SettleIQ — Settlement Intelligence Platform
Security Controls Active

Attorneys doing due diligence before putting client data in any cloud tool need clear, factual answers about security controls. This page provides the technical details — not marketing language — about how SettleIQ protects your data.

1. Encryption

Data in transit:

Data at rest:

2. Organization Isolation

SettleIQ uses a strict multi-tenant architecture. Every law firm's data is isolated at the database level, not just the application level.

There is no administrative query or interface that shows one law firm's case content to another. Cross-org access is rejected at the application layer before any database query runs.

3. Authentication & Access Control

4. AI Provider

SettleIQ uses Google Gemini for all AI processing:

Per Google's API Terms of Service, data submitted via API calls is not used to train or improve Google's AI models. Google processes SettleIQ data as a data processor under their Data Processing Agreement.

SettleIQ does not use OpenAI, Anthropic, or any other AI provider. All AI processing goes through Google Gemini exclusively.

5. HIPAA Clarification

Law firms are not HIPAA covered entities. SettleIQ handles medical records as case evidence under attorney work product privilege, not as healthcare data.

HIPAA applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. Law firms handling medical records in the course of litigation are generally not HIPAA covered entities and are not subject to HIPAA's technical safeguard requirements.

Medical bills, treatment records, and other health information you upload to SettleIQ are handled as attorney work product and case evidence, governed by attorney-client privilege and your ethical duties under ABA Rule 1.6 — not by HIPAA.

We recommend consulting your state bar ethics guidance and, if you have questions about HIPAA applicability in your specific practice, consulting with a healthcare law specialist.

6. Data Retention & Deletion

7. Incident Response

In the event of a security incident affecting your organization's data:

8. Audit Logging

SettleIQ maintains logs of significant user actions for security and compliance purposes:

Audit logs are retained for compliance review and are not deleted by the 90-day case shredder. Logs contain user identity (user ID, email), action type, affected resource, and timestamp. Log contents are not accessible to end users through the UI but are available to your organization upon request for compliance purposes.

9. Infrastructure

Questions about security controls or to request a security review: security@settle-iq.com