Security

Your documents are confidential. We treat them that way.

Sopal is built for legal and construction professionals who work with sensitive commercial and legal material. Here is exactly how we handle your data, who can access it, and how we protect it.

Encryption in transit and at rest

All data moving between your browser and Sopal's servers is encrypted via TLS. Data stored on our infrastructure — documents, account records, usage logs — is encrypted at rest.

Your data is yours

Documents you upload are used only to generate your results. They are scoped to your account, never shared across accounts, and never used to train external AI models.

Access controls

Our team operates on a need-to-know basis. Access to production systems and customer data is limited to personnel who require it to operate and support the platform.

Data handling

What happens to the documents you upload

When you upload a payment claim, payment schedule, or contract document into Sopal Projects, or when you supply material for AI research in Sopal Research, that content is processed to produce your result and stored against your account. It is not visible to other Sopal subscribers, not sold or licensed to third parties, and not made available to any public AI training corpus.

AI processing — no training on your data

Sopal uses large language model (LLM) APIs to power its AI research and document-review features. The AI providers we use are engaged on terms that prohibit them from using API input data to train or improve their general models. Your documents go in, your results come out — the model does not retain or learn from your content beyond that processing call.

This is a material distinction from consumer AI products where content submitted through a free or consumer interface may be used for model improvement. Sopal's AI usage is API-tier, not consumer-tier, and is subject to the data-processing terms of our provider agreements.

Retention and deletion

Your uploaded documents and generated outputs remain associated with your account for as long as your account is active, so you can reference previous research and claims. If you close your account, we honour deletion requests for your personal and organisational data in accordance with our Privacy Policy. Contact info@sopal.com.au to initiate a deletion request.

Log data and analytics

We collect standard server-side logs (request metadata, timestamps, errors) and product-usage analytics to operate and improve the platform. This is metadata about how the product is used, not the content of your documents or research queries. Log data is retained for a defined period for operational and security purposes, after which it is deleted.

Search and database queries

Queries you make against the Queensland adjudication decision database (7,300+ decisions) are processed server-side and are not disclosed to third parties. Search history is associated with your account and is not shared.

Infrastructure

Hosted on managed, access-controlled cloud infrastructure

Sopal runs on reputable managed cloud hosting with layered access controls, automated backups, and separation between production and development environments.

  • TLS encryption on all connections — no unencrypted HTTP in production
  • Encrypted storage for all databases and document stores
  • Production access restricted to authorised personnel via credential-gated pathways
  • Automated database backups with point-in-time recovery capability
  • Development and staging environments separated from production data
  • Australian data residency available — contact us to discuss your requirements
Infrastructure overview
TransitTLSEnforced
StorageEncrypted at rest
AccessNeed-to-knowGated
BackupsAutomated
Account security

Protecting your account

Sopal accounts are protected by password authentication with enforced minimum-complexity requirements. Passwords are stored using one-way cryptographic hashing — we do not store your password in a form that could be read back, and neither our team nor any third party can retrieve your password from our systems.

Sessions

Authenticated sessions are managed via secure, HTTP-only, signed session tokens. Sessions expire automatically after a period of inactivity. If you believe your account has been accessed without your authorisation, contact info@sopal.com.au immediately so we can revoke active sessions and investigate.

Team and organisation accounts

Sopal Plus and team arrangements provide account-level access for your organisation. Access is controlled by the account owner. If a team member leaves, it is the account owner's responsibility to revoke their access. We recommend reviewing active users periodically. Contact us if you need assistance managing team access.

What to do if you suspect a breach

If you suspect your Sopal credentials have been compromised, change your password immediately and contact info@sopal.com.au. We will assist you in reviewing account activity, revoking sessions, and assessing any impact. We take account security incidents seriously and will respond promptly.

Your responsibilities

Sopal's security controls work best when paired with good credential hygiene on your end. We recommend using a strong, unique password for your Sopal account, using a reputable password manager, and not sharing your login credentials with colleagues — use team/organisation account arrangements instead.

Confidentiality

Built for legal and construction professionals

Sopal Research is used by construction lawyers, barristers, and in-house counsel who work with privileged material and commercially sensitive contracts. Our data-handling approach reflects that context.

  • Your documents are never shared across accounts
  • AI providers process your content under API data-processing terms, not consumer terms
  • No content is used to train or improve public AI models
  • Staff access to production data is restricted and logged
  • Deletion requests are honoured on account closure
  • Queries and research history are private to your account
Account access check
Certifications and assurance

An honest stance on compliance and certifications

We want to be straightforward with procurement teams and IT reviewers: Sopal currently follows recognised security practices but does not hold formal third-party certifications such as SOC 2 Type II or ISO/IEC 27001. We will not claim certifications we do not hold.

