# GenieAI Security Centre: Enterprise-grade protection for your legal data

> Read how GenieAI protects your data: our ISO/IEC 27001:2022 certification, the controls behind it, how customer content is handled inside our AI features, and how to reach our security team.

**Certification:** ISO/IEC 27001:2022  
**Controls implemented:** 35  
**Last reviewed:** 30 July 2026  
**Security contact:** security@genieai.co

## Your data is private, and it stays that way

Confidentiality isn't a feature we added later, it's the assumption we built on. Every document you draft, review, or store in Genie stays yours: private by default, encrypted at rest and in transit, and never used to train AI models.

- You retain complete IP ownership of everything you upload or create. Your documents are yours.
- Privacy-aware document sharing on every plan keeps you in control of who can see each document.
- Access to customer data is restricted, logged, and reviewed.
- We're transparent about how our AI is built and trained. Read our model training policy for the detail.

## No data breaches in our history

GenieAI has never had a data breach. We work to keep it that way with independent ISO 27001 audits, AES-256 encryption, and documented incident response. If a personal data breach ever occurred, we would notify affected customers without undue delay and report it to the UK ICO where required.

## What we promise every customer

Your work belongs to you. We claim no rights over anything you upload or create, and your contracts are never used to train shared models.

You always know who handles your data. Our sub-processor list is published, kept current, and deliberately short.

We hold ourselves to the standard your clients hold you to. Access to customer data is restricted, logged, and reviewed.

## Security at a glance

- **Certification:** ISO/IEC 27001:2022, certificate 310012019, issued by Citation ISO Certification
- **SOC 2:** Not held. GenieAI does not have a SOC 2 report. ISO/IEC 27001:2022 is our independent certification
- **Hosting:** Amazon Web Services, with customer documents stored in UK and EU data centres
- **Encryption:** AES-256 at rest, TLS 1.2 or higher in transit
- **AI training on your content:** Never. Where third-party model providers process content, they operate under Zero Data Retention agreements
- **Data protection role:** For content you upload, GenieAI is the data processor and you remain the data controller
- **Compliance:** UK GDPR, EU GDPR, Data Protection Act 2018, registered with the UK ICO
- **Breach history:** No data breach in GenieAI's history
- **Security contact:** security@genieai.co, and we aim to respond within two working days

## Certifications and controls

### Never used to train AI models

Your contracts are never used to train AI models, shared or internal. Your data works for you alone.

[https://www.genieai.co/model-training](https://www.genieai.co/model-training)

### AES-256 encryption

Customer data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, so your documents are protected both in storage and on the wire.

### UK and EU GDPR compliant

We process personal data in line with the UK GDPR, the EU GDPR, and the Data Protection Act 2018, and provide a Data Processing Agreement for business customers.

[https://www.genieai.co/data-processing-agreement](https://www.genieai.co/data-processing-agreement)

### Vetted sub-processors

We work with a limited set of vetted sub-processors, and publish the full, up-to-date list so you always know who touches your data.

[https://www.genieai.co/data-subprocessors](https://www.genieai.co/data-subprocessors)

## Certified to ISO/IEC 27001:2022

GenieAI's Information Security Management System is certified to ISO/IEC 27001:2022, the international standard for information security management. Certification is not a one-off exercise: it is maintained through annual surveillance audits by an accredited external body and periodic recertification.

- **Standard:** ISO/IEC 27001:2022
- **Certificate number:** 310012019
- **Issued by:** Citation ISO Certification
- **Original approval:** 7 February 2019
- **Current certificate:** 7 February 2026
- **Expires:** 6 February 2029
- **Last external audit:** 29 April 2026
- **Last management review:** June 2026

The certificate, ISMS scope, and Statement of Applicability are available on request, under NDA where required. We do not hold a SOC 2 report: ISO/IEC 27001:2022 is our independent certification.

## Inside our control register

The controls below are part of the register behind our ISO 27001 certification. They describe how access, infrastructure, code, people, and data are managed day to day, grouped the way an auditor expects to be walked through them. The register is reviewed alongside each annual surveillance audit.

### Infrastructure security

The Genie platform is hosted on Amazon Web Services. Production access is restricted to authorised personnel, monitored, and protected by multi-factor authentication over encrypted connections only.

