Privileged work, and what we do to deserve it.
Every claim below maps to the code that enforces it. Where a claim was stronger than what the code actually does, we changed the claim — including the one at the bottom of this page.
Tenant isolation
Firm-scoped records
Every matter, document, message and invoice carries the firm it belongs to, and every query is filtered by a firm id read from the signed-in user’s own record — never from a URL or a token.
Scoped AI context
Agents and chat assemble context from one firm's records only, within a fixed token budget.
Paralegal scope
Paralegals see the matters and tasks assigned to them, not the firm's whole book.
Feature gating
Your admin can switch any module or AI capability off per person. Off means hidden in the interface and refused by the API.
Identity & access
Separate portals
Attorneys, paralegals, clients and firm administrators sign in to separate applications, each with its own session.
Token-based sessions
Signed session tokens with role claims; every route checks them, and deactivating an account takes effect on the next request rather than at token expiry.
Controlled file access
Documents are encrypted at rest and served through links minted at read time, only to people with access to the matter.
Impersonation on the record
When an administrator signs in as a user, the session is time-boxed, shown in an undismissable banner, and every action it takes names the person behind it.
AI guardrails
Approval-gated actions
Agents produce proposals. Filing, sending and changing records require a human decision.
Citations on every answer
Each AI response tracks which documents and records it referenced.
Policy gate
Client-facing work and anything that reads as legal advice is held for a person before it can be approved.
Cost accounting
Every run's tokens and cost are logged against the firm, with per-attorney totals.
Auditability
Complete audit log
State changes are recorded with actor, time and before/after values, and can be exported.
Immutable archive
Snapshots are written to a separate append-only collection that is never updated in place.
Agent run history
Every agent run, its inputs, outputs and the approval decision are kept.
Document versions
Every version of every document is retained with who changed it.
Infrastructure
Encryption in transit
TLS 1.2 and 1.3 only, with certificates renewed automatically.
Isolated services
Each portal, the API and the database run as separate services behind a single reverse proxy.
Encrypted backups
Nightly AES-256 backups of the database and uploaded files, with a documented and rehearsed restore procedure.
What we do not hold.
SOC 2 and ISO 27001 are not yet held. We would rather say so here than let a page of badges imply otherwise — ask us what we do hold and we will put it in writing.
Send us your security questionnaire.
We answer it in writing, including the parts where the answer is not yet.