General Platform & Security
Is Compass secure?
Yes. Security is a core consideration in the design and operation of Compass. Customer data is encrypted both at rest (AES-256) and in transit (TLS 1.2+), with access restricted to authorised personnel using named accounts and appropriate authentication controls. Customer data is logically segregated to prevent cross-customer access.
Compass is hosted on secure cloud infrastructure, with application data stored in the UK (London). The platform implements least-privilege access controls, restricted administrative access, monitoring and alerting, vulnerability management processes, and secure backup procedures. Compass also works with established cloud and infrastructure providers that maintain recognised security and compliance programmes.
How do you protect customer data?
Compass protects customer data through a combination of access controls, data segregation, encryption, and security monitoring. Access to Compass systems and customer data is restricted to authorised personnel using individually assigned accounts, with multi-factor authentication enabled where supported.
Customer data is logically segregated between clients to prevent unauthorised access across tenants. Data is encrypted both at rest using AES-256 encryption and in transit using TLS 1.2 or higher.
The Compass cloud environment follows security best practices, including least-privilege access controls, restricted administrative access, monitoring and alerting, vulnerability management, and regular security patching. These measures are designed to help protect customer data from unauthorised access, disclosure, alteration, and loss.
Where is customer data stored?
Customer data is stored in the UK, with Compass application data hosted on AWS infrastructure located in London. Compass uses a number of trusted cloud service providers to support the operation, security, and performance of the platform. Where AI features are enabled, relevant information may be securely transmitted to approved AI providers for processing, subject to appropriate contractual and data protection safeguards.
Is customer data encrypted in transit and at rest?
Yes. Compass encrypts customer data both at rest and in transit. Data stored within Compass is protected using AES-256 encryption, while data transmitted to and from the platform is secured using TLS 1.2 or higher.
Who has access to customer data within Class Legal?
Access to customer data is restricted to authorised personnel who require it to perform their job responsibilities. Individuals are provided with their own accounts, helping to ensure accountability and traceability of access. Multi-factor authentication (MFA) is used to provide an additional layer of security.
How do you prevent unauthorised access to Compass?
Access to Compass systems and customer data is restricted to authorised individuals with a legitimate business need. Compass uses a range of security controls, including individual user accounts, multi-factor authentication where supported, encryption, restricted administrative access, and continuous monitoring to help protect against unauthorised access.
What security monitoring and alerting is in place?
Compass uses monitoring and alerting mechanisms to help detect potential security events and maintain the security and availability of the platform. These controls are supported by additional security measures including restricted administrative access, encryption, least-privilege access controls, and vulnerability management processes.
How often do you conduct security testing?
Compass uses automated security scanning on an ongoing basis to help identify potential vulnerabilities and security issues. Findings are reviewed and prioritised based on their severity and potential impact.
Do you perform penetration testing?
Yes, we conduct penetration testing annually.
How do you manage security vulnerabilities?
Compass monitors its software and infrastructure for known security vulnerabilities. When vulnerabilities are identified, they are assessed and prioritised based on their potential impact and level of risk, with security updates and patches applied accordingly.
What happens if there is a security incident?
Compass follows a documented process for managing unexpected incidents. Issues are logged and escalated to the relevant technical teams, including third-party suppliers where necessary, to investigate and resolve the problem.
Customers may be notified where an incident affects service delivery, and all actions taken during the incident are recorded. Following resolution, the incident is reviewed to identify lessons learned and any improvements that can be implemented.
Do you have a documented incident response process?
Yes. Compass maintains a documented process for responding to security incidents and service disruptions. This includes incident logging, escalation to relevant technical teams, customer communication where appropriate, and post-incident review to help improve future response and resilience.
How are backups managed and protected?
The Compass database is backed up daily, with each backup retained for 14 days, supporting recovery from accidental change or deletion.
What business continuity and disaster recovery measures do you have in place?
