Security & Discretion
Discretion is the practice. Security is how we keep it.
High-stakes work deserves more than a promise of confidentiality. This page describes, in plain language, how the platform that holds your matters is actually built. We publish what we practice — and claim nothing we don’t.
Client isolation, enforced by the database
Every record in the client portal is protected by row-level security: the database itself refuses to return another client’s data, regardless of what the application asks for. Isolation is verified as part of our release process.
Encryption in transit and at rest
All traffic is encrypted with TLS. Documents and data are encrypted at rest on infrastructure hosted in the United States.
Multi-factor access for the firm
Administrative access to client information requires a second authentication factor at an elevated assurance level — a password alone is never enough to reach firm-side surfaces.
An audit trail that cannot be edited
Privileged actions are recorded to an append-only audit log that blocks updates and deletions at the database level, retained for seven years.
Trust accounting, double-entry
Client funds are tracked in an immutable double-entry ledger — every journal must balance to the cent, entries cannot be altered after posting, and processing fees can never touch trust funds.
AI with an attorney in the loop
Where AI assists client communication, no AI-generated response reaches a client until an attorney has reviewed and approved it — enforced by the same database-level controls, not by policy alone. Model calls run under zero-retention terms.
Discretion by default
We do not publish client names, logos, or matter details. Analytics on this site run only with your explicit consent, and we never sell or share personal information.
Documents on signed, expiring links
Files in the portal are never publicly addressable. Every download uses a short-lived signed link generated for the authenticated client who owns it.
We do not display badges for certifications we have not earned. As the practice grows, independent attestations will be added here — and until then, the architecture above is the honest answer to “how is my information protected?”
