Security at SenseFrame

Security for confidential legal work.

Your matters contain privileged and confidential client information. SenseFrame protects this information at each layer of the platform. This page tells you where your data is, how we protect it, and how you stay in control of it.

For IT reviewers, firm principals and information officersLast updated 3 October 2026

At a glance

Six commitments that apply to every firm.

Our Terms of Service make each of these commitments contractual.

Stored in South Africa

Your documents, matters and queries are stored in South Africa, on secure Microsoft Azure servers.

Encrypted throughout

Your data is encrypted in transit with TLS 1.2 or higher, and at rest with AES‑256.

Separate for each firm

Each firm has its own workspace. Users see only the content of their own firm.

Controlled at matter level

Your firm decides who can work on each matter.

Your content stays yours

Your content is used only to provide your service. It is excluded from AI model training.

Backed up in South Africa

Encrypted backups stay in South Africa.

01

Where your data is

Your documents, matters, queries and drafts are stored in South Africa, on secure Microsoft Azure servers. They are encrypted in transit and at rest.

The SenseFrame application is served to your browser from Cape Town. Our Terms list each provider that helps to deliver SenseFrame, in the Subprocessor Register.

02

How we protect your data

SenseFrame uses the security controls of Microsoft Azure, with our own controls added at the application level.

  • In transitAll connections to SenseFrame use TLS 1.2 or higher. Browsers must use HTTPS.
  • At restThe database, document storage, search index and backups are encrypted with AES‑256. Stored documents have a second layer of encryption.
  • Private networkThe database is reachable only from inside our private network. Stored documents are private to your firm.
  • Secrets and keysSecrets are kept in a managed key vault. Our services connect to storage and search with managed identities.
03

Who can access your data?

Your firm

Each firm has a separate workspace. The platform limits each request to the data of the firm of the user. Inside the firm, your administrators set roles and give access to each matter.

Your accounts

Each user has their own account. Passwords must have at least 12 characters, and are stored only in a protected form that cannot be turned back into the original password. Repeated failed sign-in attempts are limited.

Sessions end automatically. When a password or a role changes, or when an administrator removes a user, all sessions of that user end.

SenseFrame personnel

Access to customer content is limited to authorised SenseFrame personnel. We use it only to give support that you ask for, to examine a fault or a security issue, or when the law requires it. Access to production systems, stored documents and secrets is logged with the identity of the authorised personnel.

AI models

Your content is used only to provide your service. It is excluded from the training of AI models, both public models and our own.

04

How we build and operate SenseFrame

  • Separate environmentsProduction has its own database and document storage, separate from development.
  • Secure developmentAutomatic tests and security checks run before each release. Each change is scanned for vulnerable dependencies and exposed secrets, and our code is analysed regularly.
  • Independent testingAn independent firm does a penetration test of the platform each year.
  • MonitoringOur engineering team monitor the platform continuously, using automated alerts to notify us of incidents.
05

Backups and recovery

  • Continuous backupThe database is backed up continuously and can be restored should any unintentional data loss occur.
  • In South AfricaAll backups are encrypted and stay in South Africa. Archive copies are kept in two Azure regions in South Africa.
06

Security incidents

We follow defined procedures to locate, contain and correct security incidents.

If an incident puts personal information at risk, we tell your firm without undue delay, as section 22 of POPIA requires. Our target for the first notice is 72 hours after we become aware of the incident. We give your firm the information that it needs to meet its own obligations, and we work with your firm until the incident is closed.

07

Your data, your control

  • OwnershipYour firm owns its content. Under POPIA, your firm is the responsible party and SenseFrame is the operator.
  • ExportYou can download your documents, drafts and chat responses at any time.
  • DeletionDeleted content leaves the service immediately. You can restore it for 30 days. After that, it is permanently deleted from our live systems.
  • When you leaveYour account stays available as read-only for 90 days after cancellation, after which it is purged from our systems. A firm administrator can ask us in writing to delete all the content of the firm, or to supply a copy.
08

Standards and assurance

  • POPIA

    Operator terms

    Our Terms include operator terms for the personal information that we process for your firm.

  • Microsoft Azure

    ISO 27001 · SOC 2

    SenseFrame runs on Microsoft Azure, whose infrastructure is certified to ISO/IEC 27001 and SOC 2.

  • Penetration testing

    Annual

    An independent firm tests the platform each year.

  • Due diligence

    On request

    We complete security questionnaires and supply more information for your review. Email legal@senseframe.ai.

Security is an ongoing practice. We review our controls regularly and make them stronger as SenseFrame grows. When a control changes, we update this page.

09

Report a security issue

If you find a possible vulnerability in SenseFrame, please tell us.

Send an email to legal@senseframe.ai, with a description of the issue and the steps to show it. Please test only with your own account and data. We’ll confirm receipt of your report and keep you informed until resolution.

10

Questions

Your content is used only to provide your service. It is excluded from the training of AI models, both public models and our own.

In South Africa, on secure Microsoft Azure servers. Your data is encrypted in transit and at rest, and your backups also stay in South Africa.

Only authorised SenseFrame personnel, and only to give support that you ask for, to examine a fault or a security issue, or when the law requires it. Access to production systems is logged with the identity of the authorised personnel.

SenseFrame keeps your content confidential under contract. We process it only to provide your service, and our providers are bound to the same purpose. Your firm controls who can see each matter.

Yes. We complete security questionnaires and supply more information about our controls. Email legal@senseframe.ai. We can also show the platform to your team.

Your account stays available as read-only for 90 days, so that you can download your content. After that, it is purged from our systems. A firm administrator can also ask us in writing to delete all the content of the firm sooner.

Security review

Are you examining SenseFrame for your firm?

We complete security questionnaires and supply more information about our controls. We can also show the platform to your team.