Security at Astrea

Astrea protects client data through secure service delivery, responsible vendor oversight, access controls, confidentiality practices, and incident response procedures designed for eDiscovery work.

Security Overview

Astrea maintains administrative, technical, and organizational safeguards designed to protect client data and support the secure delivery of eDiscovery services. Astrea provides services using Microsoft 365 and approved third-party platforms, including Reveal, Relativity, and Clio, where applicable to the client engagement.

Astrea does not develop proprietary eDiscovery software. Astrea's security program is focused on secure service delivery, responsible vendor oversight, access management, confidentiality, data handling, incident response, and the appropriate use of approved subservice platforms.

Shared Responsibility Model

Astrea operates under a shared responsibility model. Astrea is responsible for its internal policies, personnel controls, access management, client workflows, vendor oversight, and secure handling of client data. Microsoft 365, Reveal, Relativity, and Clio are responsible for the security, availability, and compliance controls of their respective platforms.

Control areaAstrea responsibilitySubservice vendor responsibility
User accessApprove, provision, review, and remove Astrea-controlled user access based on role and matter requirements.Provide platform-level identity, permission, logging, and access management capabilities.
Platform securityUse approved platforms according to Astrea policies and client requirements.Maintain platform infrastructure, application security, hosting controls, and related security operations.
Data handlingHandle client data according to contractual requirements, authorized workflows, and confidentiality obligations.Provide secure platform features, encryption capabilities, audit logging, availability, and storage controls.
Vendor risk managementEvaluate, approve, and periodically review vendors used to support service delivery.Provide security documentation, compliance reports, and security commitments as applicable.
Incident responseIdentify, escalate, investigate, and respond to incidents within Astrea's environment and service workflow.Notify and support customers regarding incidents affecting their respective platforms, based on vendor commitments.

Subservice Vendors

Astrea uses approved vendors to support eDiscovery service delivery and business operations. Key platforms may include:

Vendor / PlatformSecurity relevance
RevealSupports eDiscovery processing, hosting, review, analytics, production, and related workflows. Reveal maintains its own platform security and compliance controls.
RelativitySupports eDiscovery hosting, review, processing, search, analytics, production, and related workflows. Relativity maintains its own platform security and compliance controls.
ClioSupports matter management, client administration, billing, and legal practice management workflows. Clio maintains its own platform security and compliance controls.

Access Control and Identity Management

Astrea applies access controls designed to limit access to authorized users and appropriate business needs. These controls may include:

  • Multi-factor authentication where applicable.
  • Role-based and least-privilege access to systems and client data.
  • User provisioning based on approved business or matter requirements.
  • Timely removal or adjustment of access when users change roles, leave the organization, or no longer require access.
  • Periodic access reviews for systems and vendor platforms within Astrea's control.
  • Administrative access limited to authorized personnel.

Data Protection

Astrea handles client data according to contractual obligations, matter-specific instructions, internal policies, and approved workflows. Astrea relies on approved platforms, including Microsoft 365, Reveal, Relativity, and Clio, for platform-level data protection capabilities where applicable.

Data protection areaExpected practice
EncryptionData is protected using encryption in transit and encryption at rest through approved vendor platforms and configured services, where applicable.
Secure transferClient data is transferred using approved methods and access-controlled channels based on matter requirements.
Restricted accessAccess to client data is limited to authorized users with a business or matter-specific need.
ConfidentialityPersonnel and contractors are expected to follow confidentiality obligations and approved data handling procedures.
Data retention and disposalClient data is retained and disposed of according to contractual, legal, operational, and matter-specific requirements.

Vendor Risk Management

Astrea maintains a vendor risk management process for vendors that support service delivery and business operations. Vendor oversight may include maintaining a vendor list, identifying critical vendors, reviewing security documentation, reviewing SOC 2 reports or equivalent assurance materials where available, and tracking vendor risks or required follow-up actions.

Because Microsoft 365, Reveal, Relativity, and Clio provide important platform functionality, Astrea relies on each vendor's security, availability, and compliance controls for the parts of the service operated by those vendors.

Employee and Contractor Security

Astrea applies personnel security controls intended to protect client data and support secure service delivery. These controls may include:

  • Confidentiality agreements or equivalent obligations.
  • Employee or contractor agreements as applicable.
  • Security awareness training.
  • Background checks where required by policy or role.
  • Acceptable use and information security policy acknowledgement.
  • Termination and offboarding procedures, including access removal.

Incident Response

Astrea maintains an incident response process to identify, escalate, investigate, respond to, and document security events. Security concerns involving client data, Astrea systems, or approved subservice platforms are escalated based on severity, potential impact, and contractual or legal notification requirements.

Where an incident involves a subservice vendor platform, Astrea will coordinate response activities with the vendor and affected stakeholders as appropriate.

Business Continuity and Availability

Astrea maintains business continuity and disaster recovery procedures designed to support continued operations and recovery of key business processes. Astrea also relies on the resilience, backup, availability, and recovery capabilities of approved vendor platforms, including Microsoft 365, Reveal, Relativity, and Clio, where those platforms support service delivery.

Compliance and Assurance

Astrea maintains a security program aligned with SOC 2 requirements. Until a SOC 2 examination is completed, public language should state that Astrea is pursuing SOC 2 certification or maintains controls aligned with SOC 2 Trust Services Criteria. Once a SOC 2 report is available, Astrea may update this page to state that the SOC 2 report is available to authorized customers and prospects under NDA.

Security Contact

Security questions, vulnerability reports, or concerns involving Astrea services should be sent to: support@astrea-ediscovery.com.

For urgent matter-specific concerns, clients should also contact their designated Astrea service contact.