Closeout
Demo

Security

Built for your most sensitive matters.

Your clients trust you with their settlements and their health records. Closeout protects that trust at every layer, encrypted, isolated to your firm, and recorded down to the last action.

Monolithic concrete blocks, conveying strength and permanence

Protection at every layer

Enterprise-grade controls, built in from the start.

Purpose-built for PHI

Closeout is built for the most sensitive records a firm handles: medical bills, EOBs, settlement figures, and trust disbursements. Protection is designed in, not bolted on.

Encrypted end to end

Every document and record is encrypted at rest with AES-256, and all traffic between your browser and our servers is protected by TLS 1.2 or higher.

Isolated per firm

Your firm's data never touches another's. Isolation is enforced in application code on every read and write, and again at the database with forced PostgreSQL row-level security.

No model training

AI extraction runs under a Business Associate Agreement on a zero-retention basis. Your client data is never used to train shared, public, or third-party models.

Tamper-evident record

Every action is logged with the actor, timestamp, IP, and exactly what changed, a defensible, tamper-evident audit trail aligned with ABA Rule 1.15.

Least-privilege access

Role-based access, Firm Admin, Attorney, and Case Manager, gives each person only what their role needs. Internal production access follows least privilege.

Where we stand

Candid about our compliance posture.

We hold ourselves to a simple rule: we don't claim controls we don't have. Here's exactly what's in place today, and what's in motion.

HIPAA

In place

PHI is handled as a business associate under a signed Business Associate Agreement, with controls aligned to HIPAA.

SOC 2 Type II

In progress

Built to SOC 2 standards, with an audit engagement underway. We are not yet certified; our current posture is available under NDA.

Encryption

Always on

AES-256 at rest and TLS 1.2+ in transit, applied to every document and record by default.

US data residency

By default

Hosted on Amazon Web Services in the United States, on managed, hardened services.

Trusted data handling

Your data stays yours.

From where it lives to how long we keep it, every decision about your data is made in your favor, and we're specific about what that means.

Data residency

Your data is stored and processed on Amazon Web Services in the United States, on managed, hardened services configured to keep it encrypted and isolated to your firm.

Encrypted storage, scoped per firm

Documents live in encrypted object storage that is scoped to the firm that owns them, so a file is only ever reachable from within its own matter.

Backups and recovery

Managed AWS services provide automated, encrypted backups with point-in-time recovery, and audit-log history stays recoverable for compliance.

Retention and offboarding

You keep ownership of your data. On request, we help you export it, and we retain records only as long as needed to run the service and meet legal obligations.

Data minimization

We collect and keep only what a closeout needs. Extraction surfaces the fields that matter and hands them to your team to confirm, nothing more.

Sub-processors

A small, vetted set of providers.

Closeout runs on a short, carefully vetted set of infrastructure and AI providers. Each is bound by a Data Processing Agreement, and, where it may handle protected health information, a Business Associate Agreement, and is permitted to process data only as needed to deliver the service.

Our current sub-processors are listed in the Data Processing Agreement, so your team can review exactly who touches your data before you sign.

Questions, answered

Security, in plain terms.

Data is encrypted at rest with AES-256 and in transit with TLS 1.2+, isolated to your firm at both the application and database layers, restricted by role-based access, and recorded in a tamper-evident audit trail of every action.

Closeout handles medical records, bills, and EOBs as protected health information under a signed HIPAA Business Associate Agreement, and aligns its controls, encryption, least-privilege access, per-firm isolation, and audit logging, with HIPAA requirements.

We're in the process. Closeout is built to SOC 2 standards and we have begun a SOC 2 Type II audit; the engagement is underway. Certification is pending completion of that audit, and we're glad to share our current trust posture and progress under NDA.

No. AI extraction runs under a Business Associate Agreement on a zero-retention basis, so the provider does not keep your content after a request is processed, and your client data is never used to train shared, public, or third-party models.

On Amazon Web Services in the United States, encrypted at rest, on managed, hardened services.

Access is role-based, Firm Admin, Attorney, and Case Manager, and every record is scoped to your firm. Each person sees only what their role needs.

Every account is protected by a strong password policy, credentials hashed with a modern algorithm, automatic lockout after repeated failed attempts, and short-lived sessions, all scoped to your firm and recorded in the audit trail. Users can turn on app-based multi-factor authentication (MFA) from Settings, Security, using any authenticator app, with one-time recovery codes for backup. If your firm also requires single sign-on (SSO) under its own identity provider, contact our team and we'll work with you to support it.

Email security@usecloseout.com with the details. We acknowledge reports within one business day and keep you updated through resolution.

Serious about security?

See exactly how Closeout protects a case from intake to close, or write to our security team directly.

Read how we handle personal data in our Privacy Policy. Last updated August 13, 2026.