SolicitorOS helps law firms manage sensitive practice records through isolated workspaces, permission controls, matter-level organisation and audit-ready activity records.
Every firm’s data is separated by design and enforced at the database layer, not by a setting that can be forgotten.
Fine-grained, assigned-only access so each user sees only the work and information they should.
Private document storage; downloads are access-controlled and served only to authorised users.
Key workspace actions are logged so the firm can see who did what, supporting accountability.
Uploaded files are kept out of the public web root and never exposed by a guessable link.
Calendar (ICS) feeds are protected by private tokens you can reset at any time.
Any authenticator app, with single-use recovery codes and remembered devices. A firm can require it for every user, and the workspace stays shut until it is on.
Two-factor secrets, payout details, webhook signing secrets and connected-service credentials are stored encrypted; API tokens are stored only as hashes and shown once.
Every webhook delivery carries an HMAC-SHA256 signature with a timestamp; API access is per-firm, per-token, read or write, rate-limited and revocable at any time.
HTTPS everywhere with HSTS, strict referrer and frame policies, and a published security.txt so researchers know where to report a problem.
More than a thousand automated tests, including firm-isolation checks on every record type, run before any change reaches production; nightly database backups are kept for a rolling window.
SolicitorOS includes client fields for UK GDPR consent status and MLR 2017-style onboarding status. These tools support better practice administration and recordkeeping discipline — but they do not replace the firm’s own legal obligations.
SolicitorOS supports recordkeeping, access control and audit readiness. It does not guarantee legal, regulatory, accounting, trust-accounting or UK GDPR compliance. Each firm remains responsible for its own compliance, client notices, consent records and professional obligations.
Not the dates on the files — the ones the practice carries because it is a practice. They do not change with the kind of work, and SolicitorOS records them, dates them and reminds you. It records and reminds; the firm still acts.
Recorded per practitioner. A certificate nobody has captured reads as not recorded rather than as in order, and says so: every practising solicitor needs one, and it lapses at the end of the year. A lapsed one says what that means.
In one list in date order, with the accountant's report six months after year end and the monthly reconciliations beside them. The practice calendar is a list of dates, not a folder of PDFs somebody has to remember to open.
The compliance digest goes out on Monday mornings without anybody asking for it, because the dates that get missed are the ones nobody owns.
Screening runs against the FIC targeted financial sanctions list and the UN, OFAC, OFSI and EU lists. Beneficial ownership and politically exposed person approvals are recorded against the client, with the date and the person who decided.
The schedule holds both, with the floor named: SRA Accounts Rules rule 13, six years for accounting records; MLR 2017 regulation 40, five years from the end of the relationship. Employment and tax records carry their own floors, set per firm. A matter that carries a client account entry cannot be removed, and the app says which rule stopped it.
Thirty days, extendable once by thirty more with a reason, as PAIA sections 25 and 26 allow. Every request is logged with what was asked, what was done and when — which is the part a regulator asks to see.
Every sign-in, matter, invoice, trust movement and document is recorded as it happens, with the person, the time and the address it came from. A firm administrator reads it inside the workspace in plain English, filters it by person, kind or date, and downloads it for a file, an auditor or an insurer. It is written by the application and cannot be edited from anywhere in the workspace.
Availability is measured every five minutes from inside the service and published, incidents and all, on the service status page. The same figures are machine-readable at /status.json.