Skip to main content
Security
Confidential, secure, and built for in-house legal.
Security and privacy matter for you as in-house counsel, as a business matter and as part of your professional responsibility as a lawyer.
Trusted by 1,800+ legal teams.
Why GC AI
Safeguard your work with
the security it deserves.
Built for in-house counsel

Secure for your company's confidential information. Designed to give practical business guidance.
Data isolation and encryption

Your data is stored in a segregated database, encrypted at rest with AES-256 and in transit via TLS. You can delete it anytime.
Confidential and secure



With SOC 2 Type II compliance, your data is protected with encryption and security.
Compliance you can count on.
Our commitment to data privacy and security is embedded in every part of our business.


SOC 2
Type II Certified
SOC 2
Type II Certified


SOC 3
Certified
SOC 3
Certified

GDPR
Compliant
GDPR
Compliant
FAQ
Common questions
from in-house teams.
You’re in control. Delete your inputs and outputs at any time, right from the app.
If you’d like to have all of your organization’s data erased, just send a request via email to security@gc.ai.
You’re in control. Delete your inputs and outputs at any time, right from the app.
If you’d like to have all of your organization’s data erased, just send a request via email to security@gc.ai.
Encryption: Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Every connection we use, internal and external, is fully encrypted.
Data Segregation: Your data is isolated from every other customer's data, so no other customer can access your information
Vendor Protection: Our AI model providers are prohibited from using your data to train their models, and we maintain zero-data-retention agreements with our LLM providers wherever feasible. Every vendor that processes your data is SOC-2 compliant. See our Subprocessor List.
Compliance Transparency: We are SOC 2 Type II certified. All of our reports are available through our Trust Center.
Encryption: Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Every connection we use, internal and external, is fully encrypted.
Data Segregation: Your data is isolated from every other customer's data, so no other customer can access your information
Vendor Protection: Our AI model providers are prohibited from using your data to train their models, and we maintain zero-data-retention agreements with our LLM providers wherever feasible. Every vendor that processes your data is SOC-2 compliant. See our Subprocessor List.
Compliance Transparency: We are SOC 2 Type II certified. All of our reports are available through our Trust Center.
Yes. You can treat GC AI the same way you’d treat any trusted cloud tool like Google Workspace, Slack or Asana. Our platform is built with enterprise-grade security and contractual confidentiality protections designed to preserve attorney-client privilege, consistent with evolving case law and formal Bar Association guidance.
State bars and the ABA advise that lawyers should review their provider’s security, just as with any technology vendor. Current guidance also includes:
New York (NY Bar Formal Opinion 2024-5), advising that the duty of candor is such that “a lawyer must review all [G]enerative AI outputs” including but not limited to “analysis and citations to authority,” for accuracy before use for client purposes and submission to a court or other tribunal.
We recommend consulting your local bar association for the latest rules and guidance on using generative AI.
Yes. You can treat GC AI the same way you’d treat any trusted cloud tool like Google Workspace, Slack or Asana. Our platform is built with enterprise-grade security and contractual confidentiality protections designed to preserve attorney-client privilege, consistent with evolving case law and formal Bar Association guidance.
State bars and the ABA advise that lawyers should review their provider’s security, just as with any technology vendor. Current guidance also includes:
New York (NY Bar Formal Opinion 2024-5), advising that the duty of candor is such that “a lawyer must review all [G]enerative AI outputs” including but not limited to “analysis and citations to authority,” for accuracy before use for client purposes and submission to a court or other tribunal.
We recommend consulting your local bar association for the latest rules and guidance on using generative AI.
In United States v. Heppner (S.D.N.Y. Feb. 17, 2026), Judge Jed Rakoff issued the first federal ruling on AI and attorney-client privilege. The court held that a defendant's communications with a consumer AI platform were not privileged because: (1) the AI is not an attorney; (2) the platform's terms permitted data collection and third-party disclosure, defeating confidentiality; and (3) the defendant used the tool on his own initiative, not at counsel's direction.
Critically, the court left open that the analysis may differ where an AI tool is used at the direction of counsel under enforceable confidentiality protections.
GC AI is built exclusively for legal professionals. Our platform operates under enterprise-grade security with contractual confidentiality protections, and is designed to be used by attorneys as a tool to support their work. GC AI does not provide legal advice; it empowers attorneys and their companies to deliver legal advice more efficiently.
Read more at https://gc.ai/legal-ai-privilege-heppner-ruling
In United States v. Heppner (S.D.N.Y. Feb. 17, 2026), Judge Jed Rakoff issued the first federal ruling on AI and attorney-client privilege. The court held that a defendant's communications with a consumer AI platform were not privileged because: (1) the AI is not an attorney; (2) the platform's terms permitted data collection and third-party disclosure, defeating confidentiality; and (3) the defendant used the tool on his own initiative, not at counsel's direction.
Critically, the court left open that the analysis may differ where an AI tool is used at the direction of counsel under enforceable confidentiality protections.
GC AI is built exclusively for legal professionals. Our platform operates under enterprise-grade security with contractual confidentiality protections, and is designed to be used by attorneys as a tool to support their work. GC AI does not provide legal advice; it empowers attorneys and their companies to deliver legal advice more efficiently.
Read more at https://gc.ai/legal-ai-privilege-heppner-ruling
GC AI supports both individual lawyers and full legal teams, with secure authentication powered by WorkOS. Each login is tied to a single account. Organizations' admins have full access control and administration features, and we support SSO/SAML and work with all major identity providers. We also maintain incident response plans, conduct regular security audits, and train our team on data security.
GC AI supports both individual lawyers and full legal teams, with secure authentication powered by WorkOS. Each login is tied to a single account. Organizations' admins have full access control and administration features, and we support SSO/SAML and work with all major identity providers. We also maintain incident response plans, conduct regular security audits, and train our team on data security.
GC AI works with leading AI providers such as OpenAI and Anthropic. For a full list, see our subprocessor list. None of our providers train on your data.
GC AI works with leading AI providers such as OpenAI and Anthropic. For a full list, see our subprocessor list. None of our providers train on your data.
No. Your data is not used to train any AI model from our LLM providers.
No. Your data is not used to train any AI model from our LLM providers.
Yes. Our DPA is included in our standard terms for all customers.
Yes. Our DPA is included in our standard terms for all customers.
Disclosure requirements vary by jurisdiction. We encourage you to check your local rules and bar association guidance, as some courts require that attorneys disclose their use of AI to the court (see, i.e. Northern District of Texas (Civil Rule 7.2 - Briefs and Criminal Rule 47.2 - briefs).
Disclosure requirements vary by jurisdiction. We encourage you to check your local rules and bar association guidance, as some courts require that attorneys disclose their use of AI to the court (see, i.e. Northern District of Texas (Civil Rule 7.2 - Briefs and Criminal Rule 47.2 - briefs).
We retain your data only while your account is active and delete it upon written request. Other records (such as account data, financial records and security documentation), are retained in accordance with applicable legal and operational requirements. See GC AI Terms.
We retain your data only while your account is active and delete it upon written request. Other records (such as account data, financial records and security documentation), are retained in accordance with applicable legal and operational requirements. See GC AI Terms.
We use Standard Contractual Clauses (SCCs) for cross-border data transfers.
We use Standard Contractual Clauses (SCCs) for cross-border data transfers.
Get started today.
Let’s explore about how we can make your life as an in-house lawyer a whole lot easier.
Get started today.
Let’s explore about how we can make your life as an in-house lawyer a whole lot easier.


















