Security

We take data protection seriously. Please make your own security assessment and note the disclaimers throughout.

Authentication & database — Microsoft Azure

  • NextAuth with bcrypt password hashing
  • Optional multi-factor authentication (MFA) via email one-time codes
  • Azure PostgreSQL Flexible Server with TLS in transit and AES-256 encryption at rest
  • Application-level role-based access control (Owner, Editor, Viewer, Client, Custom)
  • Automated daily backups via Azure with point-in-time restore
  • Microsoft Azure compliance: SOC 2 Type 2, ISO 27001, GDPR-ready[1][2]

Data residency: Authentication and database infrastructure is hosted in EU (Sweden Central). Microsoft is the data processor under its standard DPA.

Document storage & handling — Azure Blob Storage

  • AES-256 encryption at rest and TLS 1.3 in transit for all document transfers
  • Case-level permissions — users can only access documents belonging to cases they are authorised to view
  • Logical isolation by case using structured container paths
  • User-controlled deletion — permanently delete documents at any time; deleted files are removed from storage, search indexes, and database records
  • Audit logging — track who uploaded or deleted documents and when
  • Supported formats: PDF, DOCX, XLSX, TXT, CSV, images (PNG, JPG, GIF, WebP), and more
  • File size limit: 800 MB per document

Data residency: Documents are stored in EU (Sweden Central). Microsoft is the data processor under its standard DPA.

Disclaimer

Document security is a shared responsibility. Users must ensure appropriate access permissions are configured for their cases and follow their organisation's data handling policies. Ckvens cannot prevent unauthorised access resulting from compromised user credentials or device security breaches.

Document processing — Mistral AI & Docling

  • OCR & text extraction — Mistral OCR processes PDFs and images; DOCX files are processed natively
  • Chunking & embeddings — documents are split into searchable paragraphs and embedded using Azure OpenAI (text-embedding-3-large) for semantic search
  • Visual grounding — Docling generates page images for citation-level visual references
  • No external training — document content is never used to train third-party models

Data residency — Mistral AI: Mistral AI is a French company (Paris) and acts as a sub-processor for OCR and document analysis. Processing takes place on Mistral's own infrastructure. Data transfers are covered by Mistral's Data Processing Addendum including EU Standard Contractual Clauses. Mistral is not subject to US data transfer law. See Mistral's Privacy Policy[6] for details.

AI agents — two providers, one residency regime

Ckvens uses two AI model providers depending on the task. Both process data within the EU.

Azure OpenAI (GPT models)

EU-resident
  • Inference processed within EU (Sweden Central) by Microsoft
  • Microsoft is the data processor under its standard DPA
  • Prompts, completions, and embeddings are not shared with other customers or OpenAI, and are not used to train external models
  • AES-256 encryption at rest, TLS in transit
  • Responsible AI safeguards including content filtering and abuse detection

Data residency: Guaranteed EU (Sweden Central). Microsoft DPA applies.

Anthropic Claude models (via Amazon Bedrock, AWS European regions)

EU-resident
  • EU-resident. Claude models are served through Amazon Bedrock on AWS infrastructure in the European Union, with Frankfurt (eu-central-1) as the primary region. Inference and data at rest remain within the EU.
  • AWS — not Anthropic — is the data processor. On Amazon Bedrock, model providers have no access to customer content: prompts and outputs are never shared with Anthropic, are not stored by the service after the request completes, and are not used to train models — Anthropic's or anyone else's.
  • Prompts and outputs are not shared with other customers.
  • AES-256 encryption at rest, TLS in transit.
  • Access is authenticated with short-lived, role-based federated credentials — no static cloud keys exist in the application.
  • The AWS GDPR Data Processing Addendum applies, incorporating Standard Contractual Clauses under GDPR Art. 46 for any residual transfers (e.g. remote support).

Data residency: EU (AWS European regions, primary Frankfurt). AWS DPA applies. Ckvens has updated its Transfer Impact Assessment to reflect this arrangement and will make it available to customers on request.

Disclaimer

AI processing is subject to the respective cloud provider's commercial terms and Data Processing Addendum (Microsoft for GPT models, AWS for Claude models). Users remain responsible for ensuring that use of AI-powered features complies with their professional obligations regarding client confidentiality and applicable bar rules.

Search & retrieval — Azure AI Search

  • Search indexes hosted in EU
  • Data encrypted at rest and in transit
  • Search results filtered by case — users only retrieve documents they are authorised to access
  • Search indexes accessed via API keys and not publicly accessible

Data residency: EU. Microsoft DPA applies.

Sub-processors

The following third parties act as sub-processors in connection with the Ckvens platform. All transfers outside the EU/EEA are covered by Standard Contractual Clauses under GDPR Art. 46.

ProcessorRoleProcessing locationTransfer basis
Microsoft AzureDatabase, storage, authentication, AI Search, Azure OpenAI inferenceEU (Sweden Central)Microsoft DPA — GDPR compliant
Amazon Web Services (AWS)Claude model inference (via Amazon Bedrock)EU (Frankfurt, eu-central-1)AWS DPA with SCCs; TIA updated by Ckvens
Mistral AIOCR and document text extractionEU (France)Mistral DPA with SCCs

GDPR compliance

Ckvens complies with the EU General Data Protection Regulation (GDPR) (EU) 2016/679. We process personal data only for the purpose of providing and improving our services, and respect all user rights under GDPR. Personal data is stored within the EU/EEA except where sub-processor arrangements require cross-border transfers, in which case Standard Contractual Clauses or equivalent safeguards apply. For details on how we collect, process, and protect your data, see our Privacy Policy.

References

Security FAQ

The security questions firms ask first.

Where is my data stored?

In the EU, on Microsoft Azure infrastructure. Your case data does not leave European data centres, which keeps it within GDPR's jurisdiction.

Do you use my case data to train AI?

No. Your matters are never used to train models, and they are never sold or shared. AI assists you on your data alone, isolated to your workspace.

Is Ckvens GDPR compliant?

Yes. Personal data is processed in line with GDPR, and we can put a Data Processing Agreement (DPA) in place with your firm.

How is access to a matter controlled?

Access is role-based and least-privilege. You verify and control what colleagues or clients add to a case, and activity is logged so the timeline stays defensible.

What happens to my data if I leave the pilot?

It stays yours. You can export your timelines and request deletion of your data — we don't hold it hostage.

How do I get started securely?

Request early access below. Pilot seats are limited and you'll get direct onboarding with the founding team, including any security questions your firm needs answered.

Ready to see your matters — clearly?

Submit the form to join our pilot. You can also email us at contact@ckvens.com.

Join and turn case chaos into a crisp, intelligent case.

Get access

i

Seats are limited. We'll review your request and get back to you with next steps.