Trust

Security & Confidentiality

Legal practice runs on privilege. This page sets out, in plain terms, the controls we operate so client confidences stay confidential.

Last updated 13 August 2026

Encryption

Traffic between your browser and the platform is encrypted in transit with TLS. Case records, documents and messages are stored encrypted at rest by our managed cloud infrastructure.

Uploaded documents are served through short-lived signed links rather than public URLs, so a file cannot be reached without an authenticated request.

Firm-level isolation

Every record is tagged to the firm that created it and access rules are enforced in the database itself, not only in the interface. A request that is not tied to your firm cannot read your firm's records, even if it reaches the API directly.

Client portal access is scoped to a single case and issued as a revocable link, so a client never sees another client's matter.

Access controls

Roles run from super administrator through platform administrator, firm administrator and fee earner. Sensitive actions — role changes, billing settings, deletion — are restricted to administrators.

Multi-factor authentication is available on every account, and sign-in also supports one-time codes so a password is not the only path in.

Audit trails

Case activity, assignment changes, document actions and administrative decisions are written to an audit log that firm administrators can review.

Client portal views and document downloads are recorded, so you can evidence what a client was shown and when.

Data residency & retention

Data is hosted with our managed cloud provider and retained while your account is active. Deletion requests are honoured after a defined grace period, after which records are purged from primary storage and backups age out on their normal cycle.

Our retention approach is described further in the Privacy Policy.

Payments

We do not collect fees from your clients. Invoices carry your firm's own bank or mobile money details, and any payment gateway you use remains your own merchant relationship — we can assist with the technical setup on request.

Platform subscriptions are handled by our billing provider; we do not store card numbers.

Reporting a vulnerability

If you believe you have found a security issue, contact us before disclosing it publicly. Include the steps to reproduce and any affected accounts, and we will acknowledge and work with you on a fix.

Questions about this document? Write to support@lawandlegal.app.