- **Encryption key access restricted** — Privileged access to encryption keys is restricted to authorised users with a business need.
- **Unique account authentication** — Authentication to systems and applications uses unique credentials or authorised SSH keys.
- **Production application access restricted** — System access is restricted to authorised personnel only.
- **Production database access restricted** — Privileged database access is restricted to authorised users with a business need.
- **Firewall access restricted** — Privileged firewall access is restricted to authorised users with a business need.
- **Production OS access restricted** — Privileged operating system access is restricted to authorised users with a business need.
- **Production network access restricted** — Privileged production network access is restricted to authorised users with a business need.
- **Unique network system authentication** — Production network authentication uses unique credentials or authorised SSH keys.
- **Remote access MFA enforced** — Production systems are remotely accessible only by authorised employees with a valid multi-factor authentication method.
- **Remote access encrypted** — Production systems are remotely accessible only via approved encrypted connections.
- **Infrastructure performance monitored** — Monitoring tools watch systems and infrastructure and generate alerts when predefined thresholds are met.
- **Network firewalls utilised** — Firewalls are configured to prevent unauthorised access.
- **Network and system hardening** — Hardening standards are documented, follow industry best practice, and are reviewed at least annually.

### Organisational security

The people and process controls that sit alongside the technical layer: acknowledged Code of Conduct, enforced password policy, centrally managed devices, annual security training, and quarterly access reviews.

- **Production inventory maintained** — A formal inventory of production system assets is kept up to date.
- **Code of Conduct acknowledged** — Employees acknowledge a Code of Conduct at hire. Violations are subject to a documented disciplinary policy.
- **Password policy enforced** — Passwords for in-scope system components are configured according to a documented Password Policy.
- **MDM system in use** — A mobile device management system centrally manages company-issued devices supporting the service.
- **Security awareness training** — All staff complete information security and acceptable use training at onboarding, refreshed at least annually.
- **Joiner, mover, leaver process** — Access is granted by role and removed promptly when personnel leave or change roles. Quarterly access reviews are recorded in the Access Rights Review Log.

### Product security

Encryption, monitoring, and secure development built into the platform. Customer data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, and every code change is peer reviewed before release.

- **Data encryption at rest** — Datastores housing sensitive customer data are encrypted at rest using AES-256 or equivalent.
- **Data transmission encrypted** — Confidential and sensitive data is transmitted over public networks using TLS 1.2 or higher.
- **Control self-assessments** — Self-assessments are performed at least annually to verify controls remain effective. Findings are tracked to closure within an SLA.
- **Vulnerability and system monitoring** — Vulnerability management and system monitoring are documented, with internal scanning supplemented by independent penetration testing following significant changes.
- **Secure software development** — All code changes are peer reviewed and tested. Deployment is separated from development so only authorised release managers ship to production.
- **Environment segregation** — Development, test, staging, and production environments are logically separated.

### Internal security procedures

Documented procedures for the moments that matter most. Incident response, business continuity, backups, and risk management are each owned by a named role inside the ISMS.

- **Continuity and disaster recovery** — A documented Business Continuity and Disaster Recovery Plan defines recovery priorities, communication paths, and a recovery time objective of one hour for critical services.
- **Management roles defined** — Named roles inside the ISMS oversee the design and implementation of information security controls.
- **Incident response policy** — Security and privacy incident response policies are documented and communicated to authorised users.
- **Incident management** — Incidents are logged, tracked, resolved, and communicated to affected parties through the Incident and Corrective Action Log.
- **Backup and restoration** — Critical systems and data are backed up to encrypted, redundant storage and are tested for recovery.
- **Risk management programme** — A documented risk management programme covers threat identification, risk rating, and mitigation. Risks are reviewed during ISMS management reviews.

### Data and privacy

GenieAI acts as a data processor. You remain the data controller for any personal or confidential data you upload. We comply with the UK GDPR and the Data Protection Act 2018.

- **Data retention and disposal** — Formal procedures govern the retention and secure disposal of company and customer data.
- **Data classification policy** — A data classification policy ensures confidential data is properly secured and restricted to authorised personnel.
- **Data subject rights** — Processes are in place to handle access, rectification, erasure, and objection requests within statutory timeframes.
- **Data export and deletion on exit** — On contract termination customer data can be returned or securely deleted in line with the customer agreement.

## How your data is handled inside our AI features

Genie's drafting, review, and negotiation features are powered by large language models. The questions enterprise buyers ask first are how their content is used, who can see it, and what is retained. Here is our position on each.

### No training on customer content

GenieAI does not use customer documents, prompts, or confidential data to train shared or internal AI models. Customer content is processed only to deliver the service you have contracted for.

### Zero data retention with model providers

Where Genie uses third-party language model providers to process content, currently OpenAI and Anthropic, those providers operate under Zero Data Retention agreements. Inputs and outputs are not retained by the provider after processing. Every provider is listed on our data sub-processors page.

### Processor, not controller

GenieAI acts as a data processor for content uploaded into the platform. You remain the data controller and decide what is processed, for how long, and for what purpose.

### Human and technical safeguards

Access to AI-enabled functionality is controlled through the same authentication, monitoring, and least-privilege rules that protect the rest of the platform. Risks from AI features are reviewed alongside our wider security risk process.

