Skip to main content

Trust and security

Security and data hosting

Neutly is built for confidential ADR matters. This page summarises how we host matter data, protect party information, authenticate staff, and handle payments — in plain language. For privacy collection and use, see our privacy policy; for optional AI controls, see responsible AI.

Last updated

Where matter data is hosted today

Mediation matter data — case records, party intake, documents, session scheduling, and audit logs — is hosted in AWS ap-southeast-2 (Sydney, Australia) today.

We do not claim EU, UK, or Canadian data residency. Product design follows privacy principles aligned with GDPR and UK GDPR — encryption, access control, and audit logging — and we can discuss regional residency requirements on enterprise enquiries.

Encryption in transit and at rest

Traffic between browsers and Neutly uses TLS (HTTPS). Matter data at rest is encrypted using AWS-managed encryption on storage services we use for production deployments.

  • TLS for all web and API traffic in production.
  • Encryption at rest on object storage and database volumes in our Sydney AWS region.
  • Secrets and credentials are not stored in application source code.

Party information and intake privacy

Parties interact through secure email links — they do not need a standing login. Intake answers, position papers, and document filenames are treated as confidential matter data.

We do not send party names, intake text, or document content to external logging or analytics services. Operational logs focus on system events, not party PII.

Staff authentication and practice tenancy

Mediator and practice staff access the product through Better Auth — email and password with session management. Every domain query is scoped to the authenticated practice; client-supplied practice IDs are never trusted.

  • Role-based access within a practice (practice admin, mediator, coordinator, billing clerk, read-only partner).
  • Parties and lawyers use tokenised links for onboarding and payment — not staff accounts.
  • Co-mediators and staff see only what their role permits within their practice.

Payments and PCI scope

Party mediation fees are collected through Stripe Connect — funds go directly to your practice. Neutly does not hold client money.

Card data is handled by Stripe; we do not store raw card numbers on our servers. PCI compliance for card processing is Stripe’s responsibility under their Connect model.

Certifications and enterprise enquiries

Neutly is not ISO 27001 certified today, and we do not claim SOC 2 or other third-party security certifications unless and until we publish verified attestation.

If your procurement process requires specific residency, audit evidence, or contractual data-processing terms, contact us for enterprise enquiries — we will answer honestly about current controls and roadmap.

See also our privacy policy and responsible AI pages.