Security & Compliance
Uncompromising security.
Your documents, prompts, and outputs are never used to train AI models. AI inference is zero-retention with model providers, and every organization is isolated, encrypted, and auditable.
The promise
Your data stays yours. Full stop.
Irys stores the customer content necessary to provide the product inside the customer's isolated, encrypted environment. Irys does not use that content to train models. Model-provider inference is configured for zero retention.
No AI Training
Your content never trains Irys or third-party models.
Zero-Retention Inference
Model providers don't retain your prompts or outputs.
Tenant Isolation
Your organization's data is never pooled with another customer's.
Encryption & Control
Encryption in transit and at rest, with enterprise access controls.
Certifications & Standards
Audited independently. Controlled by you.
Delete
Delete your data at any time. Cancelled accounts stay exportable for up to 90 days, then everything is permanently deleted within 30 days.
Export
Export your content in standard formats, Word or PDF, whenever you need it.
Control Access
Set roles and permissions for every user, enforced with MFA and SSO or SCIM.
Policies
Security Architecture
Layers of protection at every level.
From access control to data transit to AI inference, every layer is designed to protect your clients' data.
Encryption at Every Layer
All data is encrypted in transit and at rest. Third-party model calls are stateless. Vendor caching is disabled so nothing persists outside your tenant boundary.
View details
- TLS 1.2+ for all data in transit
- AES-256 encryption at rest
- Zero vendor-side data retention
Multi-Factor Authentication
MFA is enforced across all user sessions. Role-based access control enforces least-privilege access across the organization.
View details
- MFA enforced for all accounts
- Least-privilege role model (Org Admin, Matter Owner, Contributor)
- SSO / SCIM for enterprise deployments
Session Controls & Audit
Inactive sessions are automatically terminated. Full audit trail tracks every action, access event, and change across the platform.
View details
- Automatic idle-session expiry
- Complete audit trail, exportable for compliance
- Hard tenant isolation, no data commingling
Architecture Before AI
RAG, OCR, and a matter-centric Knowledge Graph provide context first. AI models are only invoked for narrow inference, never as a general data store.
View details
- Matter-centric workspaces, never pooled
- AI invoked only for narrow inference
- Processing is ephemeral and containerized
Built for legal
Designed to preserve confidentiality
and support privilege.
Irys is not a general AI tool retrofitted for law. It was architected from day one for privilege, confidentiality, and professional responsibility. RAG, OCR, and a matter-centric Knowledge Graph provide context first. AI models are only invoked for narrow inference, never as a general data store.
From our Head of AI
Research and analysis from Devansh, Co-Founder & Head of AI at Irys.
Security you can trust.
Built by lawyers. Audited by experts. See Irys in action.

