Scoped access
Firm and client roles are separate. New cases begin firm-only, and client access is granted per case and contributor.
Cannon is designed to keep case access explicit, analysis inspectable, and consequential actions under lawyer control.
Firm and client roles are separate. New cases begin firm-only, and client access is granted per case and contributor.
Work-email verification is required before a user can invite firm members or share client access.
Record-based answers expose citations so lawyers can inspect the supporting file and excerpt.
AI output is assistive. Lawyers remain responsible for reviewing facts, citations, redactions, strategy, and work product before use.
Firm notes and drafts stay outside client-upload views. Server-side permissions and evaluation limits remain authoritative.
Report suspected unauthorized access, data exposure, or security concerns promptly through the contact channel below.
Review the current disclosures for processing providers, retention, encryption, incident response, deletion, and AI-use boundaries:
Material service or security incidents are communicated directly to affected customers under the applicable agreement and legal obligations.
Report suspected unauthorized access, data exposure, or security vulnerabilities directly. Do not include case documents or sensitive evidence in the first message.