Skip to content
Security

Privileged work, and what we do to deserve it.

Every claim below maps to the code that enforces it. Where a claim was stronger than what the code actually does, we changed the claim — including the one at the bottom of this page.

Query scope · firm boundary
Meridian & Vale
312 matters
Calloway LLP
88 matters
GET /api/matters/6a8f44de → 404
The record exists, in the other firm. A cross-tenant miss answers exactly like a record that was never there — a 403 would confirm it existed.
01

Tenant isolation

Firm-scoped records

Every matter, document, message and invoice carries the firm it belongs to, and every query is filtered by a firm id read from the signed-in user’s own record — never from a URL or a token.

Scoped AI context

Agents and chat assemble context from one firm's records only, within a fixed token budget.

Paralegal scope

Paralegals see the matters and tasks assigned to them, not the firm's whole book.

Feature gating

Your admin can switch any module or AI capability off per person. Off means hidden in the interface and refused by the API.

02

Identity & access

Separate portals

Attorneys, paralegals, clients and firm administrators sign in to separate applications, each with its own session.

Token-based sessions

Signed session tokens with role claims; every route checks them, and deactivating an account takes effect on the next request rather than at token expiry.

Controlled file access

Documents are encrypted at rest and served through links minted at read time, only to people with access to the matter.

Impersonation on the record

When an administrator signs in as a user, the session is time-boxed, shown in an undismissable banner, and every action it takes names the person behind it.

03

AI guardrails

Approval-gated actions

Agents produce proposals. Filing, sending and changing records require a human decision.

Citations on every answer

Each AI response tracks which documents and records it referenced.

Policy gate

Client-facing work and anything that reads as legal advice is held for a person before it can be approved.

Cost accounting

Every run's tokens and cost are logged against the firm, with per-attorney totals.

04

Auditability

Complete audit log

State changes are recorded with actor, time and before/after values, and can be exported.

Immutable archive

Snapshots are written to a separate append-only collection that is never updated in place.

Agent run history

Every agent run, its inputs, outputs and the approval decision are kept.

Document versions

Every version of every document is retained with who changed it.

05

Infrastructure

Encryption in transit

TLS 1.2 and 1.3 only, with certificates renewed automatically.

Isolated services

Each portal, the API and the database run as separate services behind a single reverse proxy.

Encrypted backups

Nightly AES-256 backups of the database and uploaded files, with a documented and rehearsed restore procedure.

What we do not hold.

SOC 2 and ISO 27001 are not yet held. We would rather say so here than let a page of badges imply otherwise — ask us what we do hold and we will put it in writing.

Send us your security questionnaire.

We answer it in writing, including the parts where the answer is not yet.