Compass maintains documented business continuity and disaster recovery plans designed to help ensure service resilience and recovery in the event of an unexpected disruption. These arrangements are supported by regular database backups, incident management procedures, and coordination with key technology suppliers.
Additional business continuity and disaster recovery information can be provided during procurement or upon request.
Data Privacy & Compliance
What personal data does Compass process?
Compass processes a limited amount of personal data required to provide and administer access to the platform, including a user's name, email address, and organisation or firm name. Compass may also process platform usage information, such as login activity and interactions with the service, to support security, platform operation, and service improvement.
Is Compass GDPR compliant?
Compass is designed and operated with UK GDPR and data protection requirements in mind. Class Legal applies appropriate technical and organisational measures to protect personal data, including access controls, encryption, secure cloud hosting, data retention controls, and processes to support data deletion requests.
Compass also puts appropriate contractual measures in place with relevant sub-processors, including Data Processing Agreements and lawful international transfer mechanisms where required. Personal data is retained only for as long as necessary in accordance with applicable service terms and Class Legal's privacy policy.
Further information about Class Legal's approach to privacy and data protection can be found in our Privacy Policy.
How do you support customer privacy obligations?
Compass is designed to support customers in meeting their data protection obligations. Personal data is retained only for as long as necessary and in accordance with applicable service terms and data processing arrangements. Where appropriate, data can be deleted on request, and individuals' privacy rights are supported in line with Class Legal's Privacy Policy.
How long is customer data retained?
Data retention periods are defined in the applicable Compass service terms and data processing arrangements. In line with Class Legal's privacy policy, personal information is stored for no longer than necessary.
Can customers request deletion of their data?
Data can be deleted on request in line with those arrangements, and individuals also have the right to erasure as described in the privacy policy.
Can customers request deletion of their data?
Yes. Customers can request the deletion of their data in accordance with the applicable Compass service terms and data processing arrangements. Individuals also have the right to request erasure of their personal data, as described in Class Legal's Privacy Policy.
Do you transfer data internationally?
Customer data is primarily stored in the UK, with application data hosted on AWS infrastructure located in London. In some circumstances, such as when certain third-party services or AI features are used, data may be processed outside the UK.
Where international data transfers occur, Compass puts appropriate safeguards in place to protect personal data and complies with applicable data protection requirements. This includes the use of recognised contractual transfer mechanisms where required.
Can customers review your list of subprocessors?
Yes. Compass uses a number of carefully selected third-party service providers to support the delivery, operation, and security of the platform. An up-to-date list of subprocessors, including details of the services they provide, is available on request.
What certifications and compliance standards does Class Legal maintain?
Class Legal holds Cyber Essentials and Cyber Essentials Plus certifications. These UK-backed certifications independently assess key cybersecurity controls designed to help organisations protect against common cyber threats and secure their systems and data.
AI & Generative AI Usage
Does Compass use artificial intelligence?
Yes. Compass uses AI within its search functionality to help users research legal topics more quickly and efficiently. AI is used to support the research process and improve the relevance and usability of search results.
What type of AI technology does Compass use?
Compass uses retrieval augmented generation (RAG), a form of AI that combines large language models with relevant information retrieved from Compass to help answer legal research queries. This approach helps provide responses that are grounded in relevant source material rather than relying solely on the AI model's training data.
Does Compass use generative AI?
Yes. Compass uses generative AI as part of a retrieval augmented generation (RAG) approach. This combines large language models with relevant information retrieved by Compass, helping to generate responses that are grounded in relevant source material rather than relying solely on the model's training data.
How does AI improve legal research within Compass?
AI helps users find the information they need more quickly. Instead of relying solely on keyword searches, users can ask questions in plain English and Compass will identify relevant source material and provide a referenced answer based on that content.
Users can review the supporting sources, navigate directly to the underlying material, and continue asking follow-up questions to explore topics in more detail. This helps make legal research faster and more intuitive while keeping the source material readily accessible for verification.
