Security & Compliance

Enterprise-Grade Security
for Law Firms

Your clients trust you with their most sensitive information. We protect it with independently audited infrastructure, end-to-end encryption, and defense-in-depth security controls.

SOC 2 Type 2 Infrastructure
AES-256 Encrypted
PCI DSS Level 1
HTTPS Enforced

Infrastructure

Built on SOC 2 Type 2 Certified Infrastructure

Every layer of our infrastructure stack has been independently audited and certified to SOC 2 Type 2 or PCI DSS standards.

ProviderPurposeCertificationDetail
Backblaze B2Document StorageSOC 2 Type 2December 2025 audit, no exceptions noted
NeonDatabase (PostgreSQL)SOC 2 Type 2Continuous compliance with point-in-time recovery
VercelHosting & Edge NetworkSOC 2 Type 2Global edge network with automatic TLS
StripePayment ProcessingPCI DSS Level 1Highest level of payment security certification

Security Controls

Defense in Depth

Multiple layers of security controls protect your data at every stage — at rest, in transit, and at the application layer.

AES-256-GCM Encryption

All documents and sensitive fields are encrypted at rest using AES-256-GCM. Encryption keys are rotated and never stored alongside data.

TLS 1.3 In Transit

Every connection is encrypted with TLS 1.3. HTTPS is enforced across all endpoints with HSTS headers.

Two-Factor Authentication

TOTP-based 2FA with backup codes and trusted device management. Available for all user accounts.

Comprehensive Audit Logging

Every sensitive operation is logged with user, timestamp, IP, and action detail. Immutable audit trail for compliance.

Role-Based Access Control

Six-role permission system with per-feature granularity. Every API route enforces authorization checks.

Multi-Tenant Isolation

All database queries are scoped to firm ID. No cross-tenant data access is possible at the application layer.

Webhook Signature Validation

All incoming webhooks (Stripe, Twilio, Clio) are cryptographically validated before processing.

PCI-Compliant Payments

Payment data never touches our servers. All billing flows through Stripe with PCI DSS Level 1 certification.

Application Audit

NYL application-level SOC 2 Type 1 audit in progress — Q3 2026

Our infrastructure providers are SOC 2 Type 2 certified. The NYL application itself is undergoing its own SOC 2 Type 1 audit, expected to complete in Q3 2026. We implement SOC 2-aligned controls across our entire application layer today.

Questions about security?

Our team is happy to discuss our security posture, provide documentation, or schedule a security review call.