Enterprise Security

Your data's shield

We built Exceptio to meet the same standards you demand of yourself. Your client data deserves the strongest protection - here's exactly how we deliver it.

Security Overview
Encryption
AES-256-GCM
Active
Data Residency
EU Only
Ireland, EU
Compliance
GDPR / AVG
Verified
AI Training
Never
Guaranteed
More secure than 99% of Dutch law firms
All systems operational

How we protect every document

Every file you upload receives multiple layers of protection. From encryption to deletion, here's what happens at each step.

1

Envelope Encryption

Each document encrypted with unique keys. Even our team cannot read your files.

2

Key Rotation

Encryption keys automatically rotate. Yesterday's keys can't unlock tomorrow's data.

3

Audit Logging

Complete record of who accessed what, when. Your chain of custody, documented.

4

Secure Deletion

When you delete, it's truly gone. Cryptographically unrecoverable.

Encryption Pipeline
proces-verbaal.pdf
234 pages • 12.4 MB
AES-256-GCM encryption
256-bit
Unique document key generated
per-doc
Access logged to audit trail
immutable
Encrypted & Stored
EU data center

What we encrypt

AES-256-GCM encryption at rest

Case descriptions
Defendant names
Dates of birth
Prior convictions
Document summaries
Detected names
Detected keywords

Your team cannot read encrypted fields — only your authenticated session can decrypt them.

Data Rights Portal

Your Data Rights

Full control over your data under GDPR / AVG

Export All Data
Download complete archive
Available
Request Deletion
Complete removal within 72h
Available
Processing Agreement
DPA signed and active
Active
Compliance Status
GDPR / AVG Compliant

GDPR & AVG compliant

Full compliance with European data protection regulations. Your rights as a data controller are fully supported - export, delete, or audit at any time.

  • Data Export

    Export all your data anytime. Complete transparency, no lock-in.

  • Right to Deletion

    Request deletion of all your data. We comply within 72 hours.

  • Data Processing

    Your data processed only for case analysis. Never sold, never shared.

AI Transparency

AI you can verify

Unlike generic AI tools, every answer cites your documents. No made-up information. Trust, then verify.

How Exceptio Works
1

You ask a question

Ask in plain Dutch or English about your case.

2

System finds sources

Searches your documents for relevant passages.

3

AI drafts response

Uses only found passages. Every claim cites a source.

4

You verify instantly

Click any citation to jump to the exact page.

Your data never trains our AI

Unlike consumer AI tools, your documents are never used to improve our models. Your cases stay yours. Period.

Contractual Guarantee
Your documents are never used for training
Every answer cites your sources
Full audit trail of all queries
Professional Confidentiality

Attorney-client privilege, protected

Your ethical obligations demand safeguarding client data. Our architecture ensures your privilege remains intact.

Logical Separation

Each case exists in its own secure space. No cross-contamination between matters.

Access Controls

You control who sees what. Granular permissions for every team member.

Confidentiality Guarantee

We contractually guarantee confidentiality. Your privilege is our priority.

Client Data Isolation

Active Matters

Each client's data is completely isolated

M. de Vries
Case #2024-0847
Isolated
12 documentsEncrypted
J. Bakker
Case #2024-0923
Isolated
8 documentsEncrypted
P. Jansen
Case #2024-1102
Isolated
23 documentsEncrypted
No cross-matter data access possible
Privilege protected
EU Data Residency

Your data stays in Europe

Dutch law applies. EU regulations protect you.

1

EU-only infrastructure

All servers located within the European Union. Your data never leaves EU territory.

2

Dutch legal jurisdiction

Data subject to Dutch and EU law, not US CLOUD Act. No foreign government access.

3

No transatlantic transfers

Your data never crosses the Atlantic. Full sovereignty over your information.

Infrastructure Map
Ireland, EU
European UnionData stays here

Protected by EU law

GDPR, AVG, and Dutch privacy law govern how we handle your data. No American court can compel access.

Ready to work with confidence?

Your client data deserves the protection we provide. Start your secure practice today.

AES-256-GCM encryption
GDPR compliant
EU data residency
No AI training