Trust & Security
Nextpoint is committed to ensuring the confidentiality, integrity, and availability of all customer data.
Status Dashboard
Nextpoint publishes up-to-the-minute status information via an immediate/automated tracking service at status.nextpoint.com. Additionally, incident reports will be provided for any notable service interruption.
Backups and Disaster Security
Data stored by Nextpoint is redundantly stored in multiple physical locations at no additional charge. Additional precautionary measures are also available to all customers. Customers can export and download data at any point on an unlimited basis (no additional charge) as well as elect to have data periodically downloaded and sent to them on physical media (additional charge).
Nextpoint products hosted by Amazon Web Services are designed to provide 99.999999999% durability of objects over a given year. This durability level corresponds to an average annual expected loss of 0.000000001% of objects. For example, if you store 10,000 objects using Nextpoint, you can on average expect to incur a loss of a single object once every 10,000,000 years.
Amazon S3 redundantly stores your objects on multiple devices across multiple facilities in an Amazon S3 Region. When processing a request to store data, the service will redundantly store your object across multiple facilities before returning SUCCESS. Amazon S3 also regularly verifies the integrity of Nextpoint data using checksums.
Nextpoint is fully prepared for complete data recovery and an immediate return to service following an accident or disaster. Nextpoint data hosted on Amazon S3 is designed to sustain the concurrent loss of data in two facilities. In the event that two facilities go down, devices in a tertiary facility are activated and data is restored with no downtime.
Physical Security
Nextpoint data stored by Amazon Web Services is hosted in nondescript data centers. Critical facilities have extensive setback and military-grade perimeter control berms as well as natural boundary protection.
Employee Data Center Access
AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions.
Third-party Data Center Access
Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff.
AWS GOVCLOUD Data Center Access
Physical access to data centers in AWS GovCloud (US) is restricted to employees who have been validated as being US citizens.
Nextpoint physical security
Client data stored at the Nextpoint office is secured in a keyed office, in a keyed building, with a security system. Server access is password protected and granted only via secure VPN.
Employee Training
All new hires undergo background checks before formally starting work as well as security training as part of the Nextpoint onboarding process. Following successful completion of the training, employees sign a confidentiality agreement regarding the protection of client information. Additionally, all employees, regardless of tenure, participate in annual security training. Third-party business associates must sign agreements that include rules and responsibilities regarding confidentiality and security.
Internal Audits
Nextpoint’s Site Reliability Engineering Team assesses security risks on an ongoing basis, monitors access logs, addresses known incidents, and applies security patches. Nextpoint conducts a comprehensive, annual IT risk assessment to ensure and maintain SOC II Type 2 Compliance. Nextpoint employs an enterprise Secure Software Development Life Cycle (SDLC) as part of its ongoing commitment to building and maintaining secure applications.
Data Access
All app admin employee data access is documented via a documentation trail. This trail includes both documentation of the request and the granting of that request by an authorized party. Only a subset of employees have access to the Nextpoint application. Other employees can view account usage summaries but have no access to lower-level client data. Access is promptly revoked for employees who no longer need it, whether or not they continue to be employed by Nextpoint.
Single-sign-on and multi-factor authentication further guard against unauthorized access. Single sign-on (SSO) enables a single login for Nextpoint and other platforms, enhancing security and simplifying daily operations. It gives your IT administrators more control in defining security standards and managing access to data. Nextpoint integrates with Okta and Azure AD, with custom SSO integrations available on request through Client Success. Multi-factor authentication is mandatory for every user and device.
Data Encryption + Secure Data Loading
Data is encrypted both at rest and in storage.
Nextpoint is annually audited to ensure it meets the high standards of SOC II Type 2, a security certification that assesses the data management of both human and computer data handlers.
AWS Cloud Security
Nextpoint runs on Amazon Web Services and uses several AWS services specifically to support secure infrastructure: CloudWatch for monitoring and alerting on unusual system activity, Virtual Private Cloud (VPC) to isolate and secure the network environment, and Identity and Access Management (IAM) to control employee access to client data. Access to the AWS environment is IP-restricted and locked after five failed login attempts.
Security Standards
Nextpoint's independent security certification is SOC 2 Type II — an annual third-party audit of our own security controls, covering security, availability, confidentiality, and privacy. (SOC 3 reports are available on request; SOC 2 reports require an executed NDA.)
Nextpoint's infrastructure runs on Amazon Web Services, which maintains its own certifications including SOC 1/2/3, ISO 27001, FedRAMP, and others for the underlying cloud infrastructure.

Incident Response & Breach Notification
Nextpoint’s Site Reliability Engineering Team reviews firewall notifications and operating system event logs on a daily basis. The team also monitors access levels to secured technologies (AWS, the network, the application, etc.) and failed login attempts to the application.
If Nextpoint discovers there may have been an incident in security which has or may have resulted in unauthorized access to Nextpoint protected data, we notify potentially affected users as soon as it’s possible to do so without compromising any investigation or remediation of the breach.
Nextpoint will reasonably cooperate with users in handling of the matter, including, without limitation, (i) assisting with any investigation; (ii) providing users with physical access to Nextpoint facilities and operations affected; (iii) facilitating interviews with Nextpoint employees and others involved in the matter; and (iv) making available all relevant records, logs, files, data reporting and other materials required to comply with applicable law, regulation, or industry standards.
The user shall have the sole right to determine (i) whether notice of the breach is to be provided to any individuals, regulators, law enforcement agencies, consumer reporting agencies or others as required by law or regulation and (ii) the contents of such notice, whether any type of remediation may be offered to affected persons, and the nature and extent of any such remediation.
Nextpoint Privacy Policy
We have no higher priority than the privacy and security of our clients’ data. We seek to lead the industry as a trusted repository for customer data through a robust privacy program and secure infrastructure that enable our customers to comply with privacy and data protection regulations.
Credit Card Data
Nextpoint uses a third-party intermediary to manage credit card processing. This intermediary is not permitted to store, retain, or use billing information except for the sole purpose of credit card processing on Nextpoint’s behalf.
Cookies
Nextpoint uses cookies to make interactions with our website easy and meaningful. Each time you log in to Nextpoint, a session cookie containing an encrypted, unique identifier is placed in your browser. These session cookies allow Nextpoint to uniquely identify you when you are logged in and to process your online transactions and requests. Session cookies are required to use Nextpoint. Nextpoint also occasionally uses third-party cookies. For information on third-party cookies, please see the cookie policy in full.
Data Export & Destruction
Customers can export and download data at any point and on an unlimited basis. Additionally, Nextpoint will delete customer data upon completion of the Data Archive Form. Nextpoint uses hosting providers that follow hardware protocols identified in DoD 5220.22-M (“National Industrial Security Program Operating Manual”) or NIST 800-88 (“Guidelines for Media Sanitization”) to destroy data as part of the decommissioning process. If a hardware device is unable to be decommissioned using these procedures, the device will be degaussed or physically destroyed in accordance with industry-standard practices.
AI at Nextpoint
Nextpoint is built on a simple promise: a platform that keeps up with your caseload — reliable, fast, and built for how litigation actually works. We combine ediscovery and case-building software with hands-on expert services, so you have a team behind you at every stage of litigation.
That vision extends directly to how we think about AI: legal teams are exploring it faster than ever and asking harder questions about it. The document linked below outlines the principles, architecture, and safeguards behind every AI feature at Nextpoint.



