LatestContext is everything in the age of legal AIRead the article
Company · Security

Built to be trusted with the work

PONS holds the documents that carry a firm’s risk, so security is not a settings page, it is the foundation. Everything is encrypted, hosted in the EU or locally on request, controlled to the individual, monitored around the clock, and written to an encrypted, timestamped audit trail, certified to SOC 2, ISO 27001, and GDPR. The full detail, reports, and sub-processors live in our security center.

§ 01 - Data & hostingSecurity

Encrypted, and regionally hosted

Every document is encrypted at rest, in transit, and at the field level, and hosted in the EU by default, or locally on request. Residency is built in, not an add-on, and your content is never used to train shared models. It is yours, and it stays yours.

  • EU-hosted by default, or local on request
  • Encrypted at rest, in transit, and per field
  • Your documents are never the product
Data, hosting, and sub-processors in the security center →
§ 02 - Access & auditSecurity

Controlled to the person. Every action on the record

Access is granted per resource, at individual, team, department, or organisation level, so people see exactly what they should and nothing more. Every action is recorded in an encrypted, timestamped audit trail, and deleted records go to a recycle bin, so mistakes are recoverable and regulators get a complete, timestamped record.

  • Fine-grained, layered permissions on every resource
  • An encrypted, timestamped audit trail on every action
  • Recovery on every record, time-limited access for outside parties
Access controls and the audit model in the security center →
Matter · Acme acquisition Controlled
SMPartnerFull accessFull
JRAssociateEditEdit
AKParalegalView onlyView
DCClient · externalThis matter · 30 daysExternal
Encrypted audit trail
10:21Granted client access · Acme
10:15Deleted NDA_04.pdfRecoverable
§ 03 - CertificationsSecurity

Independently verified, not just asserted

PONS is built and operated to recognised standards, and the controls behind them are tested by third parties. Your security team does not have to take our word for it: the reports, sub-processors, data-flow diagrams, and the full control set are published in our security center, ready to review under NDA.

EUData residency

Stored and processed in the EU by default, or locally on request. Residency is built in.

SOC 2Type II

Independently audited controls for security, availability, and confidentiality, tested over time.

ISO 27001Certified

Certified against the international standard for managing information security.

GDPRCompliant

Built to the EU standard for data protection and privacy, by default, not as an add-on.

A comprehensive security whitepaper is available on request, under NDA.

Read the SOC 2 and ISO 27001 reports in the security center →
Read the detail

Everything, in the security center