Security & confidentiality

Built to carry privileged work.

Barristers bring us questions that carry client confidences. This page sets out, plainly, how Barrister AI protects that work in production today.

The controls running in production todayCurrent as at August 2026

Privilege in plain EnglishPrivacy policy

Scroll to see what is in place

The core design

Your research is private. Your identity stays separate.

In routine operations, your work is handled under a pseudonymous account reference. Your name and email remain behind a separate, restricted identity gate.
Fig. 1

How routine operations see an account

Staff work against the pseudonymous reference on the right. The identity on the left — your name and email among the identifiers — stays behind a restricted, audit-logged path, and the security alerts our automated safeguards raise use the same pseudonymous reference.

In place today

Seven commitments we make now.

Each of these describes a control that is running in production today — not an aspiration.
  1. 01

    Identity separated from activity

    In routine operations, staff work against a stable pseudonymous reference. Your name, email, sign-in tokens, IP address, billing identifiers and professional-registration details are not shown to staff in ordinary work. Revealing them requires a specific, logged reason through a restricted, audit-logged path.

  2. 02

    Held briefly, or not at all

    Research goes to our AI model providers under contract. Standard research is held on the provider's systems for at most a provider-mandated 30-day window, then deleted. Brief and document analysis runs under zero-data-retention terms — nothing is stored once the response is returned — and a zero-data-retention research mode is available on every Pro plan. The zero-data-retention mode does not run on the provider's most capable model.

  3. 03

    No training on your work

    Nothing you research, upload or draft is used to train AI models — whether it is retained for 30 days or not retained at all. That is the standing arrangement with our model providers, and it applies to every request, on every tier.

  4. 04

    Encrypted in transit and at rest

    Traffic between your browser and Barrister AI is encrypted in transit with TLS. Data is encrypted at rest at the infrastructure level, which guards against theft of physical media or backups.

  5. 05

    Two-factor authentication

    Add a rotating six-digit authenticator code on top of your password — it works with any authenticator app and takes under a minute to set up in Settings. Opt-in, with single-use backup codes for when your phone isn't to hand. The authenticator secret is sealed under its own encryption key, so a database read alone cannot produce your codes.

  6. 06

    Security guarding, identity-free

    Automated safeguards watch for abuse and probing across the product. The operational alerts they generate identify you only by a pseudonymous reference — never your name or your email.

  7. 07

    Account deletion

    A deletion request revokes access and billing immediately. After a short review window, a purge removes your identity and the data attached to it.

Security & confidentiality

Confidentiality is an engineering practice, not a slogan.

This page describes the controls as they run in production today, in plain terms — and it will keep pace as they strengthen.
Security & confidentiality — Barrister AI