Security, Compliance, and Certifications
Certifications, access controls, encryption architecture, chain-of-custody methodology, privacy-aware discovery, AI governance, and biometric litigation support documentation for GDF's eDiscovery platform.
Why Security Documentation Matters in eDiscovery
Discovery data is, by definition, sensitive. It includes privileged communications, confidential business records, personal data about employees and customers, health information, and financial records. A vendor that cannot answer specific security questions during procurement is a liability, not a resource. GDF publishes this page to answer those questions directly and allow legal, IT, privacy, and security teams to evaluate GDF's posture against their own requirements before a matter begins.
Buyers should not accept vague claims about "enterprise-grade security" from any discovery provider. The questions that matter are specific: which certifications have been independently audited? How is encryption implemented? Who can access client data, and under what conditions? How is a chain-of-custody record generated and maintained? What happens if there is a security incident? This page answers those questions with the specificity that procurement teams and outside counsel security questionnaires require.
Certifications and Standards
GDF's eDiscovery platform and operations are built around independently audited security frameworks. The certifications listed here reflect formal third-party assessments, not self-declarations.
SOC 2 Type II: GDF's platform undergoes annual SOC 2 Type II audits covering the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Type II audits evaluate the operating effectiveness of controls over a defined period, not just point-in-time design. The resulting report documents that GDF's access controls, change management, incident response, and data handling procedures functioned as designed throughout the audit period.
ISO/IEC 27001: GDF's information security management system (ISMS) is certified against ISO/IEC 27001, the international standard for systematic management of information security risks. Certification requires establishing a documented ISMS, implementing controls across 114 domains including access control, cryptography, physical security, and supplier management, and passing an independent certification audit with annual surveillance reviews.
ISO/IEC 27017: GDF's cloud operations align with ISO/IEC 27017, which extends 27001 with controls specific to cloud service environments. The standard addresses shared responsibility boundaries, virtual machine protection, cloud-specific access management, and monitoring of cloud infrastructure, all of which are directly relevant to eDiscovery platform hosting.
ISO/IEC 27018: For matters involving personal data, GDF follows ISO/IEC 27018, the code of practice for protection of personally identifiable information (PII) in public cloud environments. The standard covers consent for use of personal data, transparency about what is processed and retained, individual rights over their PII, and obligations on subprocessors. This certification is directly relevant to GDPR and CCPA compliance questions about cloud-hosted eDiscovery data.
HIPAA: GDF operates under a Business Associate Agreement (BAA) framework for matters involving protected health information (PHI). HIPAA-covered matters are hosted in a HIPAA-compliant environment with appropriate administrative, physical, and technical safeguards, audit logging, and breach notification procedures aligned with the HIPAA Breach Notification Rule.
FedRAMP: For federal government clients and matters involving federal data, GDF supports FedRAMP-aligned hosting configurations. Clients with specific FedRAMP Moderate or FedRAMP High requirements should contact GDF's security team directly to discuss hosting architecture and authorization status applicable to their matter.
Security Architecture
Access Controls
GDF enforces role-based access controls (RBAC) across all platform functions. Review platform access is provisioned by matter: a user on Matter A cannot access Matter B. Administrative access to infrastructure is restricted to named personnel with a business need, and all administrative actions are logged in an immutable audit trail. Multi-factor authentication (MFA) is required for all platform access, including administrative functions. Privileged access reviews are conducted quarterly, and access is revoked immediately upon personnel change or matter close.
Encryption at Rest and in Transit
All client data stored on GDF's platform is encrypted at rest using AES-256. Data in transit between client systems and GDF's platform is encrypted using TLS 1.2 or higher, with TLS 1.3 preferred. Encryption keys are managed through a dedicated key management service with annual rotation and access logging. GDF does not store encryption keys in the same environment as the encrypted data.
Logging and Auditability
Every action on GDF's platform generates an audit log entry: who accessed a document, what action was taken, and when. Log entries are written to an append-only store that cannot be modified by platform users, including administrators. Logs are retained for a minimum of seven years. On request, GDF can provide a complete audit log for any matter, showing every access event from ingestion through production.
Chain of Custody
Chain of custody in eDiscovery means being able to answer, at any point in time, where a piece of data came from, who handled it, what was done to it, and where it went. GDF's methodology generates this record automatically at every stage of the workflow.
At collection, GDF generates a forensic log that records the source system authenticated, the tool and version used, the date and time of collection, the personnel who executed the collection, and the cryptographic hash (SHA-256) of each collected item. That hash is re-verified at ingestion into the processing environment. If any file fails hash verification, the collection is flagged and the source file is re-collected before processing continues.
