Encryption in transit and at rest
All data is encrypted with TLS in transit and encrypted at rest in our databases. Your documents are protected at every stage.
Legal data demands the highest level of protection. Parachute is built with security at its core, from encryption to certification.
All data is encrypted with TLS in transit and encrypted at rest in our databases. Your documents are protected at every stage.
Stage 1 audit of our information security management system is complete. Stage 2 certification audit is scheduled.
Our security practices align with SOC 2 standards, demonstrating our commitment to security, availability, and confidentiality.
Your data is never used to train AI models. AI interactions are processed securely and not shared across organisations.
Granular RBAC ensures team members only access what they need. Each organisation's data is logically isolated.
Regular automated backups ensure your data is never lost. Monitoring and alerting for any suspicious activity.
Hosted on secure cloud infrastructure with regular security updates, patching, and proactive vulnerability management.
Six practices that govern how we build, run, and protect the platform.
We are working through ISO 27001 certification. Our Stage 1 audit is complete, and our Stage 2 certification audit is scheduled. Our security practices also align with SOC 2 controls.
Each organisation's data is logically isolated. Your documents, knowledge base, and AI interactions are strictly separated from other organisations on the platform.
Your documents and knowledge base content are used only to generate responses for your organisation. Parachute does not use your data to train AI models. AI interactions are not shared across organisations.
Every code change goes through automated security scanning and peer review. We follow security best practices and conduct regular dependency audits.
We maintain an incident response plan with monitoring, defined escalation paths, and transparent communication. We commit to notifying affected customers promptly in the event of any confirmed breach.
Access to production systems follows the principle of least privilege. Role-based permissions in the platform ensure your team members only access what they need.
No. Your documents, knowledge base, and AI interactions are never used to train AI models. AI interactions are processed securely and not shared across organisations.
Customer data is hosted in Australia today, with regional residency on the roadmap. All plans include enterprise-grade encryption in transit and at rest.
Parachute officially supports Australia, New Zealand, the United Kingdom, the United States and Canada. Customers select a country at sign-up and the AI defaults to that jurisdiction. Other jurisdictions are not officially supported but the AI can reason about them via web search.
Parachute is in the ISO 27001 certification process. Our Stage 1 audit is complete and the Stage 2 certification audit is scheduled. We will publish our certificate on this page once Stage 2 is complete.
Parachute's security practices are aligned with SOC 2 standards, demonstrating our commitment to security, availability, and confidentiality. We conduct regular security audits and dependency reviews.
Each organisation's data is logically isolated. Your documents, knowledge base, and AI interactions are strictly separated from other organisations on the platform. Role-based access controls (RBAC) ensure team members only access what they need.
All data is encrypted using TLS in transit and encrypted at rest in our databases. Regular automated backups ensure your data is never lost, with monitoring and alerting for any suspicious activity.
Talk to our team about your security requirements, or book a demo to see how Parachute fits your firm.