FirmLink Legal

    Security and Data Protection

    Legal work requires more than a generic promise of security. FirmLink uses administrative, technical, and organizational safeguards designed to protect firm and client information while keeping attorneys in control of access and sensitive actions.

    Practical safeguards

    Controls built around real law-firm workflows

    These descriptions focus on the controls a firm can evaluate without publishing sensitive implementation details.

    Managed cloud infrastructure

    FirmLink runs on AWS-powered infrastructure with monitoring, backup, and recovery practices designed for dependable legal operations.

    Controlled access

    Authentication, authorization, role-based permissions, and tenant-scoping controls limit access to authorized firm users and data.

    Protected information

    FirmLink uses encrypted network connections and protected storage appropriate to supported data and document workflows.

    Expiring document access

    Supported document views use time-limited access links instead of exposing permanent storage locations.

    Separated communication

    Private internal Team discussions remain separate from secure client-facing messages and portal communication.

    Audited support access

    A firm can grant support read-only access that is time-boxed, revocable, purpose-limited, and recorded in an audit history.

    Health-related information

    Business Associate Agreements when applicable

    Some legal matters include health-related information. When a customer is a HIPAA covered entity or business associate and FirmLink creates, receives, maintains, or transmits protected health information on that customer's behalf, a Business Associate Agreement is available for electronic review and execution during onboarding.

    Applicability depends on the customer's role, the information involved, and how the workspace is used. A firm's practice area alone does not determine whether HIPAA or a BAA applies.

    Shared responsibility

    FirmLink provides safeguards and access controls for supported workflows. Each customer remains responsible for its authorized users, permissions, connected accounts, devices, exports, professional obligations, and determining whether a particular workflow is appropriate for a matter.

    No technology can eliminate every risk. FirmLink reviews and improves its safeguards as the service and threat environment evolve.

    Have a security or BAA question?

    Contact Jose for product and pre-sales questions, or visit Support if your firm already uses FirmLink.