Ardela
Ardela
Help Centre
Security

Security Overview

How Ardela protects legal work, recordings, and documents.

Ardela is built for legal teams in England and Wales that handle confidential client and matter information. Security combines workspace isolation, Matter-level access, encryption, approval gates, and an audit trail.

Data location and processing

Recordings and documents are hosted in the United Kingdom by default. Data is encrypted in transit and at rest.

Some transcription and AI processing is performed by approved subprocessors and is not exclusively UK-resident. Review Ardela's current Legal Centre, privacy information, and subprocessor terms when completing your firm's data protection assessment.

Workspace isolation

Each client, matter, recording, transcript, document, and Pillar belongs to a workspace. Tenant isolation is enforced at the data layer, and access is checked against the member's role and resource permissions.

Roles and sharing

Ardela provides five built-in role tiers:

RoleTypical access
OwnerWorkspace ownership, billing, and full administration
AdminWorkspace settings, members, and operational administration
MemberCreate legal work and access granted Matters
Read-onlyView existing work they can access
TranscriberWork on recordings made available through the queue

Admins can also create custom roles. Administrators do not receive a bypass of Matter content. Explicit View, Work, or Manage grants determine which files a member or group can open. Groups organise teams and can share Matters, but membership alone does not grant resource access. Clara respects the same underlying boundaries. See Matter access and Permissions and roles.

Authentication

  • Every member can protect their account with two-factor authentication
  • Enterprise workspaces can enforce MFA for members
  • Enterprise workspaces can configure SAML single sign-on
  • Session controls reduce the risk of unattended access

See Security settings.

Human approval for AI changes

Clara presents proposed changes for review. A user must approve a proposed change before Clara updates workspace content. Generated notes, documents, form fields, and review findings should be checked by an appropriately qualified person before use. Sharing work to a Matter does not approve its contents.

Ardela is not a law firm and does not provide legal advice. AI output is draft material and requires professional review.

Audit and administration

Ardela records significant administrative and product actions in an audit trail. Enterprise workspaces receive extended audit controls. Keep roles, Matter grants, groups, and inactive members under regular review.

Compliance posture

Ardela maintains an ISO 27001-aligned information security management system, but Ardela is not yet ISO 27001 certified. Do not describe Ardela as holding ISO 27001, SOC 2, or another certification unless Ardela has provided current written evidence.

For practical firm responsibilities, see UK data and compliance.

Data requests and incidents

Workspace export and deletion requests should be handled by an owner or through Ardela support. If you suspect unauthorised access, contact your workspace administrator and Ardela support promptly.

On this page