Skip to content
clmSpace

Last updated: 24 June 2026

Trust centre

Welcome to the clmSpace trust centre. clmSpace is operated by Rated Counsel Limited (United Kingdom) and is built so that legal and commercial teams in regulated sectors can adopt it with confidence: source contracts stay in your own SharePoint or Google Drive, hosting and derived contract intelligence are in the United Kingdom, access is least-privilege and deny-by-default, every request is bound to a verified tenant, and AI output is relied upon only after a human verifier confirms it. The documents below set out exactly how we protect your data and honour our commitments.

Security and architecture

  • Security white paper : written for information-security reviewers, covering architecture and data residency, identity and access, multi-tenant isolation, encryption, secure development and testing assurance, logging, incident response, continuity, and compliance.
  • Technical and organisational measures : the formal schedule of security controls referenced by our data processing addendum, structured for a reviewer, covering access control, tenant isolation, encryption, secret management, auditability, software assurance, logging, incident response, continuity, data handling and personnel measures.

Privacy and data protection

  • Privacy policy : the personal data we handle, why, the lawful bases, international transfers, and your rights.
  • Data processing agreement : the processor terms under which we handle customer contract data on your documented instructions, with the customer as controller.
  • Sub-processors : the complete, dated register of every party that processes customer contract data, with each one’s purpose, data categories, and hosting region.
  • Transfer impact assessment : our assessment of the one routine restricted transfer, contract text sent to Anthropic in the United States for AI inference, the UK IDTA mechanism relied upon, the supplementary measures, and why the transfer can proceed.
  • Data retention schedule : the retention period we apply to each category of data, with deletion on request.

Service commitments and acceptable use

Reporting a vulnerability

  • Responsible disclosure policy : how to report a security issue in good faith, the safe harbour we offer researchers who follow it, and what to expect in return.

Request the security pack

Reviewers can request our security pack, covering policies, sub-processor due-diligence records, and the underlying platform attestations, at security@clmspace.com. For privacy questions, write to privacy@clmspace.com.