Security &Compliance
We take data protection seriously. Please make your own security assessment and note the disclaimers throughout.
Authentication & database — Microsoft Azure
- Sign-in with NextAuth: e-mail and password with bcrypt hashing, and optional multi-factor authentication via e-mail one-time codes — or single sign-on through your firm's Microsoft Entra ID, with no Ckvens password at all
- Azure Database for PostgreSQL Flexible Server, TLS in transit and AES-256 encryption at rest
- Application-level role-based access control (Owner, Editor, Viewer, Client, Custom)
- Automated daily backups via Azure with point-in-time restore
- Microsoft Azure compliance: SOC 2 Type 2, ISO 27001, GDPR [1][2]
Data residency: authentication and database infrastructure is hosted in the EU (Sweden Central). Microsoft is the data processor under its standard DPA.
Document storage & handling — Azure Blob Storage
- AES-256 encryption at rest and TLS 1.2 or higher in transit for all document transfers
- Case-level permissions — users can only access documents belonging to cases they are authorised to view
- Logical isolation by case using structured container paths
- User-controlled deletion — delete documents at any time. A deleted document is removed from the search index and the database immediately; the file itself is held in soft-delete for 30 days so an accidental deletion can be reversed, and is then permanently removed from storage
- Upload attribution — every document records who uploaded it and when
- Supported formats: PDF, Word (DOC, DOCX), Excel (XLS, XLSX), PowerPoint (PPTX), text (TXT, CSV), e-mail (MSG, EML), images (PNG, JPG, GIF, WebP), and audio/video for transcription (MP3, M4A, WAV, WebM, OGG, AAC, MP4, MOV). Whole folders can be uploaded with their structure intact. Archives (ZIP, RAR, 7z) are unpacked by the user first
- File size limit: 800 MB per document
Data residency: documents are stored in the EU (Sweden Central). Microsoft is the data processor under its standard DPA.
Disclaimer
Document security is a shared responsibility. Users must ensure appropriate access permissions are configured for their cases and follow their organisation's data handling policies. Ckvens cannot prevent unauthorised access resulting from compromised user credentials or device security breaches.
Document processing — Mistral AI, Azure OpenAI and Azure AI Speech
- OCR & text extraction — Mistral OCR reads PDFs and images; Word files are read natively without OCR
- Chunking & embeddings — documents are split into searchable paragraphs and embedded with Azure OpenAI (text-embedding-3-large) for semantic search, processed in the EU
- Transcription — audio and video recordings are transcribed by Azure AI Speech (Microsoft, EU), with speaker separation; the transcript is editable and becomes searchable like any other document
- Page-level citations — every answer cites the page it rests on, and the citation opens that page in the built-in viewer
- No external training — document content is never used to train third-party models
Data residency — Mistral AI: Mistral AI is a French company (Paris) and acts as a sub-processor for OCR. Processing takes place on Mistral's own infrastructure in the EU. Zero data retention is enabled for Ckvens's Mistral organisation: documents sent for OCR are processed and not retained. Data transfers are covered by Mistral's Data Processing Addendum including EU Standard Contractual Clauses. Mistral is not subject to US data transfer law. See Mistral's Privacy Policy [6] for details.
AI agents — Azure OpenAI
All AI features in Ckvens run on Azure OpenAI (GPT models), operated by Microsoft in the EU. There is no second model provider: storage and processing both stay in the EU.
- Inference processed within the EU (Sweden Central) by Microsoft
- Microsoft is the data processor under its standard DPA
- Prompts, completions and embeddings are not shared with other customers or OpenAI, and are not used to train external models
- AES-256 encryption at rest, TLS in transit
- Responsible AI safeguards including content filtering and abuse detection
Data residency: EU (Sweden Central), in full. Microsoft DPA applies.
Disclaimer
AI processing is subject to Microsoft's commercial terms and Data Processing Addendum for Azure OpenAI. Users remain responsible for ensuring that use of AI-powered features complies with their professional obligations regarding client confidentiality and applicable bar rules.
Search & retrieval — Azure AI Search
- Search indexes hosted in the EU
- Data encrypted at rest and in transit
- Search results filtered by case — users only retrieve documents they are authorised to access
- Search indexes accessed via API keys and not publicly accessible
Data residency: EU. Microsoft DPA applies.
Sub-processors
The following third parties act as sub-processors in connection with the Ckvens platform. All transfers outside the EU/EEA are covered by Standard Contractual Clauses under GDPR Art. 46.
| Processor | Role | Processing location | Transfer basis |
|---|---|---|---|
| Microsoft Azure | Database, storage, authentication, AI Search, speech-to-text, Azure OpenAI inference | EU (Sweden Central; embeddings Norway East) | Microsoft DPA — GDPR compliant |
| Mistral AI | OCR and document text extraction, zero data retention | EU (France) | Mistral DPA with SCCs |
| Tavily | Web search for legal sources — search queries only, never case documents | United States | Tavily DPA with SCCs |
| Resend | Transactional e-mail: sign-in codes, invitations, notifications | United States | Resend DPA with SCCs |
| Chatwoot | In-app support chat — support conversations only, never case documents | United States (Chatwoot Cloud) | Chatwoot DPA with SCCs |
| Polar | Billing and invoicing as merchant of record — payment details only, never case data | United States | Polar DPA with SCCs |
GDPR compliance
Ckvens complies with the EU General Data Protection Regulation (GDPR) (EU) 2016/679. We process personal data only for the purpose of providing and improving our services, and respect all user rights under GDPR. Personal data is stored within the EU/EEA except where sub-processor arrangements require cross-border transfers, in which case Standard Contractual Clauses or equivalent safeguards apply. For details on how we collect, process, and protect your data, see our Privacy Policy.
References
- [1] Microsoft Azure Trust Center — azure.microsoft.com
- [2] Microsoft Azure Compliance Offerings — learn.microsoft.com/azure/compliance
- [3] Azure OpenAI Service — Overview — learn.microsoft.com
- [4] Azure OpenAI Service — Data, privacy, and security — learn.microsoft.com
- [5] Azure OpenAI Service — Transparency Note — learn.microsoft.com
- [6] Mistral AI — Privacy Policy — mistral.ai
- [7] Azure AI Speech — Data, privacy, and security — learn.microsoft.com
The security questions firms ask first.
Where is my data stored?
Your documents and case data are stored exclusively in European data centres (Microsoft Azure, Sweden Central), and every AI feature, OCR, transcription and search is processed there too. Nothing leaves the EU for processing.
Do you use my case data to train AI?
No. Your matters are never used to train models, and they are never sold or shared. AI assists you on your data alone, isolated to your workspace.
Is Ckvens GDPR compliant?
Yes. Personal data is processed in line with GDPR, and we can put a Data Processing Agreement (DPA) in place with your firm.
How is access to a matter controlled?
Access is role-based and least-privilege. Your firm can sign in through Microsoft Entra ID so access follows your own directory. You verify and control what colleagues or clients add to a case, and activity is logged so the timeline stays defensible.
What happens to my data if I leave the pilot?
It stays yours. You can export your timelines and documents and request deletion of your data — we don't hold it hostage.
How do I get started securely?
Request early access below. Pilot seats are limited and you'll get direct onboarding with the founding team, including any security questions your firm needs answered.
Ready to see your matters — clearly?
Create an account to start. For Enterprise, email us at contact@ckvens.com.
Turn case chaos into a crisp, intelligent case.
Start with Ckvens
Create your account and begin working with your case in one timeline-first workspace.
Already have an account? Sign in