Through processing, deduplication, and culling, every transformation applied to the data set is documented with the parameters used and the volume of items affected. The processing log links back to the collection log through a matter-level chain-of-custody record. Review actions, including coding, privilege designations, and redactions, are recorded in the audit log but are kept separate from the forensic chain-of-custody record to preserve the integrity of the collection documentation independent of review decisions.
At production, GDF generates a production manifest that lists every produced document, its Bates identifier, its original collection source, the processing parameters applied, any redactions applied, and the hash of the produced file. That manifest is delivered alongside the production and supports a complete reconciliation from produced document back to original source data.
Incident Response and Data Residency
GDF maintains a documented incident response plan that is tested annually through tabletop exercises. In the event of a confirmed or suspected security incident affecting client matter data, GDF notifies affected clients within 72 hours of confirmation, consistent with GDPR Article 33 timelines and standard BAA requirements. The notification includes the nature of the incident, the data types and approximate volumes affected, the steps GDF has taken to contain and remediate, and GDF's contact for ongoing communication.
Data residency is configurable for matters with specific geographic requirements. By default, GDF processes and stores matter data in United States-based infrastructure. Clients with EU data residency requirements, UK jurisdiction restrictions, or other cross-border transfer constraints should specify those requirements at matter intake, and GDF will configure hosting accordingly. GDF does not transfer matter data to third-party subprocessors outside the agreed data residency region without explicit client authorization.
Audit Procedures and Third-Party Assessments
GDF's information security program is subject to annual third-party audits for SOC 2 Type II and ISO 27001 surveillance. Audit reports are available to qualified clients under NDA upon request. GDF also supports client-directed security questionnaires and procurement due diligence reviews. Clients requiring site visits or architecture review sessions for high-sensitivity matters should request those through GDF's account management team.
Privacy-Aware Discovery
Personal data collected in the course of eDiscovery is subject to the same privacy obligations that apply to any other processing of that data. GDF's privacy-aware discovery framework addresses this directly.
GDPR: For matters involving EU personal data, GDF operates as a data processor under Article 28, with a written Data Processing Agreement (DPA) that specifies the categories of data processed, the legal basis for processing, the security measures in place, the data retention and deletion schedule, and the subprocessor chain. Cross-border transfers from the EU to the United States are conducted under Standard Contractual Clauses (SCCs) as adopted by the European Commission. GDF does not retain EU personal data beyond the matter retention period without written instruction from the data controller.
CCPA: GDF acts as a service provider under the California Consumer Privacy Act for matters involving California residents' personal information. GDF does not sell, share, or use personal information collected in the course of an engagement for any purpose other than the specific eDiscovery services requested. Clients may request a CCPA-compliant service provider agreement as part of the engagement documentation.
Cross-Border Transfer Restrictions: Some jurisdictions impose restrictions on transferring personal data for litigation purposes. GDF's collection workflows can be configured to collect and process data within a specified jurisdiction, to flag cross-border transfers for privacy counsel review before they occur, and to document the legal basis for any approved transfer. GDF does not assume that litigation necessity provides an automatic override of applicable transfer restrictions, and treats cross-border transfers as requiring explicit scoping decisions at the outset of each matter.
Data Residency: GDF offers matter-level data residency configuration. Clients can specify that matter data must remain within a defined region, and GDF will configure infrastructure and processing workflows accordingly. Available regions include the United States, European Union, and United Kingdom. Multi-region matters with different data residency requirements for different data sources require advance planning at matter intake.
AI Governance
GDF uses AI-assisted tools for predictive coding, near-duplicate grouping, email threading, and early case analytics. Each of these tools is used as an aid to human reviewers and project managers, not as a substitute for human judgment. GDF's AI governance framework reflects three principles that courts, the Sedona Conference, and leading practitioners have emphasized: explainability, human oversight, and documented validation.
On explainability, GDF's AI tools provide a rationale for each prioritization or relevance prediction at the document level. Reviewers can see why a document was surfaced as likely relevant, which features drove the prediction, and how the model was trained. That transparency allows reviewers to calibrate their reliance on the tool and identify cases where the model's predictions should be overridden.
On human oversight, no document is coded as responsive or non-responsive, produced, or withheld based solely on an AI prediction. Every AI-assisted review queue is reviewed by a human attorney or qualified reviewer. Documents coded as non-responsive by an AI-assisted workflow are subject to quality-control sampling before the review set is finalized. The QC rate and methodology are documented and available for disclosure if the review process is challenged.
On validation, GDF documents the training set used to build any predictive coding model, the metrics used to evaluate model quality (precision, recall, F1 scores), and the validation protocol applied before the model was used for production-level coding. That documentation follows the guidance in the Sedona Conference TAR Case Law Primer and supports an elusion-testing or random-sample-based validation response if opposing counsel requests an explanation of the review methodology.