Is AI used to generate legal content or provide legal advice?
No. Compass is a legal research platform and is not intended to provide legal advice.
Compass uses AI to help users locate and understand relevant information within its trusted source materials. Responses are generated using a retrieval augmented generation (RAG) approach, meaning Compass first identifies relevant content from its source materials before generating a response. It does not rely on information from the wider internet to answer research queries.
Users should always exercise their own professional judgement and review the underlying source material when using Compass for legal research.
How are AI-generated responses validated?
Compass uses a combination of technical controls and application-level checks to help improve the quality and consistency of AI-generated responses. This includes carefully designed prompts, structured processing of AI outputs, and validation within the Compass platform before results are presented to users.
Responses are also generated using relevant source material within Compass, helping to ensure that answers are grounded in trusted content rather than relying solely on the AI model's training data.
Can users verify the source of AI-generated answers?
Yes. Transparency is an important part of Compass's AI-assisted research experience. Answers generated by Compass include references to the underlying source material, allowing users to see where information has come from and navigate directly to the relevant chapter or paragraph.
This helps users independently verify results and review the original source content alongside the AI-generated response.
How does Compass reduce the risk of AI hallucinations?
Compass uses a retrieval augmented generation (RAG) approach, which grounds AI-generated responses in relevant source material rather than relying solely on the AI model's training data. Additional safeguards include prompt design, structured outputs, application-level validation checks, and human review of AI features before release.
Answers are supported by references to the underlying source material, enabling users to verify information for themselves. Compass is designed to support legal research, with professional judgement always remaining with the user.
Does Compass explain how it arrived at an answer?
Yes. Compass provides transparency into how answers are generated by clearly linking responses back to the underlying source material. Relevant sources are displayed alongside the answer, and references are included throughout the response as clickable footnotes.
Users can select these references to navigate directly to the supporting source content, making it easy to understand where the information came from and verify it for themselves.
Can AI-generated outputs be trusted for legal decision-making?
Compass is designed to support legal research and assist users in finding and understanding relevant information more efficiently. AI-generated outputs are intended to aid decision-making, not replace professional judgement.
Answers generated by Compass are linked to the underlying source material, allowing users to review and verify the supporting content for themselves. Users should always consider the context of their specific matter and apply their own professional judgement when relying on research results.
What safeguards are in place to ensure accuracy?
Compass uses a range of controls to help improve the accuracy and consistency of AI-generated responses. These include carefully designed prompts, structured processing of AI outputs, and application-level validation checks before results are presented to users.
Compass also uses a retrieval augmented generation (RAG) approach, meaning responses are generated using relevant source material rather than relying solely on the AI model's training data. Users can review the supporting references and access the underlying source content to verify information for themselves.
Can users choose whether to use AI-powered features?
Yes. Compass gives users the option to enable or disable AI-powered features. If a user does not wish to use AI-assisted functionality, these features can be switched off.
This allows users to choose the research experience that best meets their needs, whether they prefer to use AI-assisted search and answers or rely on traditional research methods within Compass.
Is customer data used to train AI models?
No. Customer data submitted through Compass is not used to train AI models. Compass uses AI providers that do not use customer inputs or outputs for model training, and routing is restricted to providers that do not collect customer data for this purpose.
Compass is designed to help protect the confidentiality of customer information when AI-powered features are used.
Customer Data Handling
Are customer queries used to train your AI models?
No. Customer queries submitted through Compass are not used to train AI models. Compass uses AI providers that do not use customer inputs or outputs for model training, and processing is restricted to providers that do not collect customer data for this purpose.
This helps ensure that information submitted through Compass remains confidential and is not incorporated into AI model training datasets.
Is customer content shared with public AI services?
No. Compass does not share customer content with public AI services for training or general use. Where AI-powered features are used, relevant information is securely transmitted to approved AI providers via encrypted connections for the sole purpose of processing the user's request.
