strict content-security policy, and a WAF with rate limiting and a bot challenge on the public surfaces.
  • Site analytics are first-party only: aggregated from our own server logs with anonymised IP addresses. No cookies, no third-party trackers, no client identifiers.
  • Leaving is a documented path: every released dossier can be exported as a bundle for the firm's own document system; dossiers can be deleted from inside the product, with the deletion itself recorded in the audit trail; and automated retention erases released consultations after the configured horizon. Encrypted database backups age out on their own fixed window.

Who processes what

Sub-processors, honestly.

The complete list. A new sub-processor is added here before it processes anything.

ProviderWhereWhat it processes
Mistral AIEU (France)Language-model inference, zero data retention, enforced in code. EU endpoints only.
ScalewayEU (France)Custody of the firm's encryption keys (KEK), on EU-owned infrastructure. Sees keys, never content.
Amazon Web ServicesEU (Frankfurt, eu-central-1)Application hosting, database and backups. Client content rests there ciphertext-only; the keys that could open it are held outside AWS (documented sovereignty exception).
CloudflareUS / globalTurnstile bot check on the public intake form only. Sees the visitor's browser challenge, never dossier content.

Telephony (in-app calling) is in onboarding with an EU trunk provider; it will be added to this list, with its data-processing agreement, before the first live call.

Coverage

Dutch civil law, including the European law that governs it.

The jurisdiction is Dutch civil practice. European law is not a separate add-on: where EU law governs a practice area, it sits in the same verified corpus and passes the same render gate.

Dutch legislation and case law
Verified against wetten.overheid.nl and rechtspraak.nl, per practice area, counsel-ratified.
EU legislation
Regulations and directives that govern the covered practice areas (consumer, contract, labour, business) are verified against EUR-Lex, exactly like a Dutch statute.
Court of Justice case law
CJEU judgments in the covered areas are cited and verified against their EUR-Lex source with the same guarantee as a Hoge Raad judgment.

Honest boundary: no other member state's national law (Belgium and Germany are planned, not live), and no ECHR case law. EU law enters through the door of Dutch civil practice, not as a standalone research jurisdiction.

Documentation

What we can send your DPO.

DPIA, data processing agreement, sub-processor list, encryption and key-handling description, and audit-log specification. Ask and we will send the current set with your demo confirmation.

Request the documentation

What we do not claim yet

  • No ISO/IEC 27001 certification yet. It is on the roadmap for the multi-firm stage; the substance the certificate audits is described above and inspectable today.
  • No external penetration test yet. The internal security-audit sweep (blockers fixed, record kept) is available under NDA.
  • In-app calling is not yet live; it launches only after the trunk provider's data-processing agreement is on this page.

Responsible disclosure

Found a vulnerability? Report it to info@legal2u.ai and we will respond within two business days. Good-faith research on the public surfaces is welcome; do not access data that is not yours, and give us reasonable time to fix before disclosure. A machine-readable contact lives at /.well-known/security.txt.

Constat supports the diligence of the lawyer of record. It does not assume professional responsibility and does not substitute for the firm's own supervision and compliance obligations.