Security

ContractKen protects your data and your clients' information with top security features and protocols.

ContractKen Legal & Security FAQ

Last updated: July 23, 2025
Have a due‑diligence questionnaire (DDQ) or security review? Email hello@contractken.com and we’ll respond fast.

1. Data Privacy & Confidentiality

Q1. What data does ContractKen process?

We offer a free, 14 day,We process only what’s needed to deliver the service: the contract text you choose to analyze, your playbooks / precedents / instructions, and minimal account metadata (account data, usage logs). We do not scan your entire Word document repository or inbox, etc. by default.guided trial for all customers.

Q2. Do you use our data to train public models?

No. Your documents, prompts, and outputs are never used to train or fine‑tune any public or shared model. They remain your property.

Q3. How is our data segregated from other customers?

We use strict tenant‑level logical isolation and per‑customer encryption keys. Your data is never mixed with another customer’s corpus.

Q4. Where is data stored and processed?

Primary hosting is on AWS. We can provide EU/US data residency on request and share our current sub‑processor list.

Q5. Can we delete our data at any time?

Yes. Admins can request immediate purge of documents, prompts, logs, and backups. Routine retention is 30 days; for operational logs; you can contractually set this to 0.

Q6. How do you preserve attorney-client privilege?

We treat all content as confidential work product. Access is role‑based, logged, and limited to support engineers on a need‑to‑know basis under NDA and confidentiality obligations.

2. Security & Compliance

Q7. Are you SOC 2 / ISO certified?

Yes, ContractKen holds SOC 2 Type II (latest report available under NDA). We align with ISO 27001/27701 controls and share our security white‑paper on request.

Q8. How is data encrypted?

TLS 1.2+ in transit; AES‑256 at rest using AWS Key Vault/HSM‑backed keys. Customer‑managed keys are available for enterprise plans.

Q9. What is your incident response process?

We have a documented plan with 24×7 monitoring. Clients are notified of any material incident without undue delay (contractually within 72 hours or faster if required by law).

Q10. Do you allow security audits or pen tests?

We conduct annual third‑party penetration tests and share executive summaries. Customer audits are welcome under reasonable notice and confidentiality.

Q11. Do you support SSO/MFA and granular access controls?

Yes, for enterprise customers. SSO via Azure AD, Okta, Google Workspace, etc. MFA is enforced for admins. RBAC lets you control who can upload playbooks, review drafts, or export data.

Q12. Can we get audit logs?

Yes. Enterprise admins can view/export logs showing who opened, edited, or exported which document and when.

3. AI/Model Governance & IP

Q13. Which AI models do you use? Can we choose our own?

We default to best‑in‑class LLMs (e.g., OpenAI, Google via API) behind our moderation layer. Enterprise customers can bring their own model/endpoint.

Q14. Do upstream model providers see our data?

Requests are sent via private, no‑training endpoints. Providers contractually commit not to use your data for training. We mask PII/sensitive fields when configured.

Q15. Who owns the AI‑generated clauses/redlines?

You do. We grant no license beyond what’s needed to run the service. Outputs are yours to use, modify, or delete.

Q16. How do you reduce hallucinations or inaccurate suggestions?

We ground the model on your own playbooks/precedents, show sources, and encourage human review. Our UI flags low‑confidence suggestions.

Q17. Can we view or export the prompts ContractKen sends?

Yes. Admins can enable prompt/history export for audit or compliance reviews.

Q18. How do you handle third‑party sample clauses?

All bundled sample language is either authored by us, licensed, or sourced from public‑domain materials. You can store your own precedents privately.

4. Legal Terms & Risk Allocation

Q19. What warranties do you provide?

We warrant that the service will perform materially as documented and that we won’t knowingly infringe third‑party IP. We don’t warrant legal accuracy of AI outputs-lawyer review is required.

Q20. How do you limit liability?

Standard caps are tied to annual fees with carve‑outs for data breach, gross negligence, and IP infringement. We’re open to reasonable adjustments for enterprise deals.

Q21. Do you indemnify customers?

Yes-for third‑party IP infringement claims arising from our service. We also carry cyber/E&O insurance and can share certificates.

Q22. What is your SLA?

99.5 % uptime monthly. Priority support SLAs: P1 within 2 hours, P2 within 8 hours. Service credits apply if we miss targets.

Q23. How can we terminate and get our data out?

You can export contracts, playbooks, logs, and metadata (DOCX/JSON/CSV) before termination. We’ll assist for 30 days post‑termination if requested.

Q24. Governing law & dispute resolution?

Typically Delaware law & arbitration (JAMS/AAA). We’re flexible to match your jurisdictional needs.

5. Implementation, Integrations & Operations

Q25. What permissions does the Word add‑in require?

Minimal: it reads the active document content you choose to analyze and sends it securely to our backend for processing. It does not access other files or emails.

Q26. Can we keep data entirely inside our environment?

For highly regulated teams, we offer a private deployment where all inference happens in your Azure tenant or VPC.

Q27. How fast is it?

Typical redline generation is under 10 seconds for a standard agreement; larger agreements (e.g., 100+ pages) average 20–40 seconds.

Q28. Will the tool work with our own playbooks and clause libraries?

Absolutely. Upload them securely; ContractKen will screen drafts against your standards and suggest edits accordingly.

Q29. How do you communicate product or model changes?

We maintain a public changelog and provide 30 days’ notice for any change that could materially affect data handling or SLAs.

6. Ethics, Compliance & Governance

Q30. Do you monitor for bias or misuse?

Yes. We test models on diverse contract sets and provide transparency on limitations. We also let admins enforce redaction rules to avoid prohibited data in prompts.

