Core security is included
Encryption, MFA, tenant isolation, audit, safe telemetry, malware protection, least-privilege controls, incident response, and secure development are not premium unlocks.
Security and compliance
Simply Legal treats confidentiality as part of the product: matter-level access boundaries, accountable administration, governed files and AI, and evidence your firm can use in client, carrier, and vendor reviews.
How Simply Legal approaches security
Confidentiality cannot depend on one administrator remembering every setting. The platform starts with a safety floor, then lets firm, client, carrier, and matter requirements make behavior stricter.
Encryption, MFA, tenant isolation, audit, safe telemetry, malware protection, least-privilege controls, incident response, and secure development are not premium unlocks.
The firm can restrict replay, analytics, support access, AI, connectors, exports, retention, sessions, and matter access without weakening the platform safety floor.
Platform safeguards, firm policy, client or carrier requirements, matter policy, permissions, authentication, and consent resolve to one explainable decision. Missing policy does not become permission.
Confidentiality controls
One authorization and policy model follows firm data through records, files, search, AI, integrations, background work, sharing, and deletion.
Restricted matters require explicit access, including for administrators when the firm chooses. Unauthorized people cannot discover names, counts, files, search results, relationships, or derived work product.
Confidentiality, privilege, attorney-work-product, and contractual handling labels follow records into files, OCR, search, citations, generated documents, background work, exports, and AI outputs.
Firm policy governs sign-in methods, federation, directory lifecycle, session lifetime, idle timeout, device sessions, reauthentication, and step-up checks for sensitive actions. Deprovisioning ends access, not just visibility.
Security, directory, audit, and data responsibilities can be separated. Emergency access is justified, approved, time-limited, notified, automatically expired, and immutably reviewed.
Firm-visible support access is off by default, purpose-bound, narrowly scoped, short-lived, and revocable. Remote assistance also requires the current user’s consent.
Files are validated and malware-scanned before users, OCR, search, AI, exports, or connectors can touch them. Hashes, provenance, scan results, scope, and classification survive every transformation.
Archive, soft delete, hard delete, and legal hold are distinct. Holds preserve without granting access, while deletion tracks records, files, versions, OCR, indexes, embeddings, caches, AI data, telemetry, exports, and backup aging.
Firm and matter policy can control formats, recipients, destinations, bulk thresholds, expiring links, approvals, watermarks, DLP checks, and anomaly alerts across the app, API, agents, jobs, and connectors.
AI can be disabled by firm, client, carrier, matter, task, provider, or model. Retrieval filters before content reaches a model, customer data is not used for model training, and sourced work product preserves version and passage context.
High-stakes work product and external actions follow configured review and approval. Unsupported statements are marked, irreversible actions use the canonical authorization path, and outside AI clients cannot bypass firm policy.
The firm can allowlist managed workspaces and OAuth clients, prohibit personal tools, choose read-only, proposal-only, or direct-write modes, and audit every actor, client, tool, object, and outbound event.
Private encrypted data stores, managed edge protections, configuration and threat monitoring, content-security controls, dependency and secret checks, incident drills, restore tests, and independent penetration testing support the operating program.
Compliance and assurance
Controls are useful only when they are current, tested, documented, and scoped honestly. Simply Legal maintains evidence for firm, client, carrier, insurer, and procurement review.
Each control has an owner, test, evidence source, refresh cadence, exception process, and scoped mapping to relevant buyer and regulatory frameworks.
Security and data-flow documentation, DPA and subprocessor information, incident commitments, retention and deletion terms, continuity and recovery summaries, AI terms, testing evidence, and questionnaire answers stay tied to current evidence.
Application and cloud penetration testing, remediation and retesting, access reviews, incident and recovery exercises, deletion tests, vendor review, and a maintained SOC 2 control environment substantiate the claims the firm evaluates.
Customer staging uses synthetic or curated data, environment-local secrets, immutable release candidates, compatibility and binding checks, separate approvals, production configuration locks, and audited break glass.
Control mappings and security profiles help a firm evaluate and configure the service; they do not by themselves certify the firm, a matter, or a workflow. Framework, contractual, and professional-responsibility applicability depends on the firm’s configuration, data flows, jurisdiction, clients, carriers, and obligations.
Optional deployment choices
Most firms receive the full security and governance floor in their plan. Separate packaging is reserved for capabilities that create dedicated infrastructure, exceptional retention, or customer-specific assurance work.
For firms that need formal UAT or separation of duties: a customer-facing staging environment, selected-user access, immutable promotion evidence, and separate create, approve, and deploy permissions.
Dedicated regions or environments, private connectivity, customer-managed encryption keys, and other infrastructure isolation are scoped when client contracts or firm policy require the additional boundary.
Unusually long evidence retention, customer-specific control mappings, procurement packages, and dedicated assurance support are quoted when they create material storage or professional-services work.
Show us how a new matter reaches the firm today — the forms, the inbox, the spreadsheet. We will map it to Simply Legal and show you the version that never drops an inquiry.