TECH LEGAL
Infrastructure Support Guidance AI Services App Dev TOS Security About
Client login Book a demo
Security & Compliance

Encryption by default

All data encrypted in transit and at rest; keys managed under your firm's control, not a shared tenant's.

Encryption by default
What this means for your firm

Privilege survives a lot of things, but it doesn't survive plaintext. Every byte the firm touches — documents, email, backups, chat — is encrypted in transit with TLS 1.2+ and at rest with AES-256. That's table stakes. What most vendors skip is key custody: who can actually decrypt your data.

We run customer-managed keys wherever the platform supports it, so your firm — not a shared multi-tenant service — holds the root of trust. Lost laptop? Full-disk encryption plus remote wipe means it's a hardware loss, not a breach notification.

What's included
TLS 1.2+ enforced for all data in transit — legacy protocols disabled
AES-256 encryption at rest across documents, email, and backups
Customer-managed encryption keys where supported; documented custody for the rest
Full-disk encryption enforced on every firm device, verified by policy
Encrypted email and secure client file exchange, matter-linked
AES-256
at rest, everywhere
TLS 1.2+
in transit, enforced
100%
device disk-encryption compliance

Key custody and encryption posture are documented per system — a one-page answer for any client questionnaire.

See encryption by default running at a firm like yours.

Start with a free gap assessment against your clients' requirements.

Book a demo All security capabilities
© 2026 TechLegal, Inc. All rights reserved.
Security Privacy Terms