Features
Security built for contract data
ReviewPro is hosted on AWS and is SOC 2 Type II, HIPAA, and FISMA compliant, with AES-256 encryption, role-based access, single sign-on, and 99.9% uptime.
SOC 2 Type II, HIPAA, and FISMA
ReviewPro is SOC 2 Type II compliant and independently audited, and meets HIPAA and FISMA requirements.
Vulnerability and penetration testing runs against NIST 800-171. Intrusion detection runs at critical network points with real-time alerting, and a third-party qualified security assessor monitors continuously. Employees complete background checks and security training.
AES-256 at rest, TLS 1.2+ in transit
Contract data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Keys are managed in AWS Key Management Service using FIPS 140-2 Level 3 validated hardware security modules.
Training on your data is your choice
Your contracts are used to train LegalSifter models only if you allow it. The choice is made in your agreement, and any data used for training is de-identified and anonymized first.
ReviewPro’s generative AI features run on OpenAI, under OpenAI’s Business Terms, which state that customer content is not used to develop or improve their services. Other customers cannot see your contracts, metadata, playbooks, or prompts.
When you end your subscription, your contracts are permanently deleted within 30 days.
Single sign-on and role-based access
Single sign-on supports SAML 2.0 and OIDC through Auth0, with multiple identity providers. With SSO enabled, authentication is delegated to your identity provider, so your own conditional access policies enforce multi-factor authentication for every user.
Access is controlled by role and by feature, and tenant data is isolated at row level.
99.9% uptime across AWS regions
Data is replicated across multiple AWS Availability Zones and Regions with automatic failover, so services tolerate both system and hardware failures.
FAQ
What data does ReviewPro process?
The contract you are redlining and the playbook you are using, plus the account metadata needed to run the service: login and review history, credits used and remaining, and transaction history.