Skip to content
97.5% of teams see value from GC AI before month oneSee how

Confidential, secure, and built for in-house legal.

Security and privacy matter for you as in-house counsel, as a business matter and as part of your professional responsibility as a lawyer.

Trusted by 2100+ legal teams.

  • Arc'teryx
  • Helix
  • Interface
  • Viant
  • Wayfair
  • SimplePractice
  • Lockheed Martin
  • TIME
  • Landstar
  • Post
  • SKIMS
  • Zip
  • Gusto
  • Riot Games
  • SoftBank
  • Bass Pro Shops
  • Penguin Random House
  • Love's Travel Stops
  • Nestlé

Safeguard your work with the security it deserves

Privacy

No model training with your data

GC AI protects your data and does not use it for model training.

Legal-first

Built for in-house counsel

Secure for your company's confidential information. Designed to give practical business guidance.

Encryption

Data isolation and encryption

Your data is stored in an isolated database, encrypted at rest with AES-256 and in transit via TLS. You can delete it anytime.

Compliance

Confidential and secure

With SOC 2 Type II compliance, your data is protected.

Compliance you can count on. Our commitment to data privacy and security is embedded in every part of our business.

SOC 2
Type II Certified

Details

SOC 3
Certified

Details

GDPR
Compliant

Details

Common questions from in-house teams.

What data security does GC AI offer?
  • Encryption: Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Every connection we use, internal and external, is fully encrypted.
  • Data Segregation: Your data is isolated from every other customer’s data, so no other customer can access your information.
  • Vendor Protection: Our AI model providers are prohibited from using your data to train their models, and we maintain zero-data-retention agreements with our LLM providers wherever feasible. Every vendor that processes your data is SOC-2 compliant. See our Subprocessor List.
  • Compliance Transparency: We are SOC 2 Type II certified. All of our reports are available through our Trust Center.
What access and security controls do you have?
GC AI supports both individual lawyers and full legal teams, with secure authentication powered by WorkOS. Each login is tied to a single account. Organizations’ admins have full access control and administration features, and we support SSO/SAML and work with all major identity providers. We also maintain incident response plans, conduct regular security audits, and train our team on data security.
Can I delete my data from GC AI?
You’re in control. Delete your inputs and outputs at any time, right from the app. If you’d like to have all of your organization’s data erased, just send a request via email to security@gc.ai.
How does GC AI handle data retention and deletion?
We retain your data only while your account is active and delete it upon written request. Other records (such as account data, financial records and security documentation), are retained in accordance with applicable legal and operational requirements. See GC AI Terms.
What LLM providers does GC AI use and does GC AI or any of GC AI's subprocessors train on my data?
GC AI works with leading AI providers such as OpenAI and Anthropic. For a full list, see our subprocessor list. GC AI and our underlying service providers do not train on your data.
Can my organization opt out of a specific underlying llm?
Yes, Organization admins on Teams and Enterprise plans have full control to enable or disable specific models directly from your Organization Settings, no need to contact us. Steps for opting in and out are available here. Turning a provider off means its models will not be used for chat or any other product features. GC AI will instead use the next best model for each task. The change is reversible at any time, and every change is recorded (who, when).
Does GC AI train on data from my connected apps?
No. GC AI does not use your inputs to train models. Connected-app data is used to respond to your requests in GC AI, subject to the same security and privacy commitments described on gc.ai/security and in your agreement.
Can GC AI send an email or post to slack without my approval?
Only if you set that specific action to Always allow, or you choose Always approve on an in-chat approval card. The default for sensitive actions is Needs approval.
How can admins control agent connections for the org?
Agent Connectors are on by default. Admins can disable individual connectors for the organization from Settings → Policies → Connector policies. They can see which team members connected which apps and view connector usage, but not message or file content. Microsoft connectors may also require consent from the organization's Microsoft admin in Microsoft's own admin settings, outside GC AI.
What happens when I disconnect a connector?
Access is revoked for that connection. GC AI can no longer use that app’s tools in chat until you connect again. You can reconnect at any time from your connector settings.
Is GC AI API secure?
Yes. Calls are authenticated per request using personal API keys for the REST API. Keys and connections follow the same account permissions as the rest of GC AI, so an API key can only reach what its user can reach. Your data stays in your GC AI workspace, and your legal team has visibility into usage. The same company security model that applies across GC AI applies to the API.
What about attorney client privelage?
Yes. You can treat GC AI the same way you’d treat any trusted cloud tool like Google Workspace, Slack or Asana. Our platform is built with enterprise-grade security and contractual confidentiality protections designed to preserve attorney-client privilege, consistent with evolving case law and formal Bar Association guidance.State bars and the ABA advise that lawyers should review their provider’s security, just as with any technology vendor. Current guidance also includes: ABA Formal Opinion 512; New York (NY Bar Formal Opinion 2024-5), advising that the duty of candor is such that “a lawyer must review all [G]enerative AI outputs” including but not limited to “analysis and citations to authority,” for accuracy before use for client purposes and submission to a court or other tribunal.We recommend consulting your local bar association for the latest rules and guidance on using generative AI.
Do I need to disclose to my stakeholders or clients I use AI?
Disclosure requirements vary by jurisdiction. We encourage you to check your local rules and bar association guidance, as some courts require that attorneys disclose their use of AI to the court (see, i.e. Northern District of Texas (Civil Rule 7.2 - Briefs and Criminal Rule 47.2 - briefs).
Has there been a court case on privilege and AI yet?
In United States v. Heppner (S.D.N.Y. Feb. 17, 2026), Judge Jed Rakoff issued the first federal ruling on AI and attorney-client privilege. The court held that a defendant’s communications with a consumer AI platform were not privileged because: (1) the AI is not an attorney; (2) the platform’s terms permitted data collection and third-party disclosure, defeating confidentiality; and (3) the defendant used the tool on his own initiative, not at counsel’s direction.Critically, the court left open that the analysis may differ where an AI tool is used at the direction of counsel under enforceable confidentiality protections. GC AI is built exclusively for legal professionals. Our platform operates under enterprise-grade security with contractual confidentiality protections, and is designed to be used by attorneys as a tool to support their work. GC AI does not provide legal advice; it empowers attorneys and their companies to deliver legal advice more efficiently.Read more at https://gc.ai/legal-ai-privilege-heppner-ruling
Do you have a privacy addendum?
Yes. Our DPA is included in our standard terms for all customers.
How does GC AI handle cross border data transfers?
We use Standard Contractual Clauses (SCCs) for cross-border data transfers.
SOC 2 certification badgeSOC 2
SOC 3 certification badgeSOC 3
GDPR badgeGDPR

Get started today

Let's explore how we can make your life as an in-house lawyer a whole lot easier. SOC 2 certified. We maintain zero-data-retention agreements with our LLM providers wherever feasible.

What to expect:

  • A walkthrough of the platform, tailored to your team's use cases.
  • Q&A session about security, integrations, and onboarding.
  • A 14-day free trial if the platform looks like a fit for your team.

Book a Demo

Dial code +1 (United States)

By submitting, you agree to our Terms and Privacy Policy.