HAQQ Cloud
We run it, in the region you pick. Encrypted, isolated per firm, nothing pooled between customers.
Your matters never train a model, never leave the region you choose, and never touch another firm's data.
Justinian runs as seven layers. The seventh is not a feature sitting on top of the other six - it is the boundary they all run inside.
Ethical walls, residency and retention, wrapping all six.
SSO, MFA and role-based access across every surface.
Every action logged, attributable and exportable.
One tenant per firm. No cross-matter mixing, ever.
AES-256 at rest, TLS 1.3 in transit, on every connection.
Guardrails and human review on every agent action.
No training on your data. Bring your own encryption key.
Three ways to run HAQQ and three regions to run it in. The platform is identical in all of them - only the boundary moves.
We run it, in the region you pick. Encrypted, isolated per firm, nothing pooled between customers.
Your own cloud tenancy. You hold the encryption keys, we operate the software inside your account.
Inside your own building, on your own hardware. Nothing crosses your network boundary.
Available regions: European Union, United States, Middle East
Compliant with the SOC 2 framework for security, availability, processing integrity, confidentiality, and privacy of customer data.
International standard for information security management systems (ISMS), demonstrating systematic approach to managing sensitive data.
Compliant with the ISO 42001 standard for AI management systems, ensuring responsible and ethical AI development and deployment.
Full compliance with EU General Data Protection Regulation, ensuring data subject rights and privacy protections.
Trust centre: privacy notice, DPA, sub-processors and compliance evidence
"Security isn't a feature we added - it's the foundation we built on. Legal professionals trust us with their most sensitive data, and we take that responsibility seriously every single day."
Antoine Kanaan
Co-Founder & CEO, HAQQ
Your data is stored in SOC 2 compliant data centers. You can choose your preferred region (EU, US, or Middle East) to meet data residency requirements.
No. Your data is never used to train our AI models or any third-party models. Your information remains exclusively yours.
Our platform is designed to maintain attorney-client privilege. Data isolation, encryption, and access controls ensure privileged communications remain protected.
We have a comprehensive incident response plan. You'll be notified within 72 hours of any incident affecting your data, per GDPR requirements.
Compliant. Our controls are designed and operated to align with the SOC 2 Trust Services Criteria, ISO/IEC 27001 and ISO/IEC 42001, and we meet GDPR obligations as a processor. We describe that as alignment rather than a completed third-party certification, and we will confirm the exact scope in writing for your procurement team.
Yes. Enterprise customers can bring their own key and keep full control of the key lifecycle and rotation. Revoking the key ends our ability to read the data.
Yes. HAQQ runs as a managed service in the region you choose, inside your own cloud tenancy, or fully on-premise. The product is the same in all three; what changes is who owns the perimeter.
You configure the retention period to match your regulatory obligations. Purging is automatic once it elapses and produces a verification log. You can export everything at any time.
Nobody, by default. Access is role-based, least-privilege and logged. Support access to a specific matter requires your explicit approval and expires on its own.
Found a vulnerability? Read our disclosure policy and contact the security team. Responsible disclosure