BundleCreator.co implements comprehensive security measures to protect your sensitive legal documents with multiple layers of defence, aligned with UK GDPR and legal professional privilege.
Quick Answer
BundleCreator protects legal documents with AES-256 encryption at rest, TLS 1.3 in transit, UK-hosted infrastructure in the europe-west2 (London) region, and defence-in-depth including Clerk authentication with optional MFA, row-level security in PostgreSQL, CSRF protection, rate limiting, and 7-year audit logging. The platform is tested against the OWASP Top 10 and aligned with UK GDPR and legal professional privilege.
Defence-in-depth security architecture • UK-based infrastructure • Full audit trails
A 90-second walkthrough of where your bundles live, who can reach them, and how they're protected.

Knowing the Boundary
Stored and processed in the UK, hosted on Google Cloud Run in the London region. AES-256 at rest, TLS 1.3 in transit, UK GDPR and Data Protection Act 2018, ICO-regulated. Particular reassurance for sensitive cases — domestic abuse, public children law, redacted documents.
Comprehensive security measures at every level to safeguard your confidential legal documents
Your bundles are assembled entirely in your browser. The server never sees your assembled bundle contents, ensuring maximum privacy for privileged documents.
Your documents are protected with AES-256 encryption at rest and comprehensive access controls.
Enhanced identity verification protecting Legal Professional Privilege with additional authentication layers.
Multiple independent security layers ensure your documents remain protected even if one layer is compromised.
Transparent internal review: our own security review documents coverage of the OWASP Top 10, with findings remediated and test results published internally. This is an in-house assessment, not an independent certification.
Defence in depth
Layered
UK-hosted infrastructure
BundleCreator does not use customer documents, bundles, or case details to train AI models — ours or any third party’s. The Mind Map feature uses Claude with zero data retention and client-side PII stripping before any text leaves your browser. Read Aloud uses Google Cloud Text-to-Speech, which does not train on content. Document OCR runs entirely on your device via Tesseract.
Read the full AI transparency statement →Training on your data
Never
Zero data retention with Anthropic
Multiple independent layers of protection safeguard your sensitive legal documents
Unlike single-layer security approaches, our defence-in-depth architecture implements multiple independent security controls at every level. If one layer is compromised, additional layers continue protecting your data. This professional multi-layered approach ensures your sensitive legal documents remain secure even against sophisticated threats.
Security controls implemented based on ISO 27001:2022 Annex A framework. Formal certification audit scheduled Q2 2026.
Trust Service Criteria framework adopted with professional security controls. Formal audit planned Q2 2026.
Current Status: Professional security controls implemented, working towards formal certification
Designed around recognised standards for legal data protection, with a clear roadmap for formal certification
Data handling practices aligned with UK data protection law
Working towards certification. Trust Services Criteria framework adopted. Formal audit planned Q2 2026.
Working towards certification. Security controls based on Annex A framework. Formal audit Q2 2026.
Privacy by design: Your bundles are assembled in your browser. The server never sees your assembled bundle contents.
How it works: When you create a bundle, encrypted documents are downloaded to your browser, decrypted and assembled entirely on your device, and optionally password-protected before being saved to your computer. This privacy-preserving architecture ensures your privileged legal documents remain confidential throughout the entire process.
Transparent self-assessment: our own security review covers the OWASP Top 10 risks. Findings are documented internally and remediated. This is an in-house assessment, not an independent certification.
Yes, we're cloud-based but we don't have to be. Contact us about our Enterprise solutions.
Our technology can be housed within your secure environment, for the ultimate assurance.
We deliver secure, state-of-the-art innovation with clean, modern designs.
Get in touch
Tailored solutions for law firms requiring maximum control and security
All our critical infrastructure providers maintain recognised security certifications (SOC 2, ISO 27001, Cyber Essentials), independently audited and verified:
Supply Chain Security: All critical infrastructure providers reviewed and verified on 5th November 2025 as part of our ISO 27001:2022 A.5.22 control implementation
BundleCreator is designed to meet all 14 National Cyber Security Centre Cloud Security Principles, demonstrating our commitment to UK government security standards.
| Principle | Status |
|---|---|
| 1. Data in Transit Protection | Compliant |
| 2. Asset Protection & Resilience | Compliant |
| 3. Separation Between Customers | Compliant |
| 4. Governance Framework | Compliant |
| 5. Operational Security | Compliant |
| 6. Personnel Security | Compliant |
| 7. Secure Development | Compliant |
| 8. Supply Chain Security | Compliant |
| 9. Secure User Management | Compliant |
| 10. Identity & Authentication | Compliant |
| 11. External Interface Protection | Compliant |
| 12. Secure Service Administration | Compliant |
| 13. Audit Information for Users | Compliant |
| 14. Secure Use of the Service | Compliant |
All user data stored exclusively in London, UK data centres (europe-west2). No data transfer outside the United Kingdom.
Multiple independent security layers at network, application, and data levels ensure protection even if one layer is compromised.
Comprehensive audit logs retained for 7 years to meet UK legal requirements. Tamper-evident logging architecture.
Reference: NCSC Cloud Security Principles • G-Cloud 15 Framework (RM1557.15)
Complete transparency with detailed audit trails for every action
Our comprehensive activity log provides complete visibility into all bundle activities, essential for compliance, security audits, and team collaboration.
Note: All activity logs are immutable and retained for record-keeping purposes. Logs can be exported for security audits or legal requirements.
Important Note: While your documents are protected with industry-standard encryption at rest and in transit, authorised system administrators may access data for support and maintenance purposes under strict confidentiality agreements.