Biometric Litigation Support
Biometric litigation has become one of the most technically demanding areas of eDiscovery. Illinois's Biometric Information Privacy Act (BIPA) has generated more class action litigation than any other state privacy law, and the FTC's biometric policy statement has expanded regulatory scrutiny across facial recognition, voice biometrics, fingerprints, iris scans, and derived data including templates and embeddings. GDF has developed a specific collection and analysis framework for matters involving biometric data.
What Biometric Discovery Actually Covers: Biometric eDiscovery is not just about documents. The relevant evidence in a BIPA case or FTC enforcement action typically includes written retention and destruction policies, notice documents provided to individuals, consent records, vendor contracts governing biometric data collection or processing, templates and embeddings stored by the system (often in proprietary formats), audit logs showing who was enrolled and when, access logs showing which personnel accessed biometric data, training and testing datasets used to develop biometric models, and records documenting deletion of biometric data. GDF's collection workflow addresses all of these source types, not only conventional documents and email.
BIPA-Specific Collection Protocol: Illinois BIPA requires a written retention and destruction policy, written notice to individuals, informed written consent before collection, and restrictions on disclosure and profit from biometric data. For BIPA matters, GDF's collection protocol targets the systems that generate and store the relevant evidence: employee onboarding systems, time and attendance platforms, access control systems, third-party biometric vendor APIs, and the internal policy and consent management repositories. GDF's forensic analysis documents what the data shows about the company's collection and storage practices; the legal team uses that analysis to assess compliance and exposure.
FTC Biometric Policy Alignment: The FTC has defined biometric information broadly to include any data derived from face, voice, fingerprints, iris or retina, genetics, and other physical characteristics, including templates, embeddings, and other derived representations. GDF's collection scope for FTC-adjacent matters extends to AI model training datasets, embedding stores, and any system that processes biometric-derived data, not only systems that capture biometric data at enrollment. This broader scope reflects the FTC's framing and avoids the collection gaps that create problems when regulators ask why certain evidence was not preserved.
Consent Records and Retention Documentation: Biometric consent records are often stored separately from the biometric data itself, sometimes in HR systems, sometimes in paper files, and sometimes in the onboarding platform's own database. GDF maps the consent record chain from the moment individuals were enrolled through the current date, identifies any gaps in the record, and produces a report documenting what consent evidence exists and what is missing. That analysis supports counsel's assessment of liability exposure before litigation strategy is set.
Last reviewed and updated: April 2026
SOC 2 Type II and ISO 27001
Independently audited annually. Reports available under NDA to qualified clients undergoing procurement due diligence. GDF does not ask clients to accept self-certification in place of third-party audit documentation.
AES-256 Encryption at Rest
All client matter data is encrypted at rest using AES-256 with dedicated key management and annual key rotation. Data in transit is encrypted using TLS 1.2 minimum, with TLS 1.3 preferred for all new connections.
Immutable Audit Logs
Every platform action generates an append-only audit log entry retained for a minimum of seven years. Complete access logs for any matter are available on request and support both chain-of-custody documentation and security incident response.
GDPR and CCPA Compliant Processing
GDF operates under Article 28 DPAs for GDPR-covered matters and service provider agreements for CCPA-covered matters. Cross-border transfers are documented and conducted under SCCs. Data residency is configurable by jurisdiction.
Explainable AI with Human Oversight
GDF's AI-assisted review tools provide document-level rationale for prioritization decisions. No document is produced or withheld based solely on AI prediction. QC sampling rates and validation metrics are documented and available for disclosure.
Biometric Litigation Expertise
GDF collects from biometric systems, time and attendance platforms, vendor APIs, embedding stores, and consent record repositories. The analysis covers BIPA-specific collection gaps, FTC-scope biometric data, and consent record completeness across the enrollment period.
Security Questionnaire or DPA Request?
GDF's security team responds to procurement security questionnaires, DPA requests, and architecture review sessions. Contact us to initiate a security due diligence review for your matter or program.
Related Services
Review Platform
GDF's in-house review environment with flat-rate feature access, AI-assisted workflows, privilege tools, and built-in audit logging. SOC 2 Type II and ISO 27001 certified hosting.
Learn MoreCloud and SaaS Collections
Direct-source collections using least-privilege credentials, with full metadata preservation, hash verification, and immutable chain-of-custody documentation at every step.
Learn MoreeDiscovery for Corporations
GDF coordinates with legal, IT, and privacy teams to ensure that collections satisfy data governance requirements, cross-border transfer rules, and internal access controls.
Learn MoreSecurity Questions Before You Proceed?
GDF responds to procurement security questionnaires, DPA requests, and architecture review sessions. Send your questionnaire or call to discuss your specific requirements.