Security

Engineered for clients whose IT review actually has questions.

The case materials uploaded for a Mootly session are among the most sensitive documents your firm or program possesses. We treat them that way. This page is the high-level overview.

Data handling

Where your documents live

Uploaded briefs and supporting documents are stored in a private, access-controlled bucket and are readable only by the account that uploaded them, through short-lived signed links. The text we extract from them, the case profile built from it (the tension map and anticipated questions), and each hearing’s transcript are kept with the matter so you can practise the same motion more than once and review past hearings.

Deletion

Deleting a matter removes its documents, extracted text, case profile and hearing records. Retention controls for organisations are on the roadmap and are not yet available; today, data is kept until you delete it.

No model training on customer data

Customer-uploaded materials are never used to train Mootly’s models or any third party’s models. Our model providers are used under API terms that exclude training on our inputs.

Encryption

All data in transit is encrypted with TLS. Data at rest is encrypted by our hosting providers. The audio for live sessions travels over an encrypted WebRTC connection.

Access control

Every account is verified by email and approved by Mootly before it can open a hearing. Organisations can be set up so that members are approved together, and each practitioner sees only their own matters and debriefs. Single sign-on is on the roadmap and is not yet available.

Talk to your IT team

Hand them this page. They’ll know what to ask next.

Request a demo