Security

The security groundwork

A quiet release: nothing visible to visitors, everything underneath. This is also the date our policy pages were last touched. The two went together on purpose.

What changed

Encryption upgrade. Current standards end to end: TLS 1.3 in transit and AES-256 at rest, across every system that touches firm data — the live conversation, the stored transcript, and the attorney summary alike. No conversation travels in the clear, and no stored conversation sits in it.

Configurable data retention. The 90-day transcript default became a window each firm sets for itself, shorter or longer depending on how the firm wants to run its own records. Deletion from the dashboard became direct — a firm removes a conversation itself, on its own schedule, without filing a request and waiting on us to act on it.

Vulnerability disclosure program. Reports go to security@oculonsystems.com, with stated commitments: two-day acknowledgment, updates until resolved, credit if wanted. The program has its own page, including what is and is not in scope.

Why now

Firms hand us conversations that contain people's worst days: the injury, the arrest, the custody question after bedtime. The controls that protect those conversations should not wait for a security questionnaire.

None of this was built against a looming deadline. It was built against the alternative, which is worse: the controls arriving after an incident instead of before it.

What this does not mean

This release does not grant a certification, and we will not dress it up as one. It is groundwork. The commitments live on the disclosure page.

Share this article