Security & Privacy
Security is the first requirement, not a launch-week addition.
CourtDocs holds identity documents, medical information, privileged communications, court records and financial transactions. Developer priorities are ordered accordingly: security, data isolation, reliability, then everything else.
Document access levels
Six levels, set per document.
Permission is a property of the document, not of the relationship. Hiring a firm does not hand it your passport.
Private
Visible only to you. Every document starts here.
Shared With Specific Case
Visible inside one matter workspace.
Shared With Specific Attorney
Visible to one named attorney, not the whole firm.
Shared With Law Firm
Visible to the firm staff assigned to your matter.
Signature Requested
Shared for the purpose of executing a document.
CourtDocs Admin Restricted
Requires elevated authorisation and writes an audit record.
Security architecture
Built for identity documents, medical records and privileged communications.
CourtDocs holds the material people are least willing to lose. Security is the first requirement, ahead of speed of development.
Encryption everywhere
TLS in transit, AES-256 at rest, encrypted backups, and extra field-level encryption for identity numbers and medical identifiers.
MFA and passkeys
Required for attorneys and platform administrators, strongly encouraged for everyone. Biometric unlock on mobile, plus device and session management.
Permanent audit trail
Uploaded, opened, downloaded, shared, signed, deleted. Each entry records actor, action, resource, timestamp, device and result.
Tenant isolation
Every law-firm resource is bound to a tenant. Queries enforce separation, so one firm can never reach another firm’s clients or files.
Quarantine and scanning
Uploads land in quarantine and are malware-scanned before they become available. OCR and thumbnails run in background workers.
Soft delete and retention
Deleting moves a document to Deleted Items for a retention window before permanent destruction. Legal holds override deletion.
Audit trail
Thirteen event types written permanently.
Each entry captures actor, action, resource, timestamp, IP where appropriate, device or session, and result.
The test case
What happens to a birth certificate, precisely.
If a development team cannot describe this workflow end to end, they should not be trusted with the platform. Here is ours.
- 01
Encrypted and stored outside the database
The file goes to encrypted object storage under a generated identifier such as DOC-89F2A1C7. The database holds metadata only, and the storage path is never exposed to a browser.
- 02
Bound to one account
Ownership is recorded at upload. No other consumer, no unrelated attorney and no unrelated firm has a query path that returns it.
- 03
Invisible until you share it
Access level starts Private. An attorney must request access, and you decide between specific documents, the whole folder, or refusal.
- 04
Protected from CourtDocs staff
Administrators do not get implicit read access. Opening a restricted document requires elevated authorisation and produces a permanent audit record.
- 05
Audited on every access
Actor, action, resource, timestamp, IP where appropriate, device and result are written for each event, and you can read your own trail.
- 06
Backed up and recoverable
Continuous database backups, daily snapshots, encrypted object redundancy and version history. Losing your phone does not lose the document.
- 07
Revocable
Access granted can be withdrawn where legally and operationally appropriate, and the revocation is itself an audit event.
Start your briefcase
Store it. Protect it. Find counsel. Keep it for life.
Free to start. No card required. Your documents stay yours whether or not you ever hire a lawyer through CourtDocs.
Consumers · Attorneys · Law firms