Security

Every case, held in confidence

Motex holds the litigation portfolios of law firms and companies. We treat them with the care of a sealed case file.

Explore Security Portal

Platform controls

Per-organization isolation

The database filters every query by the user’s organization. One organization cannot read another’s cases, even if the application gets it wrong.

No model training

Your documents and data never train or fine-tune AI models. The data processing agreement makes it an obligation.

Encrypted in transit and at rest

TLS 1.3 between the browser and the platform. Documents encrypted with AES-256 and encrypted connections required to the database.

Corporate sign-in

Microsoft Entra ID, a list of authorized emails and per-user roles. Your company’s access policies apply inside Motex too.

Activity log

Every action by a user, the agent or an automatic rule is recorded with its author, the case and the time.

Return and deletion

When the service ends, your data is returned or deleted, at your choice. Deletion is certified in writing.

Security starts in the database

Motex’s controls live in the database and the infrastructure, not in each screen. Each one is described in a versioned, dated document on the security portal.

Explore Security Portal
What data does Motex process?

The cases your organization follows: public information from the Judiciary, the documents in each case file and what your team adds, such as tasks, amounts and evidence. Motex processes it as a data processor, on your organization’s behalf.

Where is my data hosted and processed?

In the United States. The database runs on Supabase (Oregon), documents and processing functions on AWS (Virginia and Ohio) and the application on Vercel (Washington, D.C.). The database is backed up daily.

Who can see my organization’s information?

Only the users your organization authorizes, with the role it assigns them. The database enforces that boundary on every query.

Is my data used to train AI models?

No. Not to train or fine-tune any model, ours or a third party’s. It is an obligation under the data processing agreement.

What happens to my data if I stop using Motex?

It is returned or deleted, as your organization chooses, and the deletion is certified in writing.

How often is the platform’s security reviewed?

On every change: everything goes through code review, with tests and secret detection. Every week, static analysis, dynamic analysis and a secret scan of the full history also run.