Encryption
Traffic between your browser and the platform is encrypted in transit with TLS. Case records, documents and messages are stored encrypted at rest by our managed cloud infrastructure.
Uploaded documents are served through short-lived signed links rather than public URLs, so a file cannot be reached without an authenticated request.
Firm-level isolation
Every record is tagged to the firm that created it and access rules are enforced in the database itself, not only in the interface. A request that is not tied to your firm cannot read your firm's records, even if it reaches the API directly.
Client portal access is scoped to a single case and issued as a revocable link, so a client never sees another client's matter.
Access controls
Roles run from super administrator through platform administrator, firm administrator and fee earner. Sensitive actions — role changes, billing settings, deletion — are restricted to administrators.
Multi-factor authentication is available on every account, and sign-in also supports one-time codes so a password is not the only path in.
Audit trails
Case activity, assignment changes, document actions and administrative decisions are written to an audit log that firm administrators can review.
Client portal views and document downloads are recorded, so you can evidence what a client was shown and when.
Data residency & retention
Data is hosted with our managed cloud provider and retained while your account is active. Deletion requests are honoured after a defined grace period, after which records are purged from primary storage and backups age out on their normal cycle.
Our retention approach is described further in the Privacy Policy.
Payments
We do not collect fees from your clients. Invoices carry your firm's own bank or mobile money details, and any payment gateway you use remains your own merchant relationship — we can assist with the technical setup on request.
Platform subscriptions are handled by our billing provider; we do not store card numbers.
Reporting a vulnerability
If you believe you have found a security issue, contact us before disclosing it publicly. Include the steps to reproduce and any affected accounts, and we will acknowledge and work with you on a fix.
