Chapter VerityA TSG NextGen Solutions product · Resources PUBLIC SECURITY STATEMENT

Chapter Verity security statement

Effective July 27, 2026 · Product and demonstration environment

Security boundary

Chapter Verity separates the public demonstration from firm production environments. The public demo is for synthetic information only. Real client data is not permitted until the firm’s identity, multifactor authentication, tenant isolation, storage, retention, provider, jurisdiction, and incident-response controls have been configured and accepted in writing.

Identity and authorization

Production access is designed around named users, multifactor authentication, role-based permissions, firm tenancy, and matter-level authorization. Staff and attorney assignment changes create audit events. Administrative access and provider consent remain limited to authorized firm administrators.

Documents and evidence

Uploads enter a controlled intake path before evidence admission. The system records provenance, hashes, timestamps, review status, and reconciliation decisions. Temporary processing copies are subject to deletion controls; admitted evidence and approved work product follow the firm’s retention and legal-hold instructions.

AI controls

AI output is advisory and has no operational or legal authority. Chapter Verity is designed to minimize attribution data sent to an approved model provider, use matter-scoped context, record model and prompt receipts, cite supporting authority, and require attorney review before a recommendation or filing work product is released. Client material is not used to train a general-purpose model through Chapter Verity.

Encryption, secrets, and integrations

Transport uses HTTPS. Provider credentials belong in server-side encrypted secret stores and are not exposed to the browser. Google, Microsoft, storage, payment, signature, email, OCR, and meeting integrations remain fail-closed until their assurance gates and configuration receipts pass.

Monitoring and accountability

Security-relevant actions, evidence decisions, configuration changes, releases, and provider results are intended to produce auditable receipts. Deployment readiness is evaluated separately from feature demonstrations; a working demo control does not represent production approval.

Firm-tailored security schedule

Before production activation, Chapter Verity and the subscribing firm document the selected office suite, identity provider, storage location, jurisdictions, retention periods, incident contacts, approved integrations, data residency, and shared responsibilities in a firm-specific security schedule. Contract terms and that approved schedule control if they differ from this public summary.

Current assurance statement

This statement describes intended controls and verified product boundaries; it is not a certification, penetration-test report, warranty, or substitute for the firm’s own legal, privacy, and security review. Detailed design records remain controlled engineering and audit artifacts rather than public sales material.

Contact

Security inquiries and firm-specific review requests: tsg_team@tsgnextgen.com.