Trust and evidence
What we can show you — and when it last ran
Every claim here links to its evidence or names its limit. Each date is read from the record of the run itself, never typed into the page.
Two services, two kinds of software
The self-help service
Your documents are assembled deterministically from the answers you give and the source-locked Florida statutes. No AI model writes, phrases or reviews them — the same answers make the same document.
How the drafting worksWhat the self-help service does and refuses
For law firms
AI runs only inside a firm's own workspace, through one governed gateway — an exact list of allowed models, a monthly spending limit and a record of every call — and nothing is released as final until a licensed attorney of the firm approves that exact version.
Independent audits
No independent audit report — SOC 2, ISO 27001 or any other — has been issued for EstateDraftFL, and none is claimed. What we publish instead is below: the checks we run, what each one shows, what it does not, and when it last ran.
The evidence
Tenant isolation
- What it shows
- Every release runs the database's isolation suite against production before it is promoted: firms, matters and people are kept apart by the database itself (row-level security on every table that holds them), and each wall is tried from the wrong side.
- What it does not show
- A passing suite proves the walls it tests, on the day it ran. It is not a penetration test and not an independent audit.
Last recorded run ·
Release checks
- What it shows
- A release is promoted only after its checks pass on the exact commit: types and lint, the unit suite, the browser suite (the accessibility census, the visual baselines, the journeys), the isolation suite, the secret scan and the dependency stamp — then probed live.
- What it does not show
- Checks prove what they test on that commit; they do not prove the absence of defects. The page lists releases, not every check's output.
Last recorded run ·
Accessibility
- What it shows
- The accessibility statement: what the code enforces, what a machine checks and with which harness, what no machine here checks, and the dated limitations — each from the evidence ledger.
- What it does not show
- No human assistive-technology run has been recorded yet, and PDF copies are print copies; the statement names both.
Last recorded run ·
EstateBench
- What it shows
- The deterministic evaluation our engines are graded on — 555 of 555 checks in the committed snapshot — with the commands to run it yourself.
- What it does not show
- It grades engine behaviour on fixtures; it scores no human judgment and no live model answer, and it publishes no outcome-style metric.
Last recorded run ·
Receipts and the verifier
- What it shows
- Check that a document is exactly the one released — its fingerprint against the receipt, or a signed manifest in your own browser, with nothing sent to us.
- What it does not show
- A match proves the file is byte-for-byte the one released. It does not prove the document was signed or witnessed, that it is legally valid, or that it is complete for your purpose.
Last recorded run ·
Sub-processors
- What it shows
- Every provider that processes data for us: what it does, what reaches it, and when it is used.
- What it does not show
- An AI provider's retention is its declared policy — something we record, not something we can observe.
Last reviewed ·
Privacy and data processing
- What it shows
- What we collect and why, how long we keep it, and your rights; for firms, the data processing agreement.
- What it does not show
- A policy states our commitments; the isolation suite and the release checks are the evidence that the product keeps them.
Last reviewed ·
Capabilities and refusals
- What it shows
- What each surface does, does not do, and refuses — the self-help service and the firm platform separately — including the AI surfaces retired for consumers.
- What it does not show
- A status says what the deployment is configured for and what our checks last saw; a configured provider can still fail, and the status then says so.
Last reviewed ·
Service status
- What it shows
- The live state of each service the product depends on, read when you open the page.
- What it does not show
- Status reflects our own checks; it is not a service-level agreement.
Live ·
Backups and recovery
- What it shows
- The database is backed up by our hosting provider every day, and a restore drill rebuilds a copy in an isolated project and checks it.
- What it does not show
- Point-in-time recovery is not enabled, stored files are not yet copied to an independent backup, and a full recovery of production has not been performed.
Last recorded run ·
How these dates are made
Each date is read when the site is built, from the record it names — the isolation suite's run log, the release baseline, the accessibility ledger, the benchmark snapshot, the restore drills, and the review dates the pages carry. None is typed into this page; a newer run moves it.