Skip to content
revyn

Security & data privacy

Custody is the product.

For most software, security is a feature list. For legal software it is the entire proposition — which is why Brevyn's architecture starts from the assumption that your data must never leave your control.

Principles

What the architecture guarantees.

Local-first deployment

Brevyn is designed to be installed inside your environment — on your servers or your own private cloud tenancy — rather than accessed as shared multi-tenant software.

Air-gap capable

The system is being built so it can run with no outbound internet connectivity at all, for environments where that is a hard requirement.

No training on your data

Your matters, documents and drafts are never used to train models, and are never pooled with any other organisation's material.

Encryption in transit and at rest

Data is encrypted on disk and over the wire, with key material held by you rather than by us.

Role-based access control

Access follows the firm's own structure — matter teams, ethical walls and confidentiality rings — so people see only what they should.

Complete audit logging

Every query, generation and record change is logged and attributable, giving you a defensible account of how the system was used.

Where we actually are today

Brevyn is a pre-launch company and our first product is still in development. The principles above describe the architecture we are building. We do not yet hold third-party security certifications, and we will say so plainly here until we do.

Questions we get

Straight answers.

Where does our data actually live?
On infrastructure you control — your own servers, or your own private cloud tenancy. Brevyn is installed into that environment rather than being a shared service you upload material to.
Do you ever see our documents?
No. Because the system runs inside your environment, your matters and documents are never transmitted to us. We have no copy of them and no route to access them.
Is our data used to train models?
No. Your material is never used to train models and is never pooled with any other organisation's data.
Can it run without internet access?
That is an explicit design goal. We are building Brevyn so it can operate fully air-gapped for environments where outbound connectivity is prohibited.
Who holds the encryption keys?
You do. Key material stays within your environment rather than being escrowed with us.
Do you hold security certifications?
Not yet. We are a pre-launch company and we will not claim certifications we do not have. When we complete formal audits, we will publish them here.

Want the technical detail behind any of this?

We are happy to walk through the architecture with your IT or compliance team. Ask us anything.