Compass uses contractual and technical controls designed to prevent customer data from being used for AI model training. Processing is restricted to providers and endpoints that do not collect customer data for training purposes. Where data is processed outside the UK, appropriate data protection safeguards and transfer mechanisms are applied.
How is customer data separated from other customers' data?
Compass uses logical data segregation to ensure that each customer's information remains separate from that of other customers. The platform is designed so that users can only access data belonging to their own organisation, helping to prevent unauthorised cross-customer access.
Access to the underlying database is restricted to the Compass application and authorised personnel, with additional security controls in place to protect customer information.
Do AI providers retain any customer data?
Compass is designed to minimise the retention of customer data by AI providers. OpenRouter does not retain customer prompts or responses by default, and input and output logging is not enabled for Compass.
OpenRouter may retain limited technical metadata, such as token counts and request latency, to support the operation of the service. Compass also restricts AI processing to providers and endpoints that operate with zero-data-retention policies for customer content wherever available.
What contractual protections exist with AI service providers?
Compass puts contractual measures in place with its AI service providers to help ensure customer data is handled securely and is not used for AI model training. Appropriate data protection obligations are applied where required, alongside technical safeguards such as encrypted data transmission.
Where personal data is processed outside the UK, Compass uses recognised international data transfer mechanisms, including the UK IDTA and the UK Addendum to the EU Standard Contractual Clauses, where applicable.
What data is sent to AI models when a user submits a query?
When AI-powered features are used, Compass sends the information needed to process the user's request to an approved AI provider. This may include the user's query and relevant source material required to generate a response.
Compass only shares data necessary to support the requested AI functionality. Where personal data is processed outside the UK, appropriate data protection safeguards and contractual transfer mechanisms are applied.
How is sensitive or confidential information handled by AI features?
Compass applies the same security and data protection standards to its AI features as it does to the wider platform. Information sent to AI providers is transmitted using encrypted connections and is processed subject to contractual safeguards designed to protect customer data.
Compass also restricts AI processing to approved providers and endpoints that do not use customer data for model training and are configured to minimise or eliminate retention of customer content.
What controls are in place to prevent AI data leakage?
Compass uses a combination of technical, contractual, and operational controls to help protect customer data when AI features are used. Data is transmitted using encrypted connections, and Compass restricts processing to approved AI providers that do not use customer prompts or responses for model training.
In addition, Compass is configured to use non-collecting, zero-data-retention AI endpoints wherever available. OpenRouter input and output logging is not enabled for Compass, helping to minimise the retention of customer content by AI service providers.
Enterprise IT & Procurement Questions
Does Compass support Single Sign-On (SSO)?
Yes. Compass currently supports Single Sign-On (SSO) using Google accounts. Support for Microsoft SSO is planned and will be available in a future release.
Which identity providers are supported?
Compass currently supports authentication through Google. Support for Microsoft is planned and will be available in a future release.
Does Compass support Multi-Factor Authentication (MFA)?
Yes. Multi-Factor Authentication (MFA) is enabled by default for all Compass accounts, providing an additional layer of security beyond a username and password.
What user access controls are available?
Access to Compass is restricted to authorised users with individually assigned accounts. Shared accounts are not used, helping to ensure accountability and traceability of user activity. Multi-Factor Authentication (MFA) is enabled by default for all users.
User access and feature permissions are managed by the Class Legal team. Requests to add, remove, or amend user access can be submitted to Class Legal for action.
How are user permissions managed?
User permissions are managed by the Class Legal team. Changes to user access, account status, or feature availability can be requested through Class Legal, and are administered by authorised personnel.
Can Compass integrate with our existing security tools?
Compass does not currently integrate directly with customer security tools. However, users can access Compass through supported Single Sign-On (SSO) providers, helping organisations manage authentication through their existing identity platform.
Is audit logging available?
Yes. Compass maintains audit and usage logging to support platform management, security monitoring, and service improvement.
