Lawyer-built. Secure by default. Accountable by design.
TRUSTED BY LEGAL & PROPERTY TEAMS
Enterprise-grade protection
In-house security team
Security sits in product, infrastructure and operations. Monitoring and incident response run 24/7.
Your data, your control
You set retention. You can export your data when you need it.
No training. ZDR with model providers.
We do not train on your data. Model providers are under zero data retention (ZDR) agreements: they do not retain prompts or outputs.
Access controls
SAML SSO, role-based permissions, audit logs and user lifecycle management.
Contractual commitments
Security addendum aligned to SOC 2 Type 2. Terms your counsel can review.
Independent testing
Third-party audits and annual penetration tests. Reports are in the Trust Center.
The rigor of Big Law, applied to every output.

Maarten Schellingerhout
Ex-Freshfields, A&O Shearman

Willem Jongert
Ex-Paul Hastings
Everything to know about security at Alaro
Find answers about how Alaro protects your data, safeguards its platform, and approaches compliance.
If you don’t find the answer you need, reach out to us.
No. We hold Zero Data Retention agreements with every model provider we use and neither we nor they use your inputs or outputs to train or fine-tune any model.
It's deleted. This is a passing, continuously-monitored control on our trust center, not just a policy statement.
Access to our backend runs on SAML SSO, role-based permissions, audit logs and user lifecycle management — nobody gets standing access without a reason tied to their role and every access event is logged.
No — you send us the work directly, nothing to log into. Our own backend systems (where your data is actually processed) are the ones under access control, not a product surface you interact with.