Security
Built for privileged, financial, and court-facing records.
This page is a plain-language overview of how Law Grasp protects firm and client data. It stays at the level of what the controls do rather than how they are implemented.
Access control
Who can do what is decided on the server, on every request.
- Single sign-on
- SAML and OIDC single sign-on per firm, with directory group-to-role mapping, so access follows your identity provider.
- Multi-factor authentication
- Authenticator-app MFA with single-use recovery codes.
- Step-up verification
- Trust movements, ethical-wall changes, and other sensitive operations require fresh re-verification at the moment of action.
- Granular permissions
- Every operation is permission-checked server-side. Roles are least-privilege by default.
- Ethical walls
- Screened staff are excluded from restricted matters everywhere they could surface — lists, reports, and search included. Raising or lifting a wall requires a reason and is audited.
- Brute-force protection
- Escalating account lockouts and platform-wide rate limiting.
Data protection
Firm data is protected in layers, so no single mistake is enough to expose it.
- Firm-level isolation
- Each firm's data is separated at the database layer — every table holding firm data carries a database-level isolation policy — and an adversarial cross-tenant suite is run against a live database to prove it.
- Encryption in transit
- All traffic is encrypted in transit with modern TLS and strict transport policies.
- Field-level encryption
- The most sensitive identifiers — government IDs, bank details — carry an additional layer of application-level encryption with keys held outside the database. Revealing one is a separately permissioned, audited act.
- Validated input
- Every request is validated against a strict allow-list before it reaches business logic.
- A separate client surface
- The client portal runs on its own least-privilege access, valid only for that client's own matters and rejected everywhere else.
Accountability
In legal work, being able to prove what happened matters as much as preventing what shouldn't.
- Tamper-evident audit trail
- Every change records who, what, when, and why, with before-and-after values. The record is append-only and enforced at the database layer, and the highest-stakes trails — evidence custody, conflicts, enclave access, and e-signature — are additionally hash-chained, so altering one of those is detectable.
- Mandatory reasons
- Statutory dates, trust movements, invoice voids, and similar records cannot change without a documented reason.
- Field-level history
- See any value as of any date, with guarded revert.
- Signing ceremony records
- E-signature envelopes carry their own sealed event trail and a complete audit certificate.
Trust accounting integrity
Client funds get structural safeguards.
- Overdraft-proof ledgers
- A client ledger can never go negative, by construction.
- Anti-commingling
- Operating funds structurally cannot be credited into trust accounts.
- Three-way reconciliation
- Bank, book, and client-ledger totals reconciled together, with period locks and audit-ready reports.
- Guarded movement
- Transfers and disbursements require fresh re-verification and a documented reason; held or disputed funds are unspendable.
AI data policy
AI features are useful only if they are safe for privileged material. The policy is short and absolute.
- No training on client data
- Client data is never used to train models — ours or anyone else's.
- Zero-retention endpoints only
- AI providers that cannot guarantee zero retention are refused at the gateway, not discouraged by policy.
- Attorneys stay in the loop
- Every AI output is a labeled draft, and citations are verified against your firm's own law corpus before display.
How we build
Security controls are code, and code gets tested.
- Security suites ship with the code
- Isolation, injection, authorization, and header regression suites live in the codebase. The suites that need no database run automatically on every change; the database-backed ones, cross-tenant isolation included, are run against a live database.
- Static analysis
- Automated analysis gates every change in the delivery pipeline.
- Hardened browser policies
- Strict content-security policies and hardened headers on every page.
Compliance & certifications
Where Law Grasp stands against the frameworks legal work is measured by. Program items describe controls we operate today; formal attestations are listed only once they are real and in progress.
SOC 2
ProgramSOC 2-aligned controls across all five Trust Services Criteria.
A SOC 2-aligned control set spanning all five Trust Services Criteria, with a Type II evidence program designed.
HIPAA Security Rule
ProgramDesigned to align with the HIPAA Security Rule; BAA program for PHI.
Designed to align with the HIPAA Security Rule, with a Business Associate Agreement program for firms handling protected health information.
CJIS-aligned enclave
ProgramCriminal-history data in a CJIS-aligned, clearance-gated enclave.
Criminal-history data is handled in a CJIS-aligned enclave: separately encrypted, clearance-gated, access hash-chained, and never sent to AI.
NIST 800-53 mapping
ProgramHardening mapped to NIST 800-53 (Moderate).
Security hardening mapped to the NIST 800-53 (Moderate) baseline.
ESIGN / UETA
ProgramE-signatures designed for ESIGN/UETA conformance.
E-signatures designed for ESIGN/UETA conformance, with sealed audit certificates.
PCI (via providers)
ProgramPayments processed by PCI-compliant providers; no card data stored.
Payments are processed by PCI-compliant providers; Law Grasp never stores card data.
GDPR / CCPA readiness
ProgramData-subject export and legal-hold-aware erasure built in.
Data-subject export and legal-hold-aware erasure are built in.
Want the details?
Control mappings and full security documentation are available to prospective customers on request, and you can talk directly with the people who built these systems.
Request information