Chapter VerityA TSG NextGen Solutions product · Resources
PUBLIC SECURITY STATEMENT
Chapter Verity security statement
Effective July 27, 2026 · Product and demonstration environment
Security boundary
Chapter Verity separates the public demonstration from firm production environments. The public demo is for synthetic information only. Real client data is not permitted until the firm’s identity, multifactor authentication, tenant isolation, storage, retention, provider, jurisdiction, and incident-response controls have been configured and accepted in writing.
Identity and authorization
Production access is designed around named users, multifactor authentication, role-based permissions, firm tenancy, and matter-level authorization. Staff and attorney assignment changes create audit events. Administrative access and provider consent remain limited to authorized firm administrators.
Documents and evidence
Uploads enter a controlled intake path before evidence admission. The system records provenance, hashes, timestamps, review status, and reconciliation decisions. Temporary processing copies are subject to deletion controls; admitted evidence and approved work product follow the firm’s retention and legal-hold instructions.
AI controls
AI output is advisory and has no operational or legal authority. Chapter Verity is designed to minimize attribution data sent to an approved model provider, use matter-scoped context, record model and prompt receipts, cite supporting authority, and require attorney review before a recommendation or filing work product is released. Client material is not used to train a general-purpose model through Chapter Verity.
Encryption, secrets, and integrations
Transport uses HTTPS. Provider credentials belong in server-side encrypted secret stores and are not exposed to the browser. Google, Microsoft, storage, payment, signature, email, OCR, and meeting integrations remain fail-closed until their assurance gates and configuration receipts pass.
Monitoring and accountability
Security-relevant actions, evidence decisions, configuration changes, releases, and provider results are intended to produce auditable receipts. Deployment readiness is evaluated separately from feature demonstrations; a working demo control does not represent production approval.
Firm-tailored security schedule
Before production activation, Chapter Verity and the subscribing firm document the selected office suite, identity provider, storage location, jurisdictions, retention periods, incident contacts, approved integrations, data residency, and shared responsibilities in a firm-specific security schedule. Contract terms and that approved schedule control if they differ from this public summary.
Current assurance statement
This statement describes intended controls and verified product boundaries; it is not a certification, penetration-test report, warranty, or substitute for the firm’s own legal, privacy, and security review. Detailed design records remain controlled engineering and audit artifacts rather than public sales material.
Contact
Security inquiries and firm-specific review requests: tsg_team@tsgnextgen.com.