Skip to main content

Built for live client work.

Matter Desk handles real client matters. That requires clear information on storage, AI processing, privacy, audit trails, and human oversight. These are our current controls and the limits of what has been verified.

Our commitments.

Australian-region customer storage

Primary customer databases and matter-document storage use Australian regions. This does not establish Australian storage or processing for every operational record or service provider. AI-assisted features send relevant matter content to a third-party AI provider; processing and storage may occur outside Australia. Matter Desk does not claim provider zero-retention or no-training until the applicable account controls and written terms are independently verified. Assessment of overseas providers' locations, terms and controls, including the steps required under APP 8 where applicable, is not yet complete.

Human review policy

Substantive AI output requires lawyer review before client-facing use. Research flows link retrieved citations to source records and mark unmatched authorities for verification. The practitioner remains responsible for the final work product.

Audit trail

Currently instrumented matter-linked AI, document, workflow, and partner conflict-search events create product records with the available user, matter, timestamp, and output references. This is not presented as a complete regulatory record. Firms should confirm required retention and export settings during onboarding.

Model-training policy

Matter Desk does not use client matter data to train its own models. We do not claim provider zero retention or no training until the applicable account controls and written provider terms are independently verified.

Privacy Act handling

The Privacy Act 1988 (Cth) and Australian Privacy Principles set requirements where applicable. This page is not a legal compliance certification. Our current disclosures and verification limits are in our Privacy Policy.

Deadline safety

Calculated deadlines are deterministic, versioned, and require explicit human confirmation before activation. No deadline auto-activates. Every calculation cites its statutory source.

Document and data handling.

Private by default

Matter documents are private. Access requires signed URLs that expire. Documents are never made public.

Encrypted in transit and at rest

Connections use HTTPS. Customer databases and matter-document storage are encrypted at rest in Australian regions.

Deletion requests

Contact us to request deletion and confirm the applicable arrangements. A complete retention and deletion schedule, including backups and external services, has not yet been verified.

Cancellation and export

Confirm cancellation, export and retention arrangements for your workspace before relying on a deadline.

Security architecture.

Row-level security

Supported firm and matter data paths combine server-side access checks with database row-level security.

CSRF protection

Authenticated mutating actions are protected by double-submit CSRF tokens.

Rate limiting

API endpoints are rate-limited to prevent abuse. Distributed rate limiting backed by the database.

Security headers

Browser-facing application responses use configured HSTS, X-Frame-Options, Content-Security-Policy, Referrer-Policy, and Permissions-Policy controls.

Input validation

Supported API operations validate and normalise request fields at the server boundary before database operations.

Signed document URLs

Matter documents are served via time-limited signed URLs. No public bucket access.

Data Processing Agreement.

Data-handling responsibilities depend on applicable law and the arrangements agreed with your firm. This page does not establish that every firm has the same Privacy Act obligations or that an agreement has been executed.

Your firm decides what client personal information enters Matter Desk and remains accountable to its clients and to its professional obligations for that information. Assessment of overseas-provider locations, account controls and written terms is not yet complete. Confirm available data-handling terms and provider details before onboarding. Contact legal@matterdesk.ai.

Subprocessors

Application hosting

Australia

Configured primary application processing; not a location assurance for every delivery service or log.

Primary database and storage

Australia

Primary customer databases and matter-document storage.

AI processing

Outside Australia

AI-assisted research, analysis and drafting using relevant matter context; account-specific controls remain to be verified.

Payment and email services may involve overseas processing or storage. Their logs are not covered by the Australian primary-storage statement. Product analytics and error-tracking services are not currently configured. This list is not a verified, complete provider schedule.

Retention

Confirm the retention and deletion arrangements relevant to your workspace. A complete schedule has not yet been verified.

Deletion requests

Contact privacy@matterdesk.ai to request deletion and confirm applicable legal and operational limits.

Breach notification

Where the Notifiable Data Breaches scheme applies, notification is required as soon as practicable once there are reasonable grounds to believe an eligible data breach occurred, subject to applicable exceptions.

Certification status.

Matter Desk holds no external security certification today, and we do not claim independently verified alignment with a security standard. Contact security@matterdesk.ai to discuss the evidence available for your firm's security review.

Need to complete your firm's security review?

Book a walkthrough to discuss available data-handling terms and provider details.