Security Overview
How Ardela protects legal work, recordings, and documents.
Ardela is built for legal teams in England and Wales that handle confidential client and matter information. Security combines workspace isolation, Matter-level access, encryption, approval gates, and an audit trail.
Data location and processing
Recordings and documents are hosted in the United Kingdom by default. Data is encrypted in transit and at rest.
Some transcription and AI processing is performed by approved subprocessors and is not exclusively UK-resident. Review Ardela's current Legal Centre, privacy information, and subprocessor terms when completing your firm's data protection assessment.
Workspace isolation
Each client, matter, recording, transcript, document, and Pillar belongs to a workspace. Tenant isolation is enforced at the data layer, and access is checked against the member's role and resource permissions.
Roles and sharing
Ardela provides five built-in role tiers:
| Role | Typical access |
|---|---|
| Owner | Workspace ownership, billing, and full administration |
| Admin | Workspace settings, members, and operational administration |
| Member | Create legal work and access granted Matters |
| Read-only | View existing work they can access |
| Transcriber | Work on recordings made available through the queue |
Admins can also create custom roles. Administrators do not receive a bypass of Matter content. Explicit View, Work, or Manage grants determine which files a member or group can open. Groups organise teams and can share Matters, but membership alone does not grant resource access. Clara respects the same underlying boundaries. See Matter access and Permissions and roles.
Authentication
- Every member can protect their account with two-factor authentication
- Enterprise workspaces can enforce MFA for members
- Enterprise workspaces can configure SAML single sign-on
- Session controls reduce the risk of unattended access
See Security settings.
Human approval for AI changes
Clara presents proposed changes for review. A user must approve a proposed change before Clara updates workspace content. Generated notes, documents, form fields, and review findings should be checked by an appropriately qualified person before use. Sharing work to a Matter does not approve its contents.
Ardela is not a law firm and does not provide legal advice. AI output is draft material and requires professional review.
Audit and administration
Ardela records significant administrative and product actions in an audit trail. Enterprise workspaces receive extended audit controls. Keep roles, Matter grants, groups, and inactive members under regular review.
Compliance posture
Ardela maintains an ISO 27001-aligned information security management system, but Ardela is not yet ISO 27001 certified. Do not describe Ardela as holding ISO 27001, SOC 2, or another certification unless Ardela has provided current written evidence.
For practical firm responsibilities, see UK data and compliance.
Data requests and incidents
Workspace export and deletion requests should be handled by an owner or through Ardela support. If you suspect unauthorised access, contact your workspace administrator and Ardela support promptly.
