Security and data
Last updated:
A law firm asks where its data goes before it asks about features. This page answers the procurement questions with the facts we actually have. No badges. Architecture.
1. Hosting
The application, its database and your uploaded files run on infrastructure located in the European Union. Data is encrypted in transit with TLS; in the object storage holding your uploaded files the content is encrypted at rest by the storage provider, and database backups are encrypted before they leave the server. The server running the application has no disk-level encryption.
We choose to host in the EU, which brings the data under the protection of the GDPR regime and a legal framework that can be audited.
2. The matter boundary
Access to your firm’s own documents is scoped to the matter they belong to. One client’s documents do not surface while a lawyer works on another.
This is not a filter, it is the default. The separation professional confidentiality requires is made into behaviour nobody has to remember.
Tenant separation is applied server side; no parameter sent by the client can change that boundary.
3. Deletion and retention
Delete a document and the original, its extracted text and its index entries go with it. If the deletion chain cannot complete, the operation fails and stops rather than half-deleting.
You can export your data before closing your account. On closure the uploaded originals are removed from object storage first and the account records after. If any step of that chain cannot complete, the closure fails and nothing is deleted; it is reported as complete only once the whole erasure is.
Uploaded originals are not backed up. On closure they are deleted immediately and irreversibly, and no other copy of them exists.
Database backups are encrypted and held separately; by their nature a single account's data cannot be selectively removed from them. Instead they are kept for a fixed 30 days: after your account is closed, your database records remain in backups for at most 30 days and are then deleted automatically. During that window the backups are held for disaster recovery only and are used for nothing else.
4. Accounts and access
Access is managed by role under a firm account. Invitations and seat count are controlled by the firm administrator.
Email verification is required at signup.
5. Certification status
We hold no security certification: no SOC 2, no ISO 27001, nothing comparable.
We write that plainly. Implying a credential we do not have is the first thing an auditor in a procurement process notices, and it damages trust more than silence does. Everything listed above is true today and can be verified.
6. Data processing agreement
For personal data your firm is the controller and we are the processor, acting on your instructions.
A data processing agreement is available on request. Write to lagel.reitnorf@ofni.