Skip to content

Security

Built for privileged, financial, and court-facing records.

This page is a plain-language overview of how Law Grasp protects firm and client data. It stays at the level of what the controls do rather than how they are implemented.

Access control

Who can do what is decided on the server, on every request.

Single sign-on
SAML and OIDC single sign-on per firm, with directory group-to-role mapping, so access follows your identity provider.
Multi-factor authentication
Authenticator-app MFA with single-use recovery codes.
Step-up verification
Trust movements, ethical-wall changes, and other sensitive operations require fresh re-verification at the moment of action.
Granular permissions
Every operation is permission-checked server-side. Roles are least-privilege by default.
Ethical walls
Screened staff are excluded from restricted matters everywhere they could surface — lists, reports, and search included. Raising or lifting a wall requires a reason and is audited.
Brute-force protection
Escalating account lockouts and platform-wide rate limiting.

Data protection

Firm data is protected in layers, so no single mistake is enough to expose it.

Firm-level isolation
Each firm's data is separated at the database layer — every table holding firm data carries a database-level isolation policy — and an adversarial cross-tenant suite is run against a live database to prove it.
Encryption in transit
All traffic is encrypted in transit with modern TLS and strict transport policies.
Field-level encryption
The most sensitive identifiers — government IDs, bank details — carry an additional layer of application-level encryption with keys held outside the database. Revealing one is a separately permissioned, audited act.
Validated input
Every request is validated against a strict allow-list before it reaches business logic.
A separate client surface
The client portal runs on its own least-privilege access, valid only for that client's own matters and rejected everywhere else.

Accountability

In legal work, being able to prove what happened matters as much as preventing what shouldn't.

Tamper-evident audit trail
Every change records who, what, when, and why, with before-and-after values. The record is append-only and enforced at the database layer, and the highest-stakes trails — evidence custody, conflicts, enclave access, and e-signature — are additionally hash-chained, so altering one of those is detectable.
Mandatory reasons
Statutory dates, trust movements, invoice voids, and similar records cannot change without a documented reason.
Field-level history
See any value as of any date, with guarded revert.
Signing ceremony records
E-signature envelopes carry their own sealed event trail and a complete audit certificate.

Trust accounting integrity

Client funds get structural safeguards.

Overdraft-proof ledgers
A client ledger can never go negative, by construction.
Anti-commingling
Operating funds structurally cannot be credited into trust accounts.
Three-way reconciliation
Bank, book, and client-ledger totals reconciled together, with period locks and audit-ready reports.
Guarded movement
Transfers and disbursements require fresh re-verification and a documented reason; held or disputed funds are unspendable.

AI data policy

AI features are useful only if they are safe for privileged material. The policy is short and absolute.

No training on client data
Client data is never used to train models — ours or anyone else's.
Zero-retention endpoints only
AI providers that cannot guarantee zero retention are refused at the gateway, not discouraged by policy.
Attorneys stay in the loop
Every AI output is a labeled draft, and citations are verified against your firm's own law corpus before display.

How we build

Security controls are code, and code gets tested.

Security suites ship with the code
Isolation, injection, authorization, and header regression suites live in the codebase. The suites that need no database run automatically on every change; the database-backed ones, cross-tenant isolation included, are run against a live database.
Static analysis
Automated analysis gates every change in the delivery pipeline.
Hardened browser policies
Strict content-security policies and hardened headers on every page.

Compliance & certifications

Where Law Grasp stands against the frameworks legal work is measured by. Program items describe controls we operate today; formal attestations are listed only once they are real and in progress.

  • SOC 2

    Program

    SOC 2-aligned controls across all five Trust Services Criteria.

    A SOC 2-aligned control set spanning all five Trust Services Criteria, with a Type II evidence program designed.

  • HIPAA Security Rule

    Program

    Designed to align with the HIPAA Security Rule; BAA program for PHI.

    Designed to align with the HIPAA Security Rule, with a Business Associate Agreement program for firms handling protected health information.

  • CJIS-aligned enclave

    Program

    Criminal-history data in a CJIS-aligned, clearance-gated enclave.

    Criminal-history data is handled in a CJIS-aligned enclave: separately encrypted, clearance-gated, access hash-chained, and never sent to AI.

  • NIST 800-53 mapping

    Program

    Hardening mapped to NIST 800-53 (Moderate).

    Security hardening mapped to the NIST 800-53 (Moderate) baseline.

  • ESIGN / UETA

    Program

    E-signatures designed for ESIGN/UETA conformance.

    E-signatures designed for ESIGN/UETA conformance, with sealed audit certificates.

  • PCI (via providers)

    Program

    Payments processed by PCI-compliant providers; no card data stored.

    Payments are processed by PCI-compliant providers; Law Grasp never stores card data.

  • GDPR / CCPA readiness

    Program

    Data-subject export and legal-hold-aware erasure built in.

    Data-subject export and legal-hold-aware erasure are built in.

Want the details?

Control mappings and full security documentation are available to prospective customers on request, and you can talk directly with the people who built these systems.

Request information