Security program overview covering tenant isolation, authentication, authorization, matter-level security, encryption, logging, monitoring, incident response, vendor management, and AI provider governance.
# Assist Mi Legal Security Addendum
Version 1.0
Effective Date: ___________
This Security Addendum describes the administrative, technical,
and organizational safeguards used by Assist Mi Legal to support
the security, confidentiality, integrity, and availability of customer
information.
This Security Addendum supplements the Terms of Service, Data
Processing Addendum, and other applicable agreements.
## 1. Purpose
Assist Mi Legal is committed to maintaining a security program
designed to protect customer information from unauthorized access,
disclosure, alteration, destruction, or misuse.
Security controls may evolve over time as threats, technologies, and
business requirements change.
## 2. Shared Responsibility Model
Security is a shared responsibility between Assist Mi Legal and
Customer.
Assist Mi Legal Responsibilities
Assist Mi Legal is responsible for:
Platform security
Infrastructure management
Application security controls
Tenant isolation
Authentication controls
Monitoring and logging
Vendor management
Incident response
Customer Responsibilities
Customer is responsible for:
User management
Permission management
Device security
Password management
User training
Data governance
Workflow configuration
Review processes
## 3. Hosting Environment
Assist Mi Legal utilizes cloud infrastructure providers to operate the
Services.
Infrastructure may include:
Cloud-hosted compute resources
Managed databases
Managed storage services
Networking services
Monitoring services
Infrastructure providers are selected based on security, reliability,
and operational requirements.
## 4. Data Segregation
The platform is designed to logically segregate customer
information between tenants.
Controls are intended to prevent unauthorized access between:
Organizations
Workspaces
Matters
Users
Tenant isolation controls are regularly reviewed as part of platform
development and testing.
## 5. Authentication
Access to the platform may be protected through:
Username and password authentication
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
Identity provider integrations
Assist Mi Legal strongly recommends MFA for all users.
Enterprise customers may require MFA enforcement.
## 6. Authorization and Access Control
The platform utilizes role-based access controls designed to restrict
access based on business need.
Examples include:
Administrator roles
Attorney roles
Staff roles
Read-only roles
Matter-specific permissions
Access should be granted according to the principle of least
privilege.
## 7. Matter-Level Security
Assist Mi Legal supports controls intended to limit access to
information based on matter assignment and authorization.
Organizations are responsible for configuring permissions
appropriate to their operational requirements.
## 8. Encryption
Information may be protected using industry-standard encryption
technologies.
Data in Transit
Communications between users and the platform are protected
using encrypted transport protocols.
Data at Rest
Stored information may be protected through encryption
technologies provided by infrastructure providers and platform
services.
## 9. Audit Logging
Assist Mi Legal maintains audit records relating to platform activity.
Examples may include:
Authentication events
User actions
Administrative actions
Workflow execution
Integration activity
Assistant activity
Audit records support:
Security monitoring
Compliance investigations
Troubleshooting
Operational review
## 10. Monitoring and Detection
Assist Mi Legal maintains monitoring capabilities designed to
identify:
Service disruptions
Operational issues
Security anomalies
Unauthorized access attempts
Infrastructure concerns
Monitoring technologies may evolve over time.
## 11. Vulnerability Management
Assist Mi Legal employs practices intended to identify and address
security weaknesses.
Examples may include:
Security reviews
Dependency monitoring
Patch management
Vulnerability remediation
Code review processes
Remediation priorities may vary based on risk and operational
considerations.
## 12. Application Security
Security considerations are incorporated throughout the software
development lifecycle.
Practices may include:
Code review
Automated testing
Dependency analysis
Security-focused development practices
Release validation procedures
## 13. Backups and Recovery
Assist Mi Legal maintains backup and recovery procedures
designed to support service restoration.
Backup frequency, retention, and recovery procedures may vary
based on operational requirements.
No backup system guarantees prevention of all data loss scenarios.
## 14. Business Continuity
Assist Mi Legal maintains operational procedures intended to
support service continuity during adverse events.
Business continuity plans may be updated periodically.
## 15. Incident Response
Assist Mi Legal maintains procedures for responding to security
incidents.
Response activities may include:
Investigation
Containment
Remediation
Recovery
Customer notification when appropriate
## 16. Security Incident Notification
When Assist Mi Legal becomes aware of a confirmed security
incident affecting customer information, notification will be provided
without unreasonable delay and in accordance with applicable
agreements and legal obligations.
Notifications may include:
Description of the incident
Known impact
Mitigation efforts
Recommended actions
## 17. Personnel Security
Personnel with access to customer information are granted access
based on business need.
Assist Mi Legal may utilize:
Confidentiality obligations
Security awareness training
Access management procedures
to support security objectives.
## 18. Vendor Management
Assist Mi Legal may utilize third-party providers supporting:
Hosting
Authentication
Email delivery
Monitoring
Artificial intelligence functionality
Infrastructure operations
Providers are selected and managed according to operational and
security considerations.
## 19. AI Provider Governance
Assist Mi Legal may utilize third-party AI providers to deliver AIpowered functionality.
Assist Mi Legal seeks to:
Limit data sharing to what is necessary
Evaluate provider capabilities
Monitor provider changes
Review provider security practices
AI-generated output remains subject to human review requirements.
## 20. Connected Applications
The platform may integrate with external services.
Customers remain responsible for:
Reviewing permissions
Managing connected accounts
Configuring access appropriately
Security of third-party platforms remains the responsibility of those
providers.
## 21. Security Requests
Enterprise customers may request reasonable security information.
Assist Mi Legal may satisfy such requests through:
Security documentation
Questionnaires
Compliance materials
Architecture reviews
Vendor assessments
## 22. Security Program Evolution
Security controls may be modified as technology, threats,
regulations, and platform capabilities evolve.
Assist Mi Legal reserves the right to improve or replace controls
while maintaining appropriate security objectives.
## 23. Contact Information
Security inquiries may be directed to:
[email protected]
or other designated security contact channels.
## 24. Acknowledgment
This Security Addendum describes Assist Mi Legal's security
practices and forms part of the applicable customer agreement
where incorporated by reference.