Trust & Security Policy
Public commitments · How we handle your data · How to verify it
Rolling Sentiment Terminal is an AI-assisted Texas legal document terminal. This page documents the security
posture of the public site (free, pro se) and the FIRMS private cloud product (paid). It uses three
transparency states: active (deployed today), in progress (committed
timeline), and paid‑tier (available on
Dedicated Private Cloud). Anything not listed is not yet a commitment.
ACTIVE — deployed today
IN PROGRESS — committed timeline
PAID TIER — Dedicated Private Cloud
1 Encryption
-
● ACTIVE
TLS 1.3 in transit — every connection to
rollingsentiment.iois HTTPS via Sectigo PositiveSSL. HSTS enabled. Mixed content blocked. - ● ACTIVE AES‑256 at rest — server disks encrypted at the storage layer. Document and prompt logs reside on encrypted volumes only.
- ◆ PAID TIER Per‑tenant KMS‑wrapped envelope encryption — each firm gets a customer‑managed encryption key (CMK) so the operator cannot decrypt firm data without the active CMK.
- ◐ IN PROGRESS Internal mTLS for service‑to‑service traffic when the architecture moves to a multi‑service deployment.
2 Access Control & Authentication
- ● ACTIVE Public site is gated by Terms‑of‑Use — every visitor must accept TOS before any AI generation. Acknowledgment is logged with timestamp + IP.
-
● ACTIVE
Per‑IP rate limiting — public AI endpoint capped at
30/hr/IPby default. Configurable. - ◐ IN PROGRESS MFA mandatory for FIRMS terminal — TOTP via authenticator app or hardware security key (WebAuthn). Target: Q3 2026.
- ◆ PAID TIER SSO via SAML / OIDC — firm uses its own identity provider (Okta, Azure AD, Google Workspace).
- ◆ PAID TIER IP allowlist — restrict access to firm office IPs / VPN ranges.
- ◆ PAID TIER Role‑based access — firm admin, attorney, paralegal, read‑only. Assigned per seat.
- ◆ PAID TIER Managing Partner Console — supervisory dashboard for partners with view of every matter, draft status, citation alerts, and pre‑send approval gating. Designed to satisfy Tex. Disc. R. 5.01 (responsibilities of a partner / supervisory lawyer).
3 Audit Logging
- ● ACTIVE Prompt + visit logging — every page visit, AI generation, and revision is logged with timestamp, IP, user‑agent, document slug, and full prompt content (truncated at 2,000 chars). Stored above the web root, never exposed publicly.
- ◐ IN PROGRESS Append‑only audit log — a write‑once log writer with cryptographic chaining (each entry signed with a hash of the previous entry) so log tampering is detectable. Required for ABA Model Rule 1.6 / Tex. Disc. R. 1.05 attestations.
- ◆ PAID TIER Customer‑exportable audit — firm admin can download CSV/JSON of all access events for their tenant.
-
● ACTIVE
Geo‑IP enrichment — log entries enriched with city/region/country and ISP for anomaly review. Lookup via
ip‑api.com; cached.
4 Data Handling & AI Inference
- ● ACTIVE No‑train contract with AI provider — prompts and uploads are never used to train any external model under our current API tier.
- ● ACTIVE Prompt content lives in your tenant only — never shared cross‑firm.
- ◆ PAID TIER House‑style inference / RAG — your past pleadings, briefs, and templates indexed in a per‑firm vector corpus. The model retrieves from your work; no cross‑tenant retrieval is possible.
- ◆ PAID TIER PII redaction (optional) — automated redaction of names, SSNs, account numbers before any prompt leaves your VPC, configurable per matter.
- ● ACTIVE Document deletion — uploaded documents (when implemented) are deleted from compute nodes after processing. Logs retain only metadata (filename, size, timestamp), never content.
5 Compliance & Attestation
- ● ACTIVE ABA Model Rule 1.6 (confidentiality) — operating posture aligned with the Rule's baseline: data segregation, access logging, prompt no‑training, prompt‑to‑client linkage avoided.