## Security questions, answered

### Is GenieAI ISO 27001 certified?

Yes. GenieAI's Information Security Management System is certified to ISO/IEC 27001:2022, certificate number {number}, issued by {issuer}. We were first certified in February 2019 and have maintained certification through annual surveillance audits since. The current certificate runs to {expires}, and our most recent external audit was on {audit}. The certificate, ISMS scope, and Statement of Applicability are available on request.

### Does GenieAI use my documents to train AI models?

No. GenieAI does not use customer documents, prompts, or confidential data to train shared or internal AI models. Customer content is processed only to deliver the service you have contracted for. Where third-party language model providers process content on our behalf, they operate under Zero Data Retention agreements, so inputs and outputs are not retained by the provider after processing.

### How is my data encrypted?

Customer data is encrypted at rest using AES-256 or equivalent, and in transit over public networks using TLS 1.2 or higher. Privileged access to encryption keys is restricted to authorised users with a documented business need, and that access is reviewed quarterly.

### Where is GenieAI data hosted?

The Genie platform is hosted on Amazon Web Services, with data storage in UK and EU data centres. Production systems are reachable only by authorised employees, only with multi-factor authentication, and only over approved encrypted connections. The full list of sub-processors and the regions each operates in is published on our data sub-processors page.

### Has GenieAI ever had a data breach?

No. GenieAI has never had a data breach. We maintain documented security and privacy incident response policies, and every security incident is logged, tracked, and resolved through our Incident and Corrective Action Log. If a personal data breach occurred, we would notify affected customers without undue delay, and where GenieAI is the controller, report it to the UK Information Commissioner's Office within 72 hours as the UK GDPR requires.

### Is GenieAI GDPR compliant?

Yes. GenieAI processes personal data in line with the UK GDPR, the EU GDPR, and the Data Protection Act 2018, and is registered with the UK Information Commissioner's Office. For content you upload to the platform, GenieAI acts as the data processor and you remain the data controller. We provide a standard Data Processing Agreement, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where a transfer requires them.

### Will GenieAI sign a data processing agreement?

Yes. Our standard data processing agreement includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable. Our sub-processor list is published alongside it. If your organisation needs its own DPA reviewed, email security@genieai.co and we will work through it with you.

### Does GenieAI comply with the EU AI Act?

Yes. GenieAI is not a high-risk AI system under the EU AI Act: contract drafting and review for commercial teams does not fall within the Annex III high-risk categories, so no conformity assessment or CE marking applies. The obligations that do apply to us came into force on 2 August 2026, and we meet them. Users always know they are working with an AI assistant, the product documents how it should be used, and we maintain AI literacy measures for staff operating the system. We do not engage in any of the practices the Act prohibits.

### Who owns the documents I create in GenieAI?

You do. You retain complete intellectual property ownership of everything you upload to or create in GenieAI. We claim no rights over your content, and your documents are never used to train AI models, shared or internal.

### What happens to my data if I stop using GenieAI?

On termination of your contract, your data can either be returned to you or securely deleted, in line with your customer agreement. Formal retention and disposal procedures govern both routes. You can also exercise access, rectification, erasure, and objection rights at any time, and we respond within the statutory timeframes.

### How do I request security documentation or report a vulnerability?

Email security@genieai.co. That mailbox reaches our security team directly, whether you are completing a vendor security assessment, requesting the ISO 27001 certificate under NDA, or reporting a suspected vulnerability. We aim to respond within two working days.

## Documents and policies

Most of what an enterprise security or procurement team needs is published here. Anything not public is routed by our security team, under NDA where required.

- **ISO/IEC 27001:2022 certificate** (Available on request) — The certificate itself, plus our ISMS scope and Statement of Applicability.
- [Data sub-processors](https://www.genieai.co/data-subprocessors) — Every third party involved in delivering the service, with its purpose, location, and safeguards.
- [Data Processing Agreement](https://www.genieai.co/data-processing-agreement) — Our standard DPA, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.
- [Model Training Policy](https://www.genieai.co/model-training) — How our AI is built and trained, and why your contracts are not part of it.
- [Privacy Notice](https://www.genieai.co/privacy-notice) — How GenieAI collects, uses, and protects personal information.
- [Product Terms of Use](https://www.genieai.co/product-terms-of-use) — The terms under which customers access and use the Genie platform.
- [Cookie Notice](https://www.genieai.co/cookie-notice) — The cookies we set, what each one does, and how to control them.

## Speak to the security team

Whether you are completing a vendor security assessment, reporting a suspected vulnerability, or asking about one specific control, our security team is the right contact. We aim to respond within two working days.

[Email security@genieai.co](mailto:security@genieai.co)

---

This is the Markdown representation of [https://www.genieai.co/security](https://www.genieai.co/security), provided for AI agents and crawlers. The HTML page is canonical. See [/llms.txt](https://www.genieai.co/llms.txt) for the full content map.
