Skip to content

Your data is safer here than at most law firms.

Isolated per-client instances. Encrypted at rest with keys held in the EU. DPA signed at onboarding. Zero cross-client contamination. Every AI output disclaimed. The boutique firm sharing your NDA over WhatsApp does none of this.

Trust is table stakes. We treat it as the moat.

Ask your security question →

1. Data we handle

What comes in, what stays, what leaves.

  • Client legal work. Contracts, cap tables, deal documents, engagement letters, memos. Received via email, uploaded to Drive, drafted in Docs. Stored in per-client folders on Google Workspace (EU multi-region), mirrored nightly to Hetzner (Falkenstein DE), backed up weekly to Backblaze B2 (Amsterdam NL).
  • Client and prospect communications. Email threads, WhatsApp messages, Telegram messages, call notes. Stored in the operational stack for the duration of the engagement plus retention floor.
  • Financial records. Invoices, expenses, wire records, tax filings. Stored per Ley General Tributaria and Codigo de Comercio.
  • Operational metadata. Timestamps, task states, gate outcomes, system logs. Not personal data in most cases. Used for reliability and audit.
  • Personal communications and journal. Pepe's own comms, therapy notes, journal entries. Not client data, but treated with the same encryption posture.

Client documents are never submitted to any third-party model provider for training. Not now, not ever. This is written into every engagement letter under the AI Use clause.

2. How we protect it

Principles here. Detailed technical controls live in the internal controls register, audited quarterly by Kim.

  • Encryption at rest. Data in the operational stack is encrypted at rest with AES-256. Backup archives are encrypted with independently-managed keys before leaving primary storage.
  • Encryption in transit. TLS 1.3 for all external traffic. Certificate rotation automated.
  • Key custody. Backup encryption keys are held under a Shamir 3-of-5 split with custodians in Barcelona and elsewhere in the EU. No single person can decrypt our archive stack alone. Any three custodians can reconstruct if needed.
  • Per-client isolation. Each client's data lives in a dedicated folder tree on Google Workspace, a dedicated row space on our internal databases keyed on client_id, and dedicated access rules on Cloudflare Access. Cross-client access requires an explicit code path that logs the access.
  • Access control. Human access to client data goes through Cloudflare Access + Google Workspace 2FA. Programmatic access uses short-lived tokens.
  • AI use. Every AI output that touches client data is disclaimed and logged. No client document is submitted to any third-party model provider for training. Prompt data uses zero-retention API tiers where available.

We are structured to comply with GDPR Article 5 obligations of confidentiality, integrity, storage limitation, and lawful cross-border transfer. Compliance is a state a regulator declares. We can show the architecture and the audits that support the claim.

3. Where data lives

Full subprocessor list. Updated whenever a subprocessor is added, removed, or changes region. Last updated: 2026-08-28.

Subprocessor Purpose Location Data class Transfer basis
Hetzner Online GmbHCompute + primary storageFalkenstein, DEAll operational dataEU-only. DPA signed.
Backblaze Inc. (B2)Cold backup, encrypted archiveEU-Central-003 Amsterdam, NLEncrypted archives onlyData at rest in EU. Corporate HQ US. SCCs + AES-256 client-side (EDPB Rec 01/2020 Use Case 3).
Google LLC (Workspace)Email, Drive, Docs, CalendarUS + EU multi-regionClient comms, documents, calendarGoogle-signed DPA + SCCs + Google Cloud EU data-residency commitments.
Anthropic PBCClaude API (Janis AI layer)USPrompt content (may include client data via context)SCCs + zero-retention API mode where enabled. Prompt data not used for training.
Cloudflare Inc.CDN, DNS, Access, TunnelEU + US anycastSite traffic, auth tokensSCCs + Cloudflare DPA. EU data localization suite enabled where available.
OpenAI OpCo LLCImage generation, Whisper transcriptionUSVoice notes, image promptsSCCs + API-tier zero-retention. Client-privileged material not sent.
WhatsApp / Meta Platforms Ireland LtdWhatsApp Business Cloud APIIE + USMessage content, mediaMeta EU controller + SCCs for US onward.
Telegram FZ-LLCTelegram Bot + MTProto userbotAE (Dubai) + globalMessage contentNo SCCs available. Consent + minimisation basis. Client data not routed here.
GitHub Inc.Code + version controlUSSource code, non-secret configsSCCs + Microsoft DPA. Secrets scanning enabled.
Codeberg e.V.Secondary git mirrorDESame as GitHubEU-only. Non-profit.
Budget Bakers s.r.o. (Wallet API)Personal finance ingestCZTransaction metadataEU-only. Read-only integration.
Tavily AIWeb searchUSSearch queriesSCCs. Client data not routed here.
ResendRelease-notes digest emailUS + EUSubscriber email addresses onlySCCs. DKIM/SPF configured.

Pending review before addition: agentmail.to (Lume operator relay). Row added once transfer basis confirmed.

4. Retention

  • Client legal work and matter files. 6 years post matter close, then 4 years cold archive, then destruction. Basis: Codigo Deontologico art. 21 + Codigo Civil art. 1964.
  • Financial records. 10 years. Basis: Ley General Tributaria art. 66 + Codigo de Comercio art. 30.
  • Personal communications and journal. 3 years full-fidelity, then summary metadata only.
  • Health data. 5 years post-treatment. Basis: Ley 41/2002 art. 17.
  • Infrastructure secrets. Current plus one rotation only.

Data subjects may request erasure at any time under GDPR Article 17. Erasure from live systems happens within 30 days. Erasure from backups happens on natural rotation, tracked in our erasure log. Maximum time to full erasure across all systems: 7 years.

5. Incident history

We publish every confirmed security incident affecting our stack. Terse honesty over silence.

No security incidents reported to date.

If and when an incident occurs, we publish here with date, one-sentence description, discovery + resolution timeline, data class affected, notifications sent, root cause, remediation, and related release-notes entry.

6. How we improve

Security is not a page. It is a habit. Every security-relevant shipment lands in release-notes.

Recent security shipments

Loading recent shipments.

7. Responsible disclosure

Reporting a security issue. Email security@mexzungu.com. Encrypt sensitive reports with our PGP key (link coming; contact us in the meantime). We acknowledge within 72 hours. We aim to remediate confirmed issues within 30 days, or publicly disclose the timeline for a longer fix.

Safe harbor. We will not pursue legal action against researchers who: act in good faith, do not access, modify, or destroy data belonging to third parties, do not degrade service for other users, and give us a reasonable window to remediate before public disclosure (default: 90 days).

Out of scope. Denial of service, social engineering of staff, physical attacks, spam, and volumetric attacks.

No bug bounty. We do not currently offer monetary rewards. We publicly acknowledge researchers (with consent) in our disclosure log.

8. International data transfers

Some of our subprocessors have corporate presence in the United States or process data in US regions. For each such transfer we rely on:

  1. Standard Contractual Clauses (EU Commission Decision 2021/914),
  2. supplementary technical measures per EDPB Recommendations 01/2020, and
  3. where used, client-side encryption with keys held only in the EU, rendering transferred data non-personal in the hands of the recipient per Case C-582/14 (Breyer).

Per-subprocessor details in the table above. A copy of our Transfer Impact Assessment is available to enterprise clients on request under NDA.

9. AI use policy

We use AI in every part of our stack. Every AI output that touches client data is disclaimed and logged. No client document is submitted to any third-party model provider for training. Client-privileged material is not routed to any provider without a zero-retention API tier.

Full AI Use Policy publishing separately.