Resource Center
Trust Center
Client data on this platform is privileged material. This page is where the firm documents what protects it — the certifications it holds, who processes data on its behalf, how long records are kept, and what happens when something goes wrong.
Not yet published. The layout below is complete; the claims are not. Every certification, subprocessor and commitment on a trust page is a representation a client can rely on, so none has been written for you. Fill in the marked blocks — or remove any section the firm doesn’t intend to make a commitment on — before this page goes live.
Certifications and audits
What the firm has been assessed against, by whom, and when.
Placeholder — firm to supply
Each certification or attestation the firm actually holds: the standard, the audit period, the auditor, and where the report can be requested.
SOC 2, ISO 27001, HIPAA and CJIS are the ones clients ask about. List only what you hold and can evidence — an unearned badge here is a misrepresentation, not marketing.
How client data is protected
Encryption, access control, and where data lives.
Placeholder — firm to supply
Encryption in transit and at rest — the protocols and key management in use.
Placeholder — firm to supply
Access control — who at the firm can reach client data, under what authorisation, and how that access is logged.
Placeholder — firm to supply
Data residency — which regions client data is stored and processed in.
Placeholder — firm to supply
Retention and deletion — how long records are kept and what happens on termination.
Subprocessors
The third parties that process client data on the firm's behalf.
Placeholder — firm to supply
A table of every subprocessor: name, what it does, what data it touches, and the region it processes in.
Clients on a DPA are usually entitled to notice before this list changes — say how that notice is given.
Confidentiality and privilege
The obligations that come with being a law firm, not just a platform.
Placeholder — firm to supply
How privilege and confidentiality are preserved across the platform — conflicts screening, matter-level access, and what the firm's own staff can see.
Reporting a security issue
Where to send it, and what happens next.
Placeholder — firm to supply
A monitored security contact address, the disclosure policy, and the response times the firm commits to.
A trust page without a reachable contact is the one gap researchers complain about. Worth landing first.
Legal documents
The agreements behind the commitments above.
The Terms & Conditions and Privacy Policy currently open as panels from the home page, so there is no address to link a client to.
Placeholder — firm to supply
Give Terms and Privacy their own URLs, and add the DPA, BAA and subprocessor agreement here.
A trust page is normally cited in procurement review — every document on it needs a link that survives being pasted into an email.