Security

Built for the Most Privileged Testimony

Deposition video and transcripts are among the most sensitive material a firm handles. DepoFlow's answer is architectural: the safest copy of your testimony is the one that never leaves your machine.

Local-First Processing
Video, audio, and transcript text are processed on your machine and stay there by default.
No AI Training on Your Data
Your testimony is never used to train or fine-tune any model — ours or anyone else's.
Firm-Level Isolation
Every cloud record is scoped to your firm. Other tenants can't see that your matters even exist.
Encrypted in Transit
All traffic between your devices and DepoFlow runs over TLS. Cloud objects are stored on infrastructure with provider-managed encryption at rest.
Verified, Scoped Sign-In
Accounts require a verified email before access, and every session is scoped to your firm's data — nothing more.
Verified Integrations
Payment webhooks are cryptographically signature-checked before we act on them.

Architecture

Security by Subtraction

Most legal-tech vendors protect your data after collecting it. DepoFlow is designed so the most sensitive data is never collected in the first place.

Content Stays on Your Device

Transcription, sync, designation, and clip rendering run on your computer. After install, the desktop app doesn't need the internet to do its job — and your video never makes a round trip through our cloud.

Envelope-Only Account Sync

What syncs to your account is a thin billing envelope — witness name, matter, duration, job status. Not the transcript text. Not the media. Our servers can't leak what they were never sent.

Your Work Is Yours Alone

Job records are scoped to your firm and nothing you process is visible to anyone else. A cross-firm request for your records returns nothing — not even confirmation the record exists.

Controls

What We Do With the Data We Do Hold

Account records, billing envelopes, and anything you explicitly share are protected by controls built into the platform — not bolted on.

Your Data Is Never Training Data

DepoFlow runs pre-trained speech-recognition models locally to transcribe and align your audio. Your recordings, transcripts, and designations are never used to train or improve any AI model, and we don't sell or license your data to anyone.

Tenant Isolation, Enforced Everywhere

Every API route resolves records through firm-scoped guards. A request for another firm's matter doesn't get a permission error — it gets a 404, so even the existence of a matter is never disclosed across tenant boundaries.

Hardened Credentials

Passwords are bcrypt-hashed with a 12-character minimum policy. Sessions use httpOnly, HTTPS-only cookies with revocable server-side tokens, and sign-in, registration, and password-reset endpoints are rate limited to blunt credential-stuffing. Desktop API tokens are 256-bit, shown once, and stored only as SHA-256 hashes — a database leak alone can't replay them.

Single-Use Device Pairing

Linking the desktop app to your account uses a browser-approved device code. Codes are stored hashed and the issued token can be consumed exactly once, so an intercepted pairing can't be drained twice.

Encryption in Transit

All traffic between your devices and DepoFlow runs over TLS, and file downloads — like desktop installers — are served via short-lived presigned URLs rather than long-lived public links.

Signed Webhooks, Trusted Sources Only

Stripe billing events are verified against cryptographic signatures before we touch a credit balance. Payment state comes from the verified webhook — never from a client-side success page.

Compliance

Where We Stand — Honestly

Certification badges are earned from auditors, not copied from competitors. Here is exactly where DepoFlow stands today, in plain language.

GDPR & CCPA Privacy Principles

Built in by design

Data minimization is our architecture, not a policy afterthought: the most sensitive data never reaches us. Cloud records are deletable on request, storage lifecycle rules purge shared files automatically, and we never sell personal data.

SOC 2 (Trust Services Criteria)

Roadmap

We map our controls to the SOC 2 security criteria — access control, change management, monitoring — and a formal Type II audit is on our compliance roadmap as the platform grows. We will display the badge when an auditor issues the report, not before.

ISO 27001 / 42001 Practices

Aligned practices

Our engineering practices follow the spirit of these standards: centralized secret management, least-privilege access, documented AI model usage with no customer-data training. We do not hold these certifications today and won't claim them until an accredited body certifies us.

Cloud Infrastructure

Certified providers

The small cloud footprint we do run is hosted on infrastructure providers that maintain their own SOC 2 and ISO 27001 programs, with provider-managed encryption at rest for stored objects.

See also our Privacy Policy, Terms of Service, and the full subprocessor list.

Operations

How We Operate

Day-to-day engineering discipline that keeps the platform trustworthy as it grows.

Centralized Secret Management

All credentials and API keys flow through one audited configuration layer. Production deployments refuse to boot with development secrets or authentication disabled.

Retention You Control

Your content lives on your machine under your own retention rules. The account records we do hold are deletable on request, and deleting a matter cascades to its stored objects.

Scoped Cross-Origin Policy

The API only accepts credentialed browser requests from DepoFlow's own configured origins — never a wildcard.

Access Audit Logging

Sign-ins and every content access — transcript views, upload and download link issuance — are recorded in an append-only audit log with actor, resource, and origin.

Responsible Disclosure

Found something? Email security@depoflow.com and we'll respond promptly. We appreciate good-faith research and won't pursue it.

Security FAQ

Questions Firms Ask Us

What data does DepoFlow actually hold about my cases?

Your account details, firm and matter names, and per-job billing envelopes (witness name, duration, job status). Video, audio, and transcript text are processed and stored on your machine — we don't offer cloud processing, so there is no content-bearing copy on our servers to worry about.

Is my testimony used to train AI models?

No. Transcription uses pre-trained speech-recognition models that run locally against your audio; nothing you process is used to train, fine-tune, or improve any model, and we never sell or license your data.

Are you SOC 2 or ISO 27001 certified?

Not yet, and we won't pretend otherwise. Those are third-party audits we plan to pursue as the platform grows. Today our controls are mapped to the SOC 2 security criteria, and our biggest control is architectural: the most sensitive data never leaves your machine, so there's far less for an auditor — or an attacker — to worry about.

Who at my firm can see a transcript?

Access is scoped within your firm: firm admins, the person who created the job, and teammates explicitly granted access to the parent matter. Outside your firm, a transcript is invisible — a cross-firm request returns nothing, not even confirmation it exists.

Can I delete my data?

Yes. Deleting a job removes its cloud billing envelope, and closing your account purges the account and billing records we hold. Your video and transcript content already lives only on your machine, so deleting it there removes it entirely.

How do I report a security issue?

Email security@depoflow.com with details. We welcome good-faith security research and will respond promptly.

The Best Security Is Never Uploading

Keep privileged testimony on your machine and still get synced transcripts, designations, and trial-ready clips.