What we do

  • Encryption in transit (TLS) and at rest for all stored data
  • Password storage via one-way cryptographic hashing
  • Role-based, need-to-know access controls for production systems
  • Separation of production and non-production environments
  • Automated database backups
  • AI provider agreements that prohibit use of API data for model training
  • Documented incident response process for account and data security events

Our roadmap

We are building toward recognised third-party assurance. If your organisation requires a specific certification or audit as a condition of use, please contact us at info@sopal.com.au to discuss the timeline and whether a contractual arrangement or information security questionnaire can bridge the gap in the interim.

Vendor security questionnaires

If your organisation requires a completed vendor security questionnaire or information security assessment, we are happy to work through that with you. Email info@sopal.com.au with your questionnaire and your timeframe and we will respond as promptly as we can.

Sub-processors

Sopal uses a small number of third-party service providers (sub-processors) to operate the platform — cloud hosting, AI inference APIs, and operational tooling. We do not publish a full sub-processor list publicly, but we are happy to discuss our sub-processor arrangements with enterprise customers on request. All sub-processors are engaged on data-processing terms consistent with our obligations to you.

Vulnerability disclosure

Responsible disclosure

If you discover a security vulnerability in Sopal, please report it to us responsibly before disclosing it publicly. Email info@sopal.com.au with a description of the issue, steps to reproduce it, and the potential impact as you understand it. We will acknowledge your report promptly and work to address confirmed vulnerabilities as a priority.

We ask that you do not exploit a vulnerability beyond what is necessary to demonstrate it, do not access or modify other users' data, and allow us reasonable time to investigate and remediate before any public disclosure. We appreciate responsible researchers who help us keep Sopal secure.

FAQ

Questions, answered.

Are my uploaded documents used to train AI models?

No. Documents you upload to Sopal are processed to generate your results and stored against your account. They are not used to train or improve public AI models. Sopal uses AI via API-tier agreements that include provisions prohibiting the use of API input data for model training. This is a meaningful distinction from consumer AI products where submitted content may be used for model improvement.

Can Sopal staff read my documents?

Access to production systems and customer data is restricted to a small number of authorised personnel who need it to operate and support the platform. This access is gated and limited to what is operationally necessary. We do not routinely read customer documents, and access events are logged.

Where is my data stored? Is it in Australia?

Sopal's infrastructure is hosted on managed cloud services. We are happy to discuss data residency requirements with your organisation — contact info@sopal.com.au if Australian data residency is a requirement and we will provide current information about our hosting arrangements.

Does Sopal hold SOC 2 or ISO 27001 certification?

Not currently. We follow recognised security practices — encryption in transit and at rest, role-based access controls, secure credential storage, AI provider agreements that prohibit training on API data, and documented incident response — but we do not yet hold formal third-party certifications. We are building toward recognised assurance and are happy to discuss our roadmap with procurement teams. If you have a vendor security questionnaire, please send it to info@sopal.com.au.

What happens to my data if I close my account?

If you close your account, we honour deletion requests for your personal and organisational data in accordance with our Privacy Policy. To initiate a deletion request, contact info@sopal.com.au. Some data may be retained for a limited period where required by law or for fraud prevention, after which it is deleted.

Is my payment information secure?

Sopal uses a reputable third-party payment processor. We do not store your full card details on our systems — payment processing is handled by the payment provider directly. Your billing information is subject to both our Privacy Policy and the security standards of our payment processor.

Can my colleagues see my documents and research?

Documents and research you conduct in Sopal are scoped to your account. In a team or organisation arrangement, access is controlled at the account level as configured by the account owner. If you are unsure how access is configured for your team, speak to your account administrator or contact us.

How do I report a security vulnerability?

Email info@sopal.com.au with a description of the vulnerability, reproduction steps, and your assessment of the impact. We will acknowledge your report promptly and treat it as a priority. Please allow us reasonable time to investigate and remediate before any public disclosure.

Security questions? Talk to us directly.

If you are a procurement team, IT reviewer, or legal practice manager with specific security or compliance requirements, we would rather answer your questions honestly than have you rely on a data sheet. Reach us at info@sopal.com.au or start a trial and ask us from inside the platform.

Start 14-day free trial