What information is included in audit logs?
Audit and usage logs may include information such as:
- Login and logout activity
- Pages viewed within Compass
- User interactions and clicks
- Source materials accessed
- Search terms submitted
These logs help support platform monitoring, security, and service improvement activities.
Can security documentation be provided during procurement?
Yes. Relevant security documentation can be provided as part of the procurement and due diligence process upon request.
Do you complete customer security questionnaires?
Yes. Class Legal routinely supports customer procurement and due diligence processes and can complete security questionnaires upon request.
Can customers review your penetration test summary?
Yes. A summary of penetration testing results may be provided upon request, subject to appropriate confidentiality considerations.
What service availability commitments do you provide?
Class Legal uses commercially reasonable endeavours to make Compass available with an uptime target of 99%.
This excludes:
- Planned maintenance, for which at least 24 hours' notice will normally be provided.
- Unscheduled maintenance, where reasonable efforts will be made to provide advance notice.
We aim to keep maintenance-related disruption to a minimum and, where maintenance is carried out during UK working hours, downtime would typically be less than one hour.
Customer support is available Monday to Friday, 9:00am to 5:30pm (UK time).
How do you manage software updates and deployments?
Compass is designed so that most software updates can be deployed without disrupting users. Where an update requires downtime or may affect service availability, customers will be informed in advance wherever possible.
Legal Research Accuracy & Trust
Where does Compass obtain its legal research content?
Compass draws on Class Legal's trusted family law resources, including its range of family law publications and content from the Financial Remedies Journal, such as articles, case reports, and blog posts.
This content forms the foundation of the research materials available within Compass and is used to support both traditional and AI-assisted research.
How current is the legal information within Compass?
Compass content is updated regularly in line with the underlying source materials. Content from Class Legal's publications is updated throughout the year, with book content typically reviewed and refreshed annually. New content from the Financial Remedies Journal, including articles, cases, and commentary, is added regularly and prioritised by publication date.
How does Compass ensure research accuracy?
Compass combines expert-authored legal content with technical safeguards designed to support accurate research outcomes.
The underlying content is written and reviewed by experienced family law specialists, with contributions subject to editorial review and verification processes. In addition, AI-generated responses are supported by controls such as prompt design, structured output processing, and application-level validation checks.
Users can also review the underlying source material referenced within answers to verify information for themselves.
Can users access the underlying source material?
Yes. All AI-generated answers and research results are linked to the underlying source material.
References are clearly displayed and can be accessed with a single click, allowing users to quickly review the original content and explore the source material in more detail.
Does Compass provide citations or references?
Yes. Compass provides fully referenced answers, with citations linking directly back to the relevant source material.
This allows users to see where information has come from and verify the underlying content for themselves.
How should legal professionals verify AI-assisted research?
AI-assisted research should always be reviewed alongside the underlying source material. Compass provides references and direct links to supporting content so that users can verify information and consider it in the context of their specific matter.
Compass is intended to support legal research and improve efficiency, but professional judgement remains essential when assessing research results.
Does Compass replace professional legal judgement?
No. Compass is designed to support legal research, not replace professional judgement.
Users should review the underlying source material and apply their own expertise and judgement when interpreting information and making decisions.
Can Compass provide legal advice?
No. Compass is a legal research tool and does not provide legal advice.
The platform is designed to help users locate relevant information and source material more efficiently. Any legal conclusions or advice should be based on a review of the underlying sources and the professional judgement of the practitioner.
How should law firms and legal teams use AI-assisted research responsibly?
Compass is designed to support responsible use of AI in legal research. AI-generated responses are intended to assist users by helping them find and understand relevant information more efficiently, but they should not be relied upon as a substitute for professional judgement.
Compass incorporates safeguards such as prompt design, feature review, structured outputs where appropriate, and references to source material to help users verify information. Legal professionals should review the underlying sources and apply their own expertise when using AI-assisted research in practice.