Attorney-Client Privilege
Data belongs to your firm. We never share, sell, or use it beyond providing the FirmFirst service. Full data export and deletion on demand.
Trust Center
Technical security controls protecting your firm's data — documented and current.
Last reviewed: February 2026
Security isn't a feature — it's the foundation everything else is built on.
Data belongs to your firm. We never share, sell, or use it beyond providing the FirmFirst service. Full data export and deletion on demand.
AES-256 encryption at rest, TLS 1.3 in transit. Application-level encryption for tokens, keys, and sensitive credentials.
Hosted on Google Cloud Platform (us-central1). SOC 2 certified infrastructure. Data never leaves the United States.
Role-based access with least-privilege principles. Multi-factor authentication required for all team members. Audit logging on every access.
24/7 automated monitoring. Defined incident response procedures. Breach notification within 72 hours per GDPR requirements.
All sub-processors sign DPAs and meet SOC 2 or equivalent standards. Vendor security reviewed annually.
GDPR and CCPA compliant. Data minimization — we collect only what's needed. No tracking beyond essential analytics.
Daily automated backups. Point-in-time recovery capability. Disaster recovery procedures tested regularly.
AES-256 encryption for all stored data
TLS 1.3 for all data transmission
Tokens, keys, and credentials encrypted separately
Point-in-time recovery capability
Permissions scoped to job function
Required for all personnel
Minimum necessary permissions by default
All access events recorded and retained
US data centers (us-central1)
Isolated production environments
Cloud-native DDoS mitigation
Continuous dependency and infrastructure scanning
Documented procedures for security events
Per GDPR requirements
Sub-processor compliance verification
Mandatory onboarding and annual refresher
Third-party audit of security, availability, and confidentiality controls.
Target: Q4 2026
Data Processing Agreements available. Right to access, rectification, erasure, and portability.
DPA available on request
California Consumer Privacy Act compliance for California-based prospects.
Effective since launch
Signal analysis and verification workflows help attorneys meet 'reasonable inquiry' obligations.
Aligned since launch
Contact our security team for documentation, pen test reports, or compliance questions.