Lawyer-built. Secure by default. Accountable by design.

TRUSTED BY LEGAL & PROPERTY TEAMS

GDPR
ISO 27001:2022
SRA-regulated experts
SOC 2 Pending

Enterprise-grade protection

In-house security team

Security sits in product, infrastructure and operations. Monitoring and incident response run 24/7.

Your data, your control

You set retention. You can export your data when you need it.

No training. ZDR with model providers.

We do not train on your data. Model providers are under zero data retention (ZDR) agreements: they do not retain prompts or outputs.

Access controls

SAML SSO, role-based permissions, audit logs and user lifecycle management.

Contractual commitments

Security addendum aligned to SOC 2 Type 2. Terms your counsel can review.

Independent testing

Third-party audits and annual penetration tests. Reports are in the Trust Center.

The rigor of Big Law, applied to every output.

Maarten Schellingerhourt

Maarten Schellingerhout

Ex-Freshfields, A&O Shearman

Willem Jongert

Willem Jongert

Ex-Paul Hastings

Everything to know about security at Alaro

Find answers about how Alaro protects your data, safeguards its platform, and approaches compliance.
If you don’t find the answer you need, reach out to us.

No. We hold Zero Data Retention agreements with every model provider we use and neither we nor they use your inputs or outputs to train or fine-tune any model.

It's deleted. This is a passing, continuously-monitored control on our trust center, not just a policy statement.

Access to our backend runs on SAML SSO, role-based permissions, audit logs and user lifecycle management — nobody gets standing access without a reason tied to their role and every access event is logged.

No — you send us the work directly, nothing to log into. Our own backend systems (where your data is actually processed) are the ones under access control, not a product surface you interact with.