Q31. Is AI‑generated content clearly labeled?

Yes. Suggestions are visually distinct in Word, with comments explaining the rationale.

Q32. Do you comply with GDPR/CCPA and similar laws?

Yes. We sign DPAs, honor data‑subject rights (access, deletion, portability), and act as a processor under GDPR and a service provider under CCPA/CPRA.

7. Need More Detail?

  • Security White‑paper & Data‑flow Diagram – request via hello@contractken.com
  • SOC 2 Report / Pen‑test Summary – under mutual NDA
  • DPA, Sub‑processor List & Insurance Certs – available on request
  • Custom Terms (BYO model, on‑prem, escrow) – talk to hello@contractken.com
Still have questions? Send us your DDQ spreadsheet or questionnaire - we’ll turn it around quickly.
Book a 20‑minute security / legal deep‑dive

ContractKen Legal & Security FAQ

Last updated: July 23, 2025
Have a due‑diligence questionnaire (DDQ) or security review? Email hello@contractken.com and we’ll respond fast.

1. Data Privacy & Confidentiality

We process only what’s needed to deliver the service: the contract text you choose to analyze, your playbooks / precedents / instructions, and minimal account metadata (account data, usage logs). We do not scan your entire Word document repository or inbox, etc. by default.

No. Your documents, prompts, and outputs are never used to train or fine‑tune any public or shared model. They remain your property.

We use strict tenant‑level logical isolation and per‑customer encryption keys. Your data is never mixed with another customer’s corpus.

Primary hosting is on AWS. We can provide EU/US data residency on request and share our current sub‑processor list.

Yes. Admins can request immediate purge of documents, prompts, logs, and backups. Routine retention is 30 days; for operational logs; you can contractually set this to 0.

We treat all content as confidential work product. Access is role‑based, logged, and limited to support engineers on a need‑to‑know basis under NDA and confidentiality obligations.

2. Security & Compliance

Yes, ContractKen holds SOC 2 Type II (latest report available under NDA). We align with ISO 27001/27701 controls and share our security white‑paper on request.

TLS 1.2+ in transit; AES‑256 at rest using AWS Key Vault/HSM‑backed keys. Customer‑managed keys are available for enterprise plans.

We have a documented plan with 24×7 monitoring. Clients are notified of any material incident without undue delay (contractually within 72 hours or faster if required by law).

We conduct annual third‑party penetration tests and share executive summaries. Customer audits are welcome under reasonable notice and confidentiality.

Yes, for enterprise customers. SSO via Azure AD, Okta, Google Workspace, etc. MFA is enforced for admins. RBAC lets you control who can upload playbooks, review drafts, or export data.

Yes. Enterprise admins can view/export logs showing who opened, edited, or exported which document and when.

3. AI/Model Governance & IP

We default to best‑in‑class LLMs (e.g., OpenAI, Google via API) behind our moderation layer. Enterprise customers can bring their own model/endpoint.

Requests are sent via private, no‑training endpoints. Providers contractually commit not to use your data for training. We mask PII/sensitive fields when configured.

You do. We grant no license beyond what’s needed to run the service. Outputs are yours to use, modify, or delete.

We ground the model on your own playbooks/precedents, show sources, and encourage human review. Our UI flags low‑confidence suggestions.

Yes. Admins can enable prompt/history export for audit or compliance reviews.

All bundled sample language is either authored by us, licensed, or sourced from public‑domain materials. You can store your own precedents privately.

We warrant that the service will perform materially as documented and that we won’t knowingly infringe third‑party IP. We don’t warrant legal accuracy of AI outputs-lawyer review is required.

Standard caps are tied to annual fees with carve‑outs for data breach, gross negligence, and IP infringement. We’re open to reasonable adjustments for enterprise deals.

Yes-for third‑party IP infringement claims arising from our service. We also carry cyber/E&O insurance and can share certificates.

99.5 % uptime monthly. Priority support SLAs: P1 within 2 hours, P2 within 8 hours. Service credits apply if we miss targets.

You can export contracts, playbooks, logs, and metadata (DOCX/JSON/CSV) before termination. We’ll assist for 30 days post‑termination if requested.

Typically Delaware law & arbitration (JAMS/AAA). We’re flexible to match your jurisdictional needs.

5. Implementation, Integrations & Operations

Minimal: it reads the active document content you choose to analyze and sends it securely to our backend for processing. It does not access other files or emails.

For highly regulated teams, we offer a private deployment where all inference happens in your Azure tenant or VPC.

Typical redline generation is under 10 seconds for a standard agreement; larger agreements (e.g., 100+ pages) average 20–40 seconds.

Absolutely. Upload them securely; ContractKen will screen drafts against your standards and suggest edits accordingly.

We maintain a public changelog and provide 30 days’ notice for any change that could materially affect data handling or SLAs.

6. Ethics, Compliance & Governance

Yes. We test models on diverse contract sets and provide transparency on limitations. We also let admins enforce redaction rules to avoid prohibited data in prompts.

Yes. Suggestions are visually distinct in Word, with comments explaining the rationale.

Yes. We sign DPAs, honor data‑subject rights (access, deletion, portability), and act as a processor under GDPR and a service provider under CCPA/CPRA.

7. Need More Detail?

  • Security White‑paper & Data‑flow Diagram – request via hello@contractken.com
  • SOC 2 Report / Pen‑test Summary – under mutual NDA
  • DPA, Sub‑processor List & Insurance Certs – available on request
  • Custom Terms (BYO model, on‑prem, escrow) – talk to hello@contractken.com

Still have questions? Send us your DDQ spreadsheet or questionnaire - we’ll turn it around quickly.
Book a 20‑minute security / legal deep‑dive