Trust & security
How we handle your contract data
This page is maintained by TermHarbor, LLC and describes the controls currently in place for TermHarbor.
Certifications and audits
SOC 2 Type II
CompletedAudit completed March 2026.
ISO 27001
In progressIn progress. Not yet certified.
Certification status is stated as of the dates above. ISO 27001 work is underway and TermHarbor is not yet certified against that standard.
Controls in place
- Hosting
- AWS us-east-1.
- Encryption
- AES-256 at rest, TLS 1.3 in transit.
- Access control
- Role-based access control, SAML 2.0 SSO, and MFA required for Admin roles.
- Audit logs
- Immutable audit logs retained for 24 months, exportable as JSON or CSV.
- AI processing
- GPT-4o via Azure OpenAI Enterprise. Customer data is not used to train global base models.
- Data processing
- A DPA is available for GDPR and CCPA jurisdictions.
Shared responsibility
We are responsible for
- Platform hosting, encryption, and infrastructure security
- Audit logging, retention, and export tooling
- AI processing boundaries and subprocessor management
Your workspace is responsible for
- Role assignment, SSO configuration, and offboarding
- What contract content is uploaded and who may see it
- Human review and approval of every AI finding before action
Review quality, January 2024 – June 2026
Source-citation accuracy measured at 98.2% from a random sample audit of 500 citations. Reviewers edited or rejected 12.4% of AI findings before approval — human review is the control, not a formality.
Security questions or reports
Report suspected vulnerabilities to security@termharbor.com. Privacy and DPA requests go to privacy@termharbor.com.
TermHarbor provides software, not legal advice. See our Privacy Policy and Terms for the governing commitments.