This page documents Crucible Discovery's security architecture, data handling practices, and compliance posture. It is written for IT departments, general counsel, and security reviewers — not marketing audiences.
Crucible offers three AI review tiers. Each has different data handling characteristics. We are precise about this because your firm's data governance policy depends on it.
Fast Review uses Llama 3.1 8B running on Crucible's dedicated GPU infrastructure. Your documents are processed entirely within Crucible's environment. No document content is transmitted to Meta, OpenAI, Anthropic, or any third party during Fast Review. This makes Fast Review suitable for the most sensitive matters.
Quality Review uses a multi-model ensemble running on Crucible's infrastructure. Like Fast Review, all document processing occurs within Crucible's environment. No document content is transmitted to any third party.
Perfect Review uses Anthropic's Claude API for maximum accuracy on high-stakes matters. Document content is transmitted to Anthropic and processed under Anthropic's enterprise data protection terms. Anthropic does not train on API data by default. Perfect Review should be evaluated against your firm's data governance policies for highly sensitive matters.
Every AI coding decision — regardless of tier — is logged immutably with model version, timestamp, confidence score, and the full decision record. AI decisions never overwrite attorney decisions. They are stored as separate layers in the immutable stack.
The audit architecture is not a feature bolted onto Crucible. It is the mechanism by which Crucible operates. The database is an append-only event log. Current state is derived by replaying events — never stored as mutable state.
Crucible Discovery depends on the following third-party services. We link to their security documentation for your review.
| Service | Purpose | Certifications |
|---|---|---|
| Stripe | Payment processing | PCI DSS Level 1 |
| Clerk | Authentication & identity | SOC 2 Type II |
| MongoDB Atlas | Database | SOC 2 Type II, ISO 27001 |
| Cloudflare R2 | Object storage | SOC 2 Type II, ISO 27001 |
| Anthropic | Perfect Review AI | Enterprise API terms |
| Vultr | Cloud infrastructure | SOC 2 Type II |
If you discover a security vulnerability in Crucible Discovery, we encourage responsible disclosure.
Report security issues to security@cruciblediscovery.com.
We respond to all security reports within 24 hours. We will work with you to understand the issue and coordinate disclosure. We do not pursue legal action against researchers who report vulnerabilities responsibly.
If your firm requires a security questionnaire, penetration test results, or a custom security review, contact us at security@cruciblediscovery.com.
We respond to all security inquiries within one business day.