Start your 7-day trial No card. Workspace opens immediately.
Start free
Security & UK GDPR

Modern doesn’t mean less secure.

SolicitorOS helps law firms manage sensitive practice records through isolated workspaces, permission controls, matter-level organisation and audit-ready activity records.

Security features

Built around protecting client data.

Firm-level isolation

Every firm’s data is separated by design and enforced at the database layer, not by a setting that can be forgotten.

Role & permission controls

Fine-grained, assigned-only access so each user sees only the work and information they should.

Permission-checked documents

Private document storage; downloads are access-controlled and served only to authorised users.

Audit activity

Key workspace actions are logged so the firm can see who did what, supporting accountability.

Private storage

Uploaded files are kept out of the public web root and never exposed by a guessable link.

Token-protected feeds

Calendar (ICS) feeds are protected by private tokens you can reset at any time.

Two-factor authentication

Any authenticator app, with single-use recovery codes and remembered devices. A firm can require it for every user, and the workspace stays shut until it is on.

Secrets encrypted at rest

Two-factor secrets, payout details, webhook signing secrets and connected-service credentials are stored encrypted; API tokens are stored only as hashes and shown once.

Signed integrations

Every webhook delivery carries an HMAC-SHA256 signature with a timestamp; API access is per-firm, per-token, read or write, rate-limited and revocable at any time.

Transport and headers

HTTPS everywhere with HSTS, strict referrer and frame policies, and a published security.txt so researchers know where to report a problem.

Tested on every release

More than a thousand automated tests, including firm-isolation checks on every record type, run before any change reaches production; nightly database backups are kept for a rolling window.

UK GDPR-aware practice management

SolicitorOS includes client fields for UK GDPR consent status and MLR 2017-style onboarding status. These tools support better practice administration and recordkeeping discipline — but they do not replace the firm’s own legal obligations.

Important limitation

SolicitorOS supports recordkeeping, access control and audit readiness. It does not guarantee legal, regulatory, accounting, trust-accounting or UK GDPR compliance. Each firm remains responsible for its own compliance, client notices, consent records and professional obligations.

Whatever you practise

The dates the practice itself has to keep.

Not the dates on the files — the ones the practice carries because it is a practice. They do not change with the kind of work, and SolicitorOS records them, dates them and reminds you. It records and reminds; the firm still acts.

Practising certificate

The certificate that lapses on 31 October

Recorded per practitioner. A certificate nobody has captured reads as not recorded rather than as in order, and says so: every practising solicitor needs one, and it lapses at the end of the year. A lapsed one says what that means.

The year

Council fees, indemnity, CPD, the PAIA manual

In one list in date order, with the accountant's report six months after year end and the monthly reconciliations beside them. The practice calendar is a list of dates, not a folder of PDFs somebody has to remember to open.

Monday

Emailed to the administrators every week

The compliance digest goes out on Monday mornings without anybody asking for it, because the dates that get missed are the ones nobody owns.

MLR 2017

Identify, risk-rate, screen, record who really owns it

Screening runs against the FIC targeted financial sanctions list and the UN, OFAC, OFSI and EU lists. Beneficial ownership and politically exposed person approvals are recorded against the client, with the date and the person who decided.

Retention

UK GDPR says no longer than you need it. Seven statutes disagree.

The schedule holds both, with the floor named: SRA Accounts Rules rule 13, six years for accounting records; MLR 2017 regulation 40, five years from the end of the relationship. Employment and tax records carry their own floors, set per firm. A matter that carries a client account entry cannot be removed, and the app says which rule stopped it.

Requests

A data subject asks, and the clock starts

Thirty days, extendable once by thirty more with a reason, as PAIA sections 25 and 26 allow. Every request is logged with what was asked, what was done and when — which is the part a regulator asks to see.

You can read your own audit trail.

Every sign-in, matter, invoice, trust movement and document is recorded as it happens, with the person, the time and the address it came from. A firm administrator reads it inside the workspace in plain English, filters it by person, kind or date, and downloads it for a file, an auditor or an insurer. It is written by the application and cannot be edited from anywhere in the workspace.

Is the service up?

Availability is measured every five minutes from inside the service and published, incidents and all, on the service status page. The same figures are machine-readable at /status.json.

Serious enough for serious firms.

Start a secure SolicitorOS workspace in minutes.

Start free trial