Back to home
Security & Governance

Enterprise-grade, by design.

Every architectural choice in RegWatch was made with one principle: legal intelligence requires the highest standards of access control, auditability, and data isolation.

Security & governance

Enterprise-grade, by design.

Built around the principle that legal intelligence requires the highest standards of access control and auditability.

Core policy

Human approval gate

No briefing or document ever reaches a client without explicit approval from a qualified MNL advocate. Enforced at the database level, not just the UI.

AI architecture

Enterprise AI retrieval

Documents are indexed inside Google's enterprise AI infrastructure, with no third-party embedding services and no export risk. Your corpus stays in one secure environment.

Data isolation

Company-scoped isolation

Each client organisation operates behind Row-Level Security. AI queries are scoped exclusively to your documents, so cross-client data leakage is architecturally impossible.

Compliance

Full audit trail

Every approval, publication, rejection, login, and document access is logged to an immutable audit table. Regulatory accountability is built in by design.

Access control

No self-signup architecture

There is no public registration. Every client account is provisioned directly by an MNL lawyer. The platform cannot be accessed without a formal onboarding relationship.

Data governance

Jurisdiction-level gating

Document access is enforced at the SQL row-security level by jurisdiction, not the UI. A client in one regulatory scope cannot see documents outside it.

Data architecture

How your data flows, and where it stays.

Documents are uploaded, indexed, queried, and answered entirely within Google's enterprise AI infrastructure and MNL's Supabase database. At no point does client data pass through a third-party embedding or retrieval service.

Lawyer uploads PDFSupabase Storage
Step 01
Gemini Files APIGoogle enterprise AI
Step 02
FileSearchStoreScoped per client
Step 03
Client AI ChatDocument-scoped query
Step 04
Answer + CitationsNo cross-client data
Step 05
🔒No third-party embeddings
🛡️No vector database
⚔️Cross-client isolation guaranteed
Access control

Who can do what, by role.

Three roles, Admin, Lawyer, and Client, each with a precisely defined permission scope. Enforced at the database row-security level, not the UI.

ActionAdminLawyerClient
Upload regulatory documents-
Approve & publish briefings-
View draft / unapproved content-
View published briefings
Chat with AI (document-scoped)
Download assigned documents
Manage lawyer accounts--
Onboard & manage clients-
View audit logs--
Audit trail

Every action, permanently logged.

Approvals, rejections, logins, document accesses: all written to an immutable audit table. Accountability is architectural, not optional.

Audit Log: RegWatch Platform
TimestampActorAction & SubjectOutcome
2026-07-14 14:23:01 UTC
Z. Mwangi (Lawyer)
APPROVED briefing"CBK Circular 7/2026: VASP Due Diligence Requirements"
Published
2026-07-14 09:11:44 UTC
Client (Acme Fintech Ltd)
ACCESSED document"KRA Digital Services Tax Guidance 2025.pdf"
Success
2026-07-13 17:58:22 UTC
Z. Mwangi (Lawyer)
REJECTED briefing"ODPC Draft Guidance: Returned to draft for revision"
Draft

Audit entries are immutable; they cannot be edited or deleted after creation.

Initiate a conversation

Ready to navigate Kenya's regulatory landscape with confidence?

Join the select group of organisations who benefit from MNL's concierge regulatory intelligence service.

info@mnlegal.net