Copenhagen, July 2026
Juristic has completed a SOC 2 Type II audit. The certification covers the controls that protect customer data in the platform, and it sits alongside our existing ISO 27001:2022 certification and our GDPR obligations.
Legal work carries some of the most sensitive material a business produces. Privileged advice, deal documents, evidence bundles. Firms evaluating a new platform are right to ask how that material is handled, and they should not have to take our word for it.
Why Type II is the one that matters
A Type I report checks that controls are designed correctly on a single day. Type II checks whether they actually operated over a sustained period. The auditor samples evidence across that window and reports on what they find, including anything that did not work as intended.
That distinction is the reason we went for Type II directly. A snapshot tells you what a company intended to build. A Type II report tells you what it ran.
What the audit covered
The review looked at how data is encrypted, where it lives, and who can reach it. All data at rest is encrypted with AES 256-bit encryption, and every connection is forced over HTTPS with TLS 1.2 or 1.3. Juristic runs on Scaleway in France, so infrastructure and data residency stay inside the EU.
On access, the auditor examined our SAML 2.0 single sign-on, configurable session and log-out restrictions, and role-based permissions covering property access, features, and account portfolios.
On resilience, the scope included daily and intraday backups, backup storage in locations geographically separate from our main infrastructure, and an architecture with no single point of failure. We target a recovery time objective under 4 hours and a recovery point objective under 1 hour.
On detection and response, the auditor reviewed our round-the-clock system monitoring, the alerting our on-call team works from, and the Incident Response Plan that sets out how security events are triaged and escalated.
A note on AI
No customer data is used to train models. That was true before the audit and it is part of what the audit examined. JuristIQ's context window is editable, so you can see exactly what the model was given for any output and change it.
What this means if you are evaluating Juristic
Most procurement and vendor due diligence processes ask for a SOC 2 report by name. If yours does, we can share ours under NDA. Ask your account contact or write to [email protected].
Certification is a checkpoint rather than a finish line. The controls above are reviewed on an ongoing basis by our security team, and we run penetration tests annually.
