Security at a glance
How client data is protected. TrusteeClear is software infrastructure, not a law firm. In a law firm's tenant, the firm's attorneys control all legal work and approvals; website trustees make their own decisions.
Your browser
TrusteeClear app
Sign-in + tenant proxy — every request scoped to your firm or matter
Postgres with row-level security
Your tenant's rows only — enforced in the database, tested in CI
Encrypted document storage
Governed AI gateway
Spend ceiling, tripwires, no training on your data
The audit chain
Recorded events · Trust Receipts hash-chained
How your clients' data is protected
- Tenant isolation. Every firm's data is separated at the database level by Row-Level Security — one firm can never see another's matters. Enforced in the database, not just the app, and covered by an automated test suite.
- Encryption. Data is encrypted in transit (HTTPS/TLS) and at rest.
- Document security. Trusts, death certificates, and financial documents live in private storage with signed, matter-scoped access — never public URLs, never emailed as attachments.
- Access control. Passwordless magic-link sign-in for end-user accounts, server-only privileged credentials, per-firm staff roles, and separated, logged platform administration.
- Audit trail. Security-relevant access and workflow events are written to append-only audit records. Coverage is expanding; we do not claim that every action is logged.
- AI handling. AI organizes documents and extracts what they say; it does not converse with consumers and does not provide legal advice. Software-extracted information is not attorney-reviewed. In firm workflows, final legal outputs require the firm's attorney approval before delivery. Our AI vendor terms prohibit training on client data, and the model provider may retain API inputs and outputs for up to 30 days for safety monitoring before deletion.
- Backups & recovery. Managed infrastructure provides automated backups. Periodic restore drills are planned; TrusteeClear does not yet claim a completed restore-testing program.
- Incident response. A documented runbook with defined severities, containment steps, and notification.
Compliance posture
- SOC 2 Type II: on our roadmap — the control practices described on this page operate today; a certified report is not yet available and we will not claim one until it is.
- Data Processing Addendum: available — TrusteeClear acts as your data processor; your firm remains the controller.
- UPL / Fla. Bar Op. 24-1: built around attorney-controlled outputs inside firm workspaces — a final legal document is released only with that firm's attorney's approval. Website users receive self-help forms and record-keeping only: no attorney review, and no AI writes to them.
- Accessibility. built to WCAG 2.2 AA with automated scans, keyboard automation and source guards on every release; the accessibility statement and the conformance report (VPAT 2.5 layout) are public. Accessibility statement and conformance report
Provenance & audit trail
Trust Receipts and selected governed workflows record what was generated, the source references, the citations, and the review or approval events, in append-only records. Coverage is not universal: a result has a durable provenance record only when the account shows one.
Subprocessors
Every provider that processes data for TrusteeClear is listed with its purpose, data categories, region, status and controls. See the provider inventory
Questions?
For a security questionnaire or our DPA, contact security@trusteeclear.com.