01

Infrastructure Security

02

Data Architecture

03

AI and Data Privacy

Crucible offers three AI review tiers. Each has different data handling characteristics. We are precise about this because your firm's data governance policy depends on it.

Fast Review — No Third-Party Transmission

Fast Review uses Llama 3.1 8B running on Crucible's dedicated GPU infrastructure. Your documents are processed entirely within Crucible's environment. No document content is transmitted to Meta, OpenAI, Anthropic, or any third party during Fast Review. This makes Fast Review suitable for the most sensitive matters.

Quality Review — No Third-Party Transmission

Quality Review uses a multi-model ensemble running on Crucible's infrastructure. Like Fast Review, all document processing occurs within Crucible's environment. No document content is transmitted to any third party.

Perfect Review — Third-Party API

Perfect Review uses Anthropic's Claude API for maximum accuracy on high-stakes matters. Document content is transmitted to Anthropic and processed under Anthropic's enterprise data protection terms. Anthropic does not train on API data by default. Perfect Review should be evaluated against your firm's data governance policies for highly sensitive matters.

Every AI coding decision — regardless of tier — is logged immutably with model version, timestamp, confidence score, and the full decision record. AI decisions never overwrite attorney decisions. They are stored as separate layers in the immutable stack.

04

Access Controls

05

Audit and Chain of Custody

The audit architecture is not a feature bolted onto Crucible. It is the mechanism by which Crucible operates. The database is an append-only event log. Current state is derived by replaying events — never stored as mutable state.

06

Compliance

07

Third-Party Dependencies

Crucible Discovery depends on the following third-party services. We link to their security documentation for your review.

Service Purpose Certifications
Stripe Payment processing PCI DSS Level 1
Clerk Authentication & identity SOC 2 Type II
MongoDB Atlas Database SOC 2 Type II, ISO 27001
Cloudflare R2 Object storage SOC 2 Type II, ISO 27001
Anthropic Perfect Review AI Enterprise API terms
Vultr Cloud infrastructure SOC 2 Type II
08

Reporting Security Issues

If you discover a security vulnerability in Crucible Discovery, we encourage responsible disclosure.

Report security issues to security@cruciblediscovery.com.

We respond to all security reports within 24 hours. We will work with you to understand the issue and coordinate disclosure. We do not pursue legal action against researchers who report vulnerabilities responsibly.

09

Questions

If your firm requires a security questionnaire, penetration test results, or a custom security review, contact us at security@cruciblediscovery.com.

We respond to all security inquiries within one business day.