Hosting & data residency
The Reglo platform is hosted on Amazon Web Services in the UK (London region, eu-west-2). Your account content, uploaded documents, and any files processed for reviews are stored in the UK. Data at rest is encrypted, and all data in transit is protected with TLS 1.2 or higher.
AI & your data
- UK inference. AI inference runs within our UK region via Amazon Bedrock. The models we use (from Anthropic and OpenAI) are accessed in-region through Bedrock.
- No training on your content. We do not allow AI providers to use the content you submit to train their models.
- Human approval. AI outputs are advisory. A person on your team reviews and approves before anything is finalised.
- File reviews. When you connect LEAP, Clio or Actionstep, we access only the files and matters you scope, process them to provide the review, and do not retain them beyond that purpose. See our Data Processing Agreement.
Access controls
- Role-based access controls within the product
- Least-privilege access and multi-factor authentication for staff access
- Network segmentation, secrets management, and audit logging
- Regular patching, dependency monitoring, and vulnerability management
Sub-processors
We keep the list of third parties who help us provide the Services, along with their purpose and location, on a dedicated page. We give at least 30 days' notice before adding a new sub-processor that processes customer personal data.
Availability
We aim for 99.9% monthly availability and design the platform for resilience, with regular backups and documented recovery procedures. We're an early-stage product and do not currently offer contractual service credits; where a signed agreement includes specific availability commitments, those terms apply. We'll keep customers informed of any significant service disruption.
Certifications & assurance
We're building toward SOC 2 and designing our controls against recognised standards as we grow. We don't claim certifications we don't yet hold. If your firm's due diligence needs more detail, we're happy to share security documentation and complete a security questionnaire — contact us and we'll help.
Incident response
We maintain documented incident-response and business-continuity procedures. If we become aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours where required, and affected customers without undue delay.
Reporting a vulnerability
Found a security issue? Please tell us at security@useReglo.com. We investigate every report and will work with you on responsible disclosure.