Safety and security
Your data is hosted in the European Union, encrypted in transit and at rest, and each firm's data is kept separate from every other firm's. Firms on the Switzerland region have their matter documents and the content Andri derives from them hosted in Switzerland.
Data protection
We do not use your data to train AI models. Client prompts, documents, and case files stay inside your firm's environment, and we keep data no longer than we need it.
Decide with your own compliance officer which data to upload. Andri applies the same encryption and access controls to everything you store.
Access control and logging
Multi-factor authentication (MFA) - Available to every user, and required for sensitive account actions
Role-based access - Admins, members and support-role colleagues each see only what their role allows
Audit logs - Activity is recorded in an audit log that company administrators can review in Andri
Compliance
Andri is designed to meet GDPR and the NOvA guidance for legal professionals, and we are working toward ISO 27001 certification.
We notify affected customers without undue delay, in line with GDPR, if a breach is likely to pose a high risk to them.
Data retention after cancellation
We keep your firm's data for 20 days after cancellation so you can reactivate, after which it is scheduled for deletion. See How do I cancel my subscription? for what happens to access and billing.
Documentation and agreements
Available on request:
Data Processing Agreement (DPA) - Standard verwerkersovereenkomst conforming to AVG/GDPR
Security documentation - Detailed infrastructure and security practices, shared under NDA
To request either document, or to report a security issue you have found, email [email protected]. We assess every report based on impact and severity.
For complete details, visit our Security page and Privacy Policy.