Security
Our commitment to security
Legal professionals are entrusted with some of the most sensitive information that exists — client strategy, privileged communications, confidential case facts. Any tool that enters that workflow carries a corresponding responsibility. CiteClerk is built around a simple principle: we should hold as little of your data as possible, for as short a time as possible, in as few places as possible.
CiteClerk is built for legal professionals who handle confidential client matters. Our security architecture reflects that reality.
1. Document handling
Documents you upload to Doc Check are not stored. They are not written to our database, not added to your history, not logged, and not retained after processing completes. CiteClerk cannot produce, subpoena, or disclose documents it does not store.
Processing a document is not a purely local operation, and we would rather say so than imply otherwise. To find the citations in a document we send its text to an AI provider; to confirm that authorities exist we send citation strings to CourtListener. If you choose the optional high-fidelity view of a Word file, the file is sent to our own conversion service and written to a temporary working directory there for the length of the conversion, then deleted. Section 2.5 and Section 4 of the Privacy Policy name every recipient and state exactly what each one receives.
CiteClerk Draft is a different product with a different posture: it is a drafting workspace and it stores your matter, your sources and your brief. See Section 2.5 of the Privacy Policy.
2. Authentication
All authentication is handled by Clerk, a SOC 2 Type II certified identity provider. CiteClerk does not store passwords. Sessions use short-lived, signed JWTs that expire automatically.
3. Payment processing
All payment processing is handled by Stripe. CiteClerk never receives, transmits, or stores credit card numbers or bank account details. We receive only a payment confirmation and subscription status.
4. Data minimization
CiteClerk collects only what is necessary to provide the service: your email address, citation query history (for the History feature), and monthly usage counts. Citation queries — the formatted citation results, not your documents or any client information — are cached in Redis for 7 days to improve response times, then automatically deleted.
5. Infrastructure
CiteClerk runs on Fly.io (hosting), Neon (database), Redis (caching), and Amazon Web Services (object storage and OCR for Draft exhibits). All data is transmitted over HTTPS. The full subprocessor list, with what each one receives, is in Section 4 of the Privacy Policy.
6. AI and training
Your content is never used to train AI models — not ours, and not our providers'. We do not train models on your documents, drafts, or queries. The three AI providers we use — Google, Anthropic and OpenAI — each receive our content through paid commercial API tiers, and each of those tiers is governed by terms under which submitted data is not used to train or improve the provider's models. CiteClerk's Google (Gemini) usage is on Google's paid tier specifically; the free Gemini tier carries different data-use terms and we do not use it.
Every recipient of your content is now on that footing, and one used not to be. Until August 2026, Doc Check included a spelling and grammar check that sent your document's prose — up to roughly 228,000 characters per check, with citation spans masked but your argument, your facts and any party or client names outside a citation transmitted as written — to LanguageTool's free, public API endpoint, against which we held no account, no API key and no data-processing agreement. It was the only place in the product where a customer's document left our control with no agreement behind it. We removed the feature rather than keep taking that risk. Nothing is sent to LanguageTool, and it is no longer named in the subprocessor list in Section 4 of the Privacy Policy.
Content is sent to those providers in order to process it, and it is not anonymised. Identifying a document's citations means reading the document, so the text of a document you check — including party names, facts, and client information in it — is sent to an AI provider as written. The same is true of the sources and brief text in Draft. We do not strip names, redact, or pseudonymise before sending, and you should assume that anything you put into CiteClerk is read by the providers named in the Privacy Policy.
An earlier version of this page stated that no data is transmitted to AI model providers in a form that identifies you or your clients. That was not correct and has been replaced with the statement above.
7. Responsible disclosure
If you discover a security vulnerability in CiteClerk, please report it to security@citeclerk.com. We will acknowledge your report within 48 hours and work to address confirmed vulnerabilities promptly. We ask that you give us reasonable time to respond before any public disclosure.
8. Independent security review
CiteClerk has not yet undergone an independent penetration test. We intend to commission an independent security review post-launch and will update this page when that review is complete.
Questions about security may be directed to: security@citeclerk.com
CiteClerk LLC | https://citeclerk.com | Effective August 15, 2026