Eve Security, Privacy & Compliance Overview
Last updated: March 10, 2026
Overview
Eve maintains SOC 2 compliance and follows industry-standard security practices to protect attorney-client privileged communications and customer data. This article explains Eve's security infrastructure, data handling policies, compliance with privacy regulations, and how your firm's data is isolated from other firms on the platform.
How It Works
Security Infrastructure
Eve uses industry-standard encryption and monitoring to protect customer data:
Encryption at rest: All databases are encrypted at rest to protect stored data
Encryption in transit: All data transmitted to and from Eve uses TLS or SSL encryption
Audit logging: Eve uses AWS CloudWatch, a compliance automation platform client, AWS WAF, and AWS CloudTrail to monitor systems and security events
SOC 2 compliance: Eve maintains SOC 2 compliance and can share a copy of the SOC 2 report with customers who have entered the pilot stage
For a complete overview of Eve's security practices, visit: https://www.eve.legal/security-and-compliance
Data Retention and Deletion
After your agreement with Eve terminates or expires, Eve retains your customer data for 30 days. During this period, you can retrieve your data by submitting a prior written request. After the 30-day period ends, your service instance and all customer data are permanently deleted.
AI Model Training and Data Usage
Eve has a zero-retention agreement with the LLM vendors we use. This agreement prohibits those vendors from retaining your client data for the purpose of training AI models. Your firm's data is never used to improve results for other firms.
Tenant Isolation and Data Separation
Your firm's data is completely walled off from every other firm on the Eve platform. No other firm can see, access, or interact with your data. Eve enforces this separation (tenant isolation) at the technical level across the entire system. Your data is encrypted at rest and in transit, access is logged, and we never use one firm's data to improve results for another.
California Privacy Law Compliance
Eve's Privacy Policy includes specific provisions for California residents to comply with CCPA and CPRA requirements:
Right to access: California residents can request access to their personal data
Right to deletion: California residents can request deletion of their personal data
Non-discrimination: Eve does not discriminate against users for exercising their privacy rights
Key Terms
SOC 2 compliance: A security framework that demonstrates Eve follows industry best practices for protecting customer data
Tenant isolation: Technical separation that ensures one firm's data is completely walled off from all other firms on the platform
Zero-retention agreement: A contractual guarantee that LLM vendors cannot retain customer data for training AI models
Encryption at rest: Protection for stored data in databases
Encryption in transit: Protection for data being transmitted between systems using TLS or SSL