- ● ACTIVE Tex. Disciplinary Rule 1.05 — same baseline applied to Texas‑licensed attorneys' use of the FIRMS terminal. Public site is non‑representational and includes a clear no‑attorney‑client‑relationship disclaimer.
- ◐ IN PROGRESS SOC 2 Type II — engagement scheduled with auditor. Target Type I letter Q4 2026, Type II report 6 months later.
- ◆ PAID TIER HIPAA‑eligible architecture — Business Associate Agreement (BAA) available on request for firms handling protected health information (e.g., personal‑injury or family‑law matters with medical records).
- ◆ PAID TIER Data Processing Agreement (DPA) — standard EU‑style DPA available, signable before onboarding. Subprocessor list maintained and notified on change.
6 Backups & Disaster Recovery
- ● ACTIVE Daily snapshots of all logs and configuration, retained for 30 days.
- ◐ IN PROGRESS 3‑2‑1 backup (3 copies, 2 media, 1 off‑site) with KMS‑wrapped encryption and quarterly restore tests. Target Q3 2026.
- ◐ IN PROGRESS Documented RTO/RPO — Recovery Time Objective 4 hours, Recovery Point Objective 24 hours for paid tiers.
7 Incident Response
- ● ACTIVE Monitoring — auth events, rate‑limit hits, and unusual access patterns reviewed via the admin log.
- ◐ IN PROGRESS 72‑hour breach notification SLA — affected customers notified within 72 hours of confirmed compromise affecting their data.
- ◐ IN PROGRESS Post‑incident report within 30 days — root cause, scope, remediation, and customer‑facing summary.
- ● ACTIVE Vulnerability reports accepted at rollingsentiment@gmail.com. We acknowledge within 5 business days.
8 Subprocessors
The following services may process customer data on behalf of Rolling Sentiment Terminal. Customers on the Dedicated Private Cloud tier are notified at least 30 days before any subprocessor change.
| Provider | Purpose | Region | Status |
|---|---|---|---|
| Namecheap (Stellar Hosting) | Web hosting, DNS, SSL | US | Current |
| VOUX CORE (AI inference partner) | AI inference for document drafting and Q&A | US (multi‑region) | Current · no‑train contract |
| ip‑api.com | Geo‑IP enrichment for security logs | US/EU | Current · IP only, no PII |
| Texas Legislature Online | Statute text source (read‑only public archive) | US | Current · public data, no customer data sent |
| CourtListener | Court opinion feed (read‑only) | US | Optional · no customer data sent |
| Texas county clerks (254) · Odyssey · PACER · 5th Cir. | Public‑record case scrape during firm onboarding (per‑firm, gated) | US | Paid tier · only public‑record content is pulled · written consent required at onboarding |
| AWS / GCP / Azure | Hosting on Dedicated Private Cloud tier | Customer‑chosen region | Per‑contract |
9 Customer Obligations
- ● USER Use strong, unique passwords and enable MFA where available. Never share credentials.
- ● USER Report suspicious activity promptly to rollingsentiment@gmail.com.
- ● USER Verify generated text against the official Texas statutes / rules / case law before filing or signing. AI output is a draft, not legal advice.
- ● USER Keep your devices secure — endpoint security is your responsibility (full‑disk encryption, screen lock, current OS).
10 Contact
| Inquiry type | Expected response | |
|---|---|---|
| Security & vulnerability reports | rollingsentiment@gmail.com | 5 business days |
| FIRMS access / sales | rollingsentiment@gmail.com | 3 business days |
| Data subject requests (GDPR/CCPA) | rollingsentiment@gmail.com | 30 days |
| Press / general | rollingsentiment@gmail.com | — |
What this page is and isn't. This is a public commitment, not a legal contract.
Paid customers receive a signed Master Services Agreement, Data Processing Agreement, and (where
applicable) BAA that codify these commitments and expand on them. If anything here conflicts with
your signed contract, the signed contract governs. If you need a custom security questionnaire
answered or a specific attestation letter, email
rollingsentiment@gmail.com.