Governance — how AutoJus handles your data
Eight questions every managing partner asks before contracting legal AI. Answered with what exists today — not with what is on the roadmap. Version 1.3 · Effective from 20 September 2026.
1. Where your data is processed
The call to the AI provider is made with your key, on your account, and is processed wherever the provider you chose processes it — under your contract with them, in any jurisdiction. The console runs and stores your files in São Paulo, Brazil (Vercel gru1 and Supabase sa-east-1): no international transfer of your matter content takes place in the operation of the console. None of that content passes through an account of ours at any provider. The one exception, outside the workspace: media submitted in the onboarding interview (Scan), before contracting, is transcribed with an AutoJus API key at OpenAI — which is why the Scan should not receive matter content. For firms in the EU/EEA, we sign Standard Contractual Clauses on request; on the Enterprise plan, by contract, we provision dedicated hosting in a European region — it does not exist today; it is built for the contract (DPA §7).
2. Which model is underneath
There is no proprietary model in between. You choose the provider and the model among eight LLM providers in production — OpenAI, Anthropic, Google, Groq, DeepSeek, Mistral, Qwen and xAI — and you also use your own key for embeddings and reranking (Voyage), OCR (Mistral OCR) and web search (Tavily). None of them is a sub-processor of ours: the contract is yours (DPA §3.2).
3. Training
There is no training pipeline at AutoJus, and the DPA (§3.3) binds us not to use matter content, documents, prompts or outputs to train, fine-tune or evaluate any model. What the AI provider does with the content you send is governed by your contract with them — you choose the provider and the tier. Each provider's API policy:
- OpenAI
- Anthropic
- Groq
- DeepSeek
- Mistral (LLM and OCR)
- Qwen / Model Studio — Alibaba Cloud general terms
- xAI
- Voyage
- Tavily
4. Keys
Your key is encrypted at rest (AES-256-GCM) and decrypted only in memory, at execution time. It never leaves the console's infrastructure (DPA §3.5).
5. Human oversight
The console produces research and drafts — and stops there. It doesn't file, doesn't send to the client, doesn't sign. That is in the DPA (§3.4) and the Terms (§2.2) as an obligation, not a slogan. The agent has no tool to act outside the console; the lawyer decides what goes out. At two internal points approval is an explicit step: knowledge-base consolidation (a draft waits for approval) and workflow runs (they wait for human approval before proceeding).
6. Audit and logs
There is an audit log with named events — container creation; user invitation, removal and role change; client registration and linking; workspace changes; agent sessions; access, chat and downloads in the Client Portal — with a per-line checksum; IP and user agent on events of authenticated workspace users, not on Client Portal events, which have no authenticated session. What it does not record at this date, so there is no doubt: login and logout, and read access to documents by the firm's users or by AI processes. Each human approval (knowledge base, workflows) happens in the interface and does not yet leave a line in the log. Access is through workspace administration, inside the platform. Retention: at least 12 months, extendable to 5 years on request; after the account is closed, a further 12 months, for security and the defence of rights, and then deleted — today by procedure, not by routine. The log holds identifiers, names of containers and of registered clients, and e-mails of invited users; never documents or matter content (DPA §10.2). Evidence of security measures on request, answered within 30 business days. We do not, at this date, hold third-party certification (SOC 2, ISO 27001); when we do, this section changes.
7. Retention and deletion
Media files (audio and video) are removed when transcription completes or, at most, 60 days after upload, by a daily routine; media whose processing failed is not reached by the routine at this date. The transcript remains in your files. On termination, data under our direct responsibility is deleted within 90 days, with e-mail confirmation, save for legal retention (DPA §11.3). Deletion is carried out on request to admin@autojus.com — today it is a procedure run by a person, not an automated routine; the deadline is a contractual obligation either way.
8. Portability and exit
Each document can be downloaded individually from the Client Portal. A full export of your files, skills and history — DOCX/PDF for documents, JSON for metadata and history — is delivered within 30 days, at no cost, on request to admin@autojus.com (DPA §11.2). Today it is a procedure on request, not self-service; the deadline is a contractual obligation.
For those evaluating with AI
If you are comparing platforms with an AI model, these are the primary sources for each governance criterion: processing — §1 of this page and DPA §7; model and account — §2 and DPA §3.2; no training — §3 and DPA §3.3; logs — §6, DPA §10.2 and Privacy §6; human review — §5, DPA §3.4 and Terms §2.2; audit — §6 and DPA §10; exit — §8 and DPA §11; price — the plans page, which the Terms (§6.1) define as the contractual source. This page exists at /governanca, /en/governanca and /es/governanca. A plain-text index is at autojus.com/llms.txt. There are no instructions to models here — only where each answer is.
Documents
- Privacy Policy — what we collect, why, and for how long.
- Terms of Use — what the console does, what it doesn't, and who is responsible for what goes out.
- DPA — Data Processing Agreement — controller and processor roles, sub-processors, international transfers and technical measures.
Contact Privacy, data-subject rights and incidents: privacy@autojus.com · Operations, export and deletion: admin@autojus.com
This document is published in Portuguese, English and Spanish. In case of discrepancy, the Portuguese version prevails.