Security
No model touches your deal.
The document engine is deterministic. No language model reads your data, drafts your documents, or decides your terms. Every figure is computed in code from your inputs, and every clause is the verbatim text of the authority it cites — so there is no step where a number or a citation could be fabricated, and no path that carries your deal into a model. Your data is processed for your organization and nothing else.
No fabricated number or citation is possible
The drafting risk your counsel worries about is closed at the architecture itself. Figures are computed in code from your deal terms, statutory clauses are reproduced word for word from the US authority they cite, and every other clause is drawn from a frozen, source-verified library. No generative step sits anywhere a number or a citation could be invented.
Your data reaches no model, and trains none
Deal terms and generated documents are processed for your organization alone. No language model or AI service sits in the path that produces your binder — nothing is used to train, fine-tune, or improve any model, and nothing is sold or shared beyond the named sub-processors that operate the platform.
Sealed to your organization, checked at every endpoint
Each organization's data is isolated and reachable only by the members you authorize, under four roles — Owner, Admin, Member, and Viewer. Permission is verified on every API request, and authentication runs through Clerk with single sign-on and multi-factor support.
An append-only record that holds under audit
Every action on your deals and documents is written to an append-only log with its originating IP, and it survives deletion — the record of a deleted deal is not erased with it. Each generated document carries a SHA-256 checksum set at creation, so any later alteration is detected on verification.
Encrypted in transit and at rest, resident in the US
Every connection is TLS 1.2+ with HSTS; documents are sealed with AES-256 at rest and the database is encrypted on US-based infrastructure with no offshore processing. Share-link passwords are hashed with bcrypt. Deletion is real — files and database records are removed in full, and retained audit metadata carries no document content.
Built for your diligence
Signed webhooks, four-tier rate limiting, server-side input validation, and a full set of HTTP security headers are in place today. We are preparing for SOC 2 Type II — our controls are built to that standard, and no report has been issued yet. Your security team is welcome to examine the data-handling model and request a full DPA.
Data handling
Stated plainly, in terms a reviewer can verify
Plain language your security team can verify, with the acronyms and certifications detailed below. Here is precisely what becomes of a document and a figure once it enters OpenShut.
- Where your data resides
- Documents are stored with AES-256 encryption and the database is encrypted at rest, on US-based infrastructure, with no offshore processing.
- Who can reach it
- Only authenticated members of your organization, under role-based access checked at every endpoint. Support gains access only with explicit, time-boxed, logged permission you grant.
- What never happens to it
- No language model or AI service reads your data or drafts your documents. Nothing is used to train or improve any model, and nothing is shared beyond the named sub-processors that run the platform.
- What deletion means
- Delete means delete. Documents and database records are hard-deleted; the append-only audit record that a deal existed is retained and carries no document content.
Compliance posture
Stated candidly, current as of today
- TLS 1.2+ in transit with HSTS; AES-256 at rest
- US-based infrastructure with no offshore processing
- Per-organization isolation, role-checked at every endpoint
- Append-only audit trail with IP, retained through deletion
- SHA-256 document integrity checksums; signed webhooks
- No language model reads your data or drafts your documents
- Four-tier rate limiting and server-side input validation
- Data export and right-to-erasure; no third-party analytics
- Preparing for SOC 2 Type II; controls built to that standard, no report issued yet
We display no certification we do not yet hold. When a control remains in progress, we say so.
Put it in front of your security team.
Request the data-handling summary and DPA, or generate one document at no cost and read the audit trail behind it for yourself.