← Back to 4All.Help
Security & Trust
How we protect your data, verify every citation, and prevent the system from making things up.
The 4All.Help Promise
We do not read your documents. We do not train computer systems on your data. We do not share your information with facility staff, corrections officers, prosecutors, or any government agency. Your documents are encrypted, isolated, and yours alone.
1. Encryption
Every document you upload is encrypted before it is stored. Every connection to our servers is secured. Here is what that means in plain terms:
Your documents
Encrypted with AES-256, the same standard the U.S. military uses. Nobody can read them without your password.
Internet connection
TLS 1.3 encryption on all connections. Even if someone is watching the network, they cannot read what you send or receive.
Your password
Scrambled 600,000 times before storage. Even if our database were stolen, your password could not be recovered.
Each case file
Has its own separate encryption key. Your different cases cannot see each other.
2. AEGIS Verification System
Legal tools that make things up are dangerous. They can produce fake case citations, wrong holdings, or claims about cases that were actually overruled. We built two systems to prevent this:
AEGIS: Content Verification
Every case in our database (28,541 Utah appellate opinions) has a unique digital fingerprint. When the system cites a case, we:
- Check that the case actually exists in our verified database
- Verify the digital fingerprint has not been tampered with
- Match what the system claims the case says against the actual stored text of the opinion
If the system says a case held something it did not actually hold, the response is blocked.
AEGIS PRIME: Structural Verification
We go further than text matching. For every Utah case, we have extracted:
- The outcome (affirmed, reversed, vacated, remanded)
- Who agreed and who dissented on the panel
- Whether the case has been overruled by a later decision
- Whether a statement is binding law or just a side comment (dicta)
If the system claims a case was affirmed when it was actually reversed, the response is blocked. If the system quotes a dissenting opinion as if it were the majority ruling, the response is blocked. If the system cites a case that has been overruled, the response is blocked.
28,541 opinions verified
8,130 statutes indexed
129 overruled cases tracked
SHA-256 tamper detection
3. What Happens When the System Gets Something Wrong
No system is perfect. When ours detects a problem, here is what it does:
- Fake citation: Blocked. The response is stopped before it reaches you.
- Wrong holding: Blocked. If the system misrepresents what a case decided, it is stopped.
- Overruled case: Blocked. Cases that have been overruled are flagged and not presented as current law.
- Uncertain claim: Flagged with a warning so you know to double-check.
- Database tampered with: Immediately detected and all affected responses are blocked.
4. User Isolation
Every user's data is completely separate from every other user's data.
- Your questions and documents are stored only in your account.
- No search by any other user can access your files.
- Administrators cannot see your documents (they are encrypted).
- Each case file has its own encryption key, separate from your other cases.
5. Session Security on Shared Devices
We know that in a facility, you may be using a shared tablet or computer. We designed for this:
- 30-minute auto-logout: If you walk away, your session ends automatically.
- Complete session wipe: When you log out (or are auto-logged out), all session data, cookies, and cached content are erased from the device.
- Signed session tokens: Your login session is cryptographically signed. It cannot be forged, stolen, or reused by another person.
- No file downloads in kiosk mode: In facility deployments, file downloads are disabled to prevent documents from being left on shared devices.
6. Infrastructure
Hosting
U.S.-based data centers (DigitalOcean, SOC 2 Type II certified)
Database
Managed PostgreSQL with automated backups and encryption at rest
Server access
SSH key-only authentication. No passwords. fail2ban intrusion prevention.
Security testing
Regular penetration testing and vulnerability assessments
7. What We Do NOT Do
- We do not sell your data.
- We do not use your data for advertising.
- We do not train computer systems on your documents or questions.
- We do not share your data with facility staff, DOC, prosecutors, or any government agency without a court order signed by a judge.
- We do not access your documents — they are encrypted and we cannot read them.
- We do not log what you search for or what questions you ask.
8. Contact
Security concerns, data requests, or questions about how we protect your information:
Email: security@benchslap.pro