Trust & security

How we handle your contract data

This page is maintained by TermHarbor, LLC and describes the controls currently in place for TermHarbor.

Certifications and audits

SOC 2 Type II

Completed

Audit completed March 2026.

ISO 27001

In progress

In progress. Not yet certified.

Certification status is stated as of the dates above. ISO 27001 work is underway and TermHarbor is not yet certified against that standard.

Controls in place

Hosting
AWS us-east-1.
Encryption
AES-256 at rest, TLS 1.3 in transit.
Access control
Role-based access control, SAML 2.0 SSO, and MFA required for Admin roles.
Audit logs
Immutable audit logs retained for 24 months, exportable as JSON or CSV.
AI processing
GPT-4o via Azure OpenAI Enterprise. Customer data is not used to train global base models.
Data processing
A DPA is available for GDPR and CCPA jurisdictions.

Shared responsibility

We are responsible for

  • Platform hosting, encryption, and infrastructure security
  • Audit logging, retention, and export tooling
  • AI processing boundaries and subprocessor management

Your workspace is responsible for

  • Role assignment, SSO configuration, and offboarding
  • What contract content is uploaded and who may see it
  • Human review and approval of every AI finding before action

Review quality, January 2024 – June 2026

Source-citation accuracy measured at 98.2% from a random sample audit of 500 citations. Reviewers edited or rejected 12.4% of AI findings before approval — human review is the control, not a formality.

Security questions or reports

Report suspected vulnerabilities to security@termharbor.com. Privacy and DPA requests go to privacy@termharbor.com.

Contact us

TermHarbor provides software, not legal advice. See our Privacy Policy and Terms for the governing commitments.