ExploreModulesCompareNetworkFAQPricingTry Free
SECURITY & PRIVACY

Trust Center

How Harlan protects your case data. Built for attorneys who handle sensitive client information and need verifiable security commitments.

Last updated: March 27, 2026
TLS 1.3
In Transit
AES-256
At Rest
Zero
Data Training
GDPR
Compliant

Data Commitments

Encryption and Infrastructure

TLS 1.3 in Transit

All data between your browser and Harlan's servers is encrypted with TLS 1.3. This includes case inputs, evaluation results, authentication tokens, and payment data. Let's Encrypt certificate with automatic renewal.

AES-256 at Rest

All stored data is encrypted at rest using AES-256. Database files, evaluation records, and user credentials are protected even in the event of physical storage compromise.

Isolated Compute

Each evaluation runs in an isolated server-side process. No shared memory between user sessions. Evaluation inputs are processed and discarded from working memory after report generation.

24/7 Automated Monitoring

Automated QA checks run every hour verifying page load, API health, interactive elements, console errors, and data integrity. Issues are detected and resolved within the hour.

CSP and Security Headers

Content Security Policy, HTTP Strict Transport Security (HSTS), X-Frame-Options, X-Content-Type-Options, and Referrer-Policy headers enforced via Nginx. Inline script handlers blocked by CSP.

Secure Authentication

Session-based auth with bcrypt-hashed passwords. Google OAuth available. No plaintext credential storage. Rate limiting on login endpoints prevents brute-force attacks.

Infrastructure Details

ComponentDetail
HostingDedicated VPS (not shared hosting). US-based data center.
Application ServerNode.js with Express, managed via PM2 process manager with automatic restart on failure.
Reverse ProxyNginx with TLS termination, rate limiting, and security headers (CSP, HSTS, X-Frame-Options).
DatabaseSQLite (server-local, not cloud-hosted). No external database connections. 439+ verified court verdicts.
AuthenticationSession-based with bcrypt-hashed passwords. Google OAuth supported. No plaintext credential storage.
PaymentsStripe (PCI DSS Level 1). Harlan never stores card numbers, CVVs, or full payment details.
AI ProviderAnthropic (Claude). Zero data retention policy on API calls. No training on your inputs.
AnalyticsPlausible Analytics (privacy-focused, no cookies, GDPR-compliant, EU-hosted).
SSL CertificateLet's Encrypt with automatic renewal. TLS 1.3 enforced.

Data Retention Policy

Data TypeRetentionDeletion
Case evaluation inputsStored while account is activeDeleted on user request or account deletion
Evaluation reportsStored while account is activeDeleted on user request or account deletion
Account credentialsWhile account is activePermanently deleted on account deletion
Payment recordsManaged by StripeSubject to Stripe retention + tax law requirements
AI API call logsNot retained by AnthropicInputs discarded after response generation
Web analyticsPlausible (aggregated, no PII)No personal data to delete
Uploaded filesStored while account is activePermanently deleted on user request

Subprocessor List

Third-party services that may process data as part of delivering Harlan's service.

AnthropicAI model provider (Claude). Processes case inputs to generate evaluations. Zero data retention on API calls.
StripePayment processing. Handles credit card transactions. PCI DSS Level 1 certified.
PlausiblePrivacy-focused web analytics. No cookies, no personal data collection. EU-hosted.
GoDaddyVPS infrastructure. US-based data center. Physical security and network infrastructure.

Access Controls

Security Roadmap

Planned security enhancements for enterprise and firm clients.

SAML SSO

Single Sign-On integration for firms using Okta, Azure AD, or Google Workspace. Planned for enterprise tier.

Audit Logs

Detailed activity logs showing who accessed what, when. Export-ready for compliance reviews. Coming to Pro and Enterprise tiers.

SOC 2 Type II

Formal SOC 2 Type II audit and certification. In progress. Target completion for enterprise launch.

IP Allow-Listing

Restrict account access to approved IP ranges. Designed for firms with strict network policies. Enterprise tier.

Questions about security?

If your firm requires additional security documentation, a Data Processing Agreement, or has questions about Harlan's security posture, reach out directly.

Contact Security Team
Or try a free evaluation to see it in action.