Security & Trust

Built for the Most Confidentiality-Sensitive Industry in the World

Law firms cannot afford a security compromise. We built Sorush from the ground up with that non-negotiable truth as our first design principle — not an afterthought.

🏛️
VPC-Native
Runs inside your Azure tenant
🔍
Background Badge
Industry-first AI certification
📋
SOC 2 Type II
Certified in Q3 2026
No-Hallucination
Guarantee on routine tasks
Data Residency

Your Data Never Leaves Your Environment. Full Stop.

The single most important security decision we made: the entire Sorush stack — LLM inference, voice processing, memory storage, RAG pipeline, and integration connectors — runs inside your firm's own Azure Virtual Network.

We do not send your clients' calls to a third-party cloud. We do not store your firm's data on our servers. We do not have access to your conversations. You own the keys. You control the environment. We provide the infrastructure blueprint and the managed deployment.

  • Deployed via Terraform into your Azure subscription
  • All LLM inference via private Azure endpoint
  • No external API calls with firm data
  • Encryption at rest: AES-256 (Azure Storage SSE)
  • Encryption in transit: TLS 1.3
  • Data residency fully under your firm's control
Architecture: Data Flow
[ Incoming Call ]
→ Your Azure VNet boundary
→ Voice Gateway (SIP/PBX)
→ Orchestration Engine
→ DeepSeek LLM (private)
→ Qdrant Vector DB
→ Cosmos DB Memory
→ Response to caller
✓ Zero data egress at every step
Industry First

The AI Background Check Badge

When you hire a human receptionist, you run a background check. You should expect the same accountability from a digital one handling your clients' confidential legal matters.

Every Sorush agent receives our Background Check Badge — a documented certification that the agent has been:

  • Data access scoped and verified (reads only what it needs)
  • Behavior tested against scripted and adversarial scenarios
  • Output audited for accuracy on routine legal intake tasks
  • Escalation paths tested to confirm proper human handoff
  • PII handling verified against firm's redaction policy

We partner with background verification vendors to provide verifiable, third-party documentation of this certification for every deployment.

🛡️
Background Certified
Agentic Employee, Inc.
Trust Standard: Human-Equivalent
Issued per deployment
Compliance

Enterprise-Grade Compliance Standards

📋

SOC 2 Type II

Agentic Employee is pursuing SOC 2 Type II certification, covering Security, Availability, and Confidentiality trust service criteria. Target certification: Q3 2026. Audit logs are immutable and available for export at any time.

🔐

Encryption Standards

AES-256 encryption for all data at rest via Azure Storage Service Encryption. TLS 1.3 enforced for all data in transit. No unencrypted data pathways exist in the architecture.

👤

Role-Based Access Control

The Sorush client dashboard supports Admin, Manager, and Viewer roles. All actions are logged with timestamp and user attribution. Azure AD SSO with MFA enforced for all dashboard access.

📝

Immutable Audit Logs

Every agent action, every call, every dashboard change is logged immutably. Logs are available for export and are retained according to your firm's specific legal hold requirements.

Accuracy Guarantee

We Guarantee Sorush Won't Invent Answers

The failure mode of most AI tools in legal settings is hallucination — confidently stating something false. This is unacceptable in a law firm context where a wrong answer about a deadline, a case status, or a fee arrangement can cause real harm.

Our guardrail enforcer monitors every response Sorush generates. When confidence falls below our threshold on any factual query, Sorush is forced to respond: "I don't have that information — let me connect you with someone who does."

We back this with a no-hallucination guarantee on routine tasks — including call answering, FAQ responses, and scheduling. If Sorush fabricates an answer that we can verify was outside its knowledge base, we own it.

How the Guardrail Works

1
Intent classifiedEvery caller query is classified before a response is generated.
2
Confidence scoredThe orchestration layer scores how well the retrieved context supports the answer.
3
Threshold enforcedBelow-threshold responses are replaced with a graceful human handoff — never an invented answer.
Legal Ethics

Designed Around ABA Model Rules

Sorush is designed to complement — not create tension with — attorneys' professional responsibility obligations. Our design explicitly accounts for the rules most relevant to front-desk AI.

Rule 1.6 — Confidentiality

Sorush never transmits client information outside the firm's VPC. All data remains inside the attorney-client privileged environment. No third-party SaaS has access to your calls or data.

Rule 5.3 — Supervision of Non-Lawyers

Sorush operates under direct attorney oversight via the dashboard. Supervising attorneys can review every interaction, update scripts in real time, and disable specific capabilities with one click.

No Legal Advice — By Design

Sorush is hardcoded to never dispense legal advice, legal opinions, or case predictions. It transfers any substantive legal question to the attorney — without exception.

Conflicts Screening

During intake, Sorush can collect conflict screening information as directed by the firm, and routes potential conflict matters to the appropriate attorney before any privileged information is disclosed.

Security Questions? Talk to Our Team.

We are happy to walk your managing partner or IT team through the full architecture before any commitment.

Schedule a Security Review →