Eve Security, Privacy & Compliance Overview

Last updated: March 10, 2026

Overview

Eve maintains SOC 2 compliance and follows industry-standard security practices to protect attorney-client privileged communications and customer data. This article explains Eve's security infrastructure, data handling policies, compliance with privacy regulations, and how your firm's data is isolated from other firms on the platform.

How It Works

Security Infrastructure

Eve uses industry-standard encryption and monitoring to protect customer data:

  • Encryption at rest: All databases are encrypted at rest to protect stored data

  • Encryption in transit: All data transmitted to and from Eve uses TLS or SSL encryption

  • Audit logging: Eve uses AWS CloudWatch, a compliance automation platform client, AWS WAF, and AWS CloudTrail to monitor systems and security events

  • SOC 2 compliance: Eve maintains SOC 2 compliance and can share a copy of the SOC 2 report with customers who have entered the pilot stage

For a complete overview of Eve's security practices, visit: https://www.eve.legal/security-and-compliance

Data Retention and Deletion

After your agreement with Eve terminates or expires, Eve retains your customer data for 30 days. During this period, you can retrieve your data by submitting a prior written request. After the 30-day period ends, your service instance and all customer data are permanently deleted.

AI Model Training and Data Usage

Eve has a zero-retention agreement with the LLM vendors we use. This agreement prohibits those vendors from retaining your client data for the purpose of training AI models. Your firm's data is never used to improve results for other firms.

Tenant Isolation and Data Separation

Your firm's data is completely walled off from every other firm on the Eve platform. No other firm can see, access, or interact with your data. Eve enforces this separation (tenant isolation) at the technical level across the entire system. Your data is encrypted at rest and in transit, access is logged, and we never use one firm's data to improve results for another.

California Privacy Law Compliance

Eve's Privacy Policy includes specific provisions for California residents to comply with CCPA and CPRA requirements:

  • Right to access: California residents can request access to their personal data

  • Right to deletion: California residents can request deletion of their personal data

  • Non-discrimination: Eve does not discriminate against users for exercising their privacy rights

Key Terms

  • SOC 2 compliance: A security framework that demonstrates Eve follows industry best practices for protecting customer data

  • Tenant isolation: Technical separation that ensures one firm's data is completely walled off from all other firms on the platform

  • Zero-retention agreement: A contractual guarantee that LLM vendors cannot retain customer data for training AI models

  • Encryption at rest: Protection for stored data in databases

  • Encryption in transit: Protection for data being transmitted between systems using TLS or SSL