Trust center

Security and control

Cannon is designed to keep case access explicit, analysis inspectable, and consequential actions under lawyer control.

Default case access
Firm only
External sharing
Case scoped
AI output
Attorney reviewed

Scoped access

Firm and client roles are separate. New cases begin firm-only, and client access is granted per case and contributor.

Verified sharing

Work-email verification is required before a user can invite firm members or share client access.

Source-grounded analysis

Record-based answers expose citations so lawyers can inspect the supporting file and excerpt.

Human approval

AI output is assistive. Lawyers remain responsible for reviewing facts, citations, redactions, strategy, and work product before use.

Operational boundaries

Firm notes and drafts stay outside client-upload views. Server-side permissions and evaluation limits remain authoritative.

Issue reporting

Report suspected unauthorized access, data exposure, or security concerns promptly through the contact channel below.

Security contact

Use the contact form and identify the message as a security concern so it can be prioritized.