🔒 Security · Privacy · Verification

Built for lawyers who can't afford to be wrong

You're handing an AI your clients' medical records. Two questions decide whether you can trust it: Is my data safe? and Can I prove every finding? Here are the honest answers — no jargon, no fine print.

HIPAA BAA signed with every customer PHI encrypted (AES-256) Never used to train AI models Every finding cites its Bates page
The two things that matter

Verifiable. Private. Secure.

Everything below is something we actually do — not a roadmap. Where we haven't earned a claim yet, we say so.

📎

Verifiable by design

Every clinical finding, deviation, and quote carries a citation to the exact Bates page of the record it came from. If the AI can't locate a claim on a tagged page, it flags it [UNVERIFIED] instead of presenting it as fact. You check the source in one click — you never take our word for it.

🛡️

Private & compliant

We sign a Business Associate Agreement with every customer before any real PHI is uploaded. Records are encrypted at rest and in transit, processed on infrastructure covered by signed BAAs with our cloud and AI providers, and never used to train any AI model.

🔐

Secure & isolated

Your cases are walled off from every other firm's — each account only ever sees its own records, enforced server-side on every request. We run adversarial security reviews of the live product and fix what they find. Access follows least-privilege.

A citation behind every sentence

Independent testing has found general-purpose AI tools invent or misattribute a meaningful share of medical-record citations. Our pipeline is built specifically to make that impossible to hide.

1

Every page is tagged

On upload, each page of the record is stamped with a page marker (and its Bates number when present) that travels with the text through analysis.

2

Every claim is pinned

The AI must attach a page pin-cite to each event, standard-of-care deviation, and verbatim quote — in a format you can click straight to the source.

Troponin elevated to 2.4 (p.7, Bates ABC0001234).
3

Unlocatable = flagged

If a statement can't be tied to a tagged page, it's marked so you see it. Fabricated page numbers can't validate against the real record.

Patient reported dizziness pre-op [UNVERIFIED]
4

Literature resolved live

PubMed citations are resolved against NCBI's E-utilities at generation time, so a PMID points to a real article — not an invented one. Still confirm each before you rely on it.

Data & compliance

What happens to your clients' records

Straight answers to the questions a records custodian — or opposing counsel — would ask.

Verifying AI output isn't optional anymore — it's your duty

Under ABA Formal Opinion 512, a lawyer's duty of competence now extends to the AI tools they use: you are responsible for the accuracy of AI-generated work, including checking that its citations are real. A tool that makes verification effortless isn't a nice-to-have — it's how you meet the standard.

"Because a citation looks right doesn't make it real. The only defensible workflow is one where every finding points back to the page it came from — so you can confirm it in seconds, not reconstruct it under deadline."

That's the entire design premise of MedLegal AI: not "trust the AI," but "here's the page — check it yourself."

Straight answers

The questions attorneys actually ask

Do you train AI on my clients' medical records?
No. Records are processed through Anthropic's API, which does not use API-submitted data to train models, and we never repurpose, sell, or share your data. Your records are used to do the one thing you uploaded them for — analyzing your case — and nothing else.
Is there a Business Associate Agreement?
Yes. We sign a BAA with every customer, and PHI upload is gated until it's signed. You can review the full agreement first at /baa. Our upstream providers (AWS, Anthropic) are covered by their own signed BAAs, so PHI is covered across the whole chain.
How do I know a citation isn't made up?
Because you click it and land on the exact page of the record. Every finding carries a page pin-cite (with Bates number when available); anything the AI can't tie to a tagged page is flagged [UNVERIFIED] rather than dressed up as sourced. Fabricated page numbers can't validate against the real record's page count. Want to pressure-test any AI's output — even a competitor's? Our free AI Citation Auditor flags every uncited claim right in your browser, and the live cite demo shows ours pinning to a real page.
Are you SOC 2 certified?
Not yet — and we won't claim a certification we don't hold. What we do have today: signed BAAs, AES-256 encryption, server-enforced tenant isolation, least-privilege access, and recurring adversarial security reviews of the live product. Formal certification is on our roadmap; if it's a procurement requirement for your firm, tell us and we'll talk timelines.
Can other firms see my cases?
No. Every record, analysis, and export is owned by your account and access is checked on the server for each request — not merely hidden in the UI. Cross-tenant isolation is one of the specific things our security reviews are designed to break, and it holds.
What if the AI gets something wrong?
Then you catch it — that's the point of pin-cites. The product is built so you verify against the source instead of trusting a black box. You remain the lawyer of record; MedLegal AI is a tool that makes checking fast, not a replacement for your judgment.

See it on a real record

Start free on a synthetic demo case — no PHI, no BAA needed to look around. Watch it build a Bates-cited chronology, then run it on your own file.