Version 1.0 · Effective August 3, 2026
ILLUMINATE PRIVACY POLICY
& SECURITY POLICY
Version 1.0 • Effective August 3, 2026
THE MENTOR ESQ INC.
Illuminate is built for lawyers, and lawyers handle other people’s secrets for a living. We designed this platform on that assumption. This document explains, in plain terms, what we collect, what we do and do not do with it, and how we protect it.
OUR THREE COMMITMENTS
1. Your files are yours alone. No other Illuminate user can see, search, retrieve, or access anything you upload to or generate in Illuminate. Your workspace is isolated to your account.
2. The platform is secured. All data is encrypted in transit and at rest, hosted on established cloud infrastructure, and protected by access controls, monitoring, and logging.
3. Two-factor authentication is required. Not optional, not encouraged — required, on every account, with no opt-out.
PART B — SECURITY POLICY
13. Security Overview
We designed Illuminate on the assumption that everything in it is confidential, privileged, or both. Security is not a feature layer bolted on afterward; it governs how the platform is built and operated.
14. Two-Factor Authentication
Two-factor authentication for Illuminate accounts is being rolled out. Once enrollment ships it will be mandatory for every account — not optional, and not disableable.
Until enrollment is available in your account settings, access to your account is protected by the password and session controls described in this Policy. We are building mandatory two-factor authentication because credential compromise — a reused or phished password — is the single most common way client files are exposed, and because a password alone is no longer a defensible control for material of this sensitivity. When enrollment reaches your account you will be required to enroll a second factor and to satisfy it at sign-in, and recovery will require identity verification through our support process.
15. Encryption
- In transit. All connections to Illuminate are encrypted using TLS 1.2 or higher. Unencrypted connections are refused and redirected. Transmission between Illuminate and its service providers, including the AI model provider, is likewise encrypted in transit.
- At rest. User Content, uploads, generated output, and database records are encrypted at rest using AES-256 or an equivalent industry-standard algorithm.
- Credentials. Passwords are never stored in plain text. They are stored only as salted, computationally expensive one-way hashes and cannot be recovered or read by anyone, including us — if you forget your password, it is reset, not retrieved.
16. Isolation — Only You Can See Your Files
Every document you upload and every output Illuminate generates for you is scoped to your account and is accessible only through your authenticated session.
- No other user, subscriber, firm, or account can view, list, search, retrieve, or reference your User Content.
- Your content is not used to answer another user’s question, does not appear in another user’s results, and is not pooled into any shared corpus or index.
- Access-control checks are enforced at the application and data layers on every request, so that a request for a record not belonging to the authenticated account is refused rather than filtered after retrieval.
- Where you use Illuminate within a firm account, visibility among your firm’s own users is governed by the roles and permissions your firm administrator configures.
17. Personnel Access
We will not overstate this, because a security policy that overstates is worse than none.
Illuminate processes your documents with artificial intelligence, which necessarily means the platform can read them. It is therefore not an end-to-end encrypted or zero-knowledge system, and any provider that tells you otherwise while offering AI document analysis is describing something that is not technically possible.
What is true is this: access to production systems and User Content by Company personnel is restricted to a small number of authorized individuals, granted on a least-privilege basis, and exercised only where necessary to operate the Service, provide support you have requested, investigate a security incident or suspected abuse, or comply with a legal obligation. All such access requires the individual’s own authenticated, two-factor-protected credentials, is logged, and is subject to written confidentiality obligations. Personnel are not permitted to access, read, or use User Content for any other purpose.
18. Infrastructure and Operations
- Hosting. Illuminate runs on Supabase (database, storage, and authentication, hosted on Amazon Web Services in us-east-2) and Vercel (application hosting) — established cloud infrastructure providers maintaining physical, environmental, and network security controls at its data centers, including 24/7 physical security, redundant power, and network-level protections.
- Network security. Production systems sit behind firewalls and are not directly reachable from the public internet except through defined, monitored entry points. Administrative interfaces are not publicly exposed.
- Segregation. Development, testing, and production environments are separated. Where development work requires production access today, it is limited to the authorized operators described in Section 17; we are adopting isolated database branches so routine development does not touch production data.
- Patching. Operating systems, runtimes, and dependencies are kept current, and security updates are applied on an expedited basis.
- Monitoring and logging. Authentication events, administrative actions, and anomalous activity are logged and monitored. Logs are retained for investigation and audit.
- Backups. Data is backed up daily, backups are encrypted, and the most recent seven daily backups are retained.
19. Vendor and Subprocessor Security
We keep the number of parties that touch your data deliberately small. Every subprocessor is selected with security as a gating criterion, is bound by written obligations to protect the information and to use it only to provide services to us, and is subject to periodic review. We will maintain a current list of subprocessors available on request and will provide notice of material changes.
20. Incident Response
We maintain an incident-response process covering detection, containment, investigation, remediation, and notification.
If we determine that a security incident has resulted in the unauthorized acquisition, access, or disclosure of your User Content or personal information, we will notify you without unreasonable delay, and in any event within the time required by applicable law. Our notice will describe, to the extent then known, what happened, what information was involved, what we have done in response, and what we recommend you do — including, where relevant, so that you can assess your own notification obligations to your clients and to regulators.
21. Your Role in Security
Security of your matters is a shared responsibility. The strongest platform controls are defeated by a shared login. You agree to:
- use a strong, unique password that you do not reuse on any other service;
- keep your second authentication factor under your sole control and never share codes with anyone, including anyone claiming to be Illuminate support — we will never ask you for a one-time code;
- never share account credentials, and provision a separate account for each person at your firm who needs access;
- sign out of and revoke sessions on shared or lost devices, and keep your devices patched and protected; and
- notify us immediately at the address in Section 23 if you suspect unauthorized access to your account.
22. Reporting a Vulnerability; No Absolute Guarantee
If you believe you have found a security vulnerability in Illuminate, please report it to us at the address in Section 23 rather than disclosing it publicly. We will acknowledge your report, investigate promptly, and will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before disclosure.
NO SYSTEM CONNECTED TO THE INTERNET CAN BE MADE PERFECTLY SECURE. WHILE WE IMPLEMENT AND MAINTAIN THE MEASURES DESCRIBED IN THIS POLICY, WE CANNOT AND DO NOT GUARANTEE THAT THE SERVICE OR ANY INFORMATION IN IT WILL BE FREE FROM UNAUTHORIZED ACCESS, INTERCEPTION, LOSS, OR MISUSE. THE DISCLAIMERS AND LIMITATIONS OF LIABILITY IN SECTIONS 13 AND 14 OF THE TERMS APPLY TO THIS POLICY.
23. Changes and Contact
We may update this Policy. When we do, we will revise the version and effective date above and, where the change is material and adverse to you, provide reasonable advance notice through the Service or by email before it takes effect. Your continued use after the effective date constitutes acceptance.
Questions, requests, vulnerability reports, and privacy or security notices should be directed to:
The Mentor Esq Inc.
Attn: Privacy & Security — Illuminate
Email: support@illuminatelaw.ai
© 2026 The Mentor Esq Inc. All rights reserved. Illuminate™ and The Mentor Esq™ are trademarks of The Mentor Esq Inc. Version 1.0 — Effective August 3, 2026. This Policy forms part of The Mentor Esq. Pledge, Disclaimer & Terms of Use.