Security & data handling
Built for confidential legal and medical-record workflows. BAA available. Attorneys about to hand over client files deserve controls described plainly — not a compliance badge with no substance behind it.
Controls in practice
- TLS in transit; private object storage with public access blocked.
- Authentication required before upload; server-side authorization on every case request.
- Short-lived signed upload URLs; files never stream through the web app by default.
- Quarantine validation, malware scanning, and UUID object names with no PHI in paths.
- Audit logging on file access; 30-day evaluation retention with deletion confirmation.
- No PHI in analytics events, email subjects, or marketing pixels on secure routes.
- No model training on your cases, ever. Your data is your data.
Access controls
- MFA for operator and admin accounts.
- Least-privilege service roles for processing jobs.
- Immutable audit logging of file access and agreement acceptance.
Customer responsibilities
You confirm you have authority to submit the records, that attorneys review all deliverables before use, and that PHI is never entered into public marketing forms. The secure portal is the only upload path for case materials.
What we don't claim
There is no HHS certification program for business associates. We describe our actual controls and sign a BAA instead of using "HIPAA compliant" as a badge.
Agreements and related pages
See what happens to your documents, the BAA, Evaluation Terms, and our Privacy Policy. Procurement questions that do not include PHI can go through contact or a demo.
Controls first. Then a closed case.
Your first demand letter is free. We'll build it from a real closed case of yours so you can judge the work, not the pitch. No credit card. Built for confidential legal and medical-record workflows. BAA available.
No credit card · No subscription · 24–48 hr turnaround · BAA available