> ## Documentation Index
> Fetch the complete documentation index at: https://docs.parley.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and compliance

> How Parley protects your firm's confidential client data, and the standards we follow.

Law firms trust Parley with confidential client matters. This page summarizes how we protect that data and the standards we follow. For full details, visit our [Trust Center](https://trust.parley.so/).

## SOC 2

Parley undergoes System and Organization Controls (SOC) 2 Type 2 audits of the design and operating effectiveness of our security controls.

## GDPR

Parley is compliant with the EU General Data Protection Regulation (GDPR). We act as a data processor for the personal data our customers store in Parley, and we support our customers in meeting their obligations as data controllers. For personal data transferred from the EU, the UK, and Switzerland, Parley is certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework, and uses Standard Contractual Clauses where another transfer mechanism is required. See our [Privacy Policy](https://www.parley.so/privacy-policy) for details.

[Contact us](mailto:support@parley.so) if you require a Data Processing Agreement (DPA) or have questions about how we handle personal data.

## Your data

Your firm owns its data. Everything your team uploads to Parley, and everything Parley generates from it, remains your firm's property and is treated as your confidential information.

We never use your content or generated work product to train, fine-tune, or otherwise develop AI models that are deployed for or accessible to other customers.

## Security controls

Our security program includes:

* Encryption of data in transit and at rest
* Multi-factor authentication and least-privilege access, with regular access reviews
* Automated backups and tested disaster recovery plans
* Centralized audit logging, monitoring, and a documented incident response and breach notification process
* Annual penetration testing, continuous vulnerability scanning, and automated patching
* Confidentiality agreements and annual security training for all personnel

See the full list of controls in our [Trust Center](https://trust.parley.so/?tab=securityControls).

## Subprocessors

Parley uses a limited set of vetted subprocessors, including cloud infrastructure and AI model providers, to deliver the service. The current list is available in our [Trust Center](https://trust.parley.so/).

## Access controls in your workspace

Who can see what inside your firm is governed by roles. Owners can see every Project, including private ones, and are the only role with access to billing. See [Permissions](/admin/permissions).

## Reporting a security issue

For security reviews, questionnaires, or compliance documentation, start at the [Trust Center](https://trust.parley.so/) or contact your account team.
