Legal Centre
Security Practices
We hold tax returns, financial statements and identity information, so security is part of how the platform is built rather than something added afterwards.
In short
- Documents live in private storage reached through short-lived signed links.
- Access is role-based, and staff accounts use multi-factor authentication.
- Access to sensitive records is logged.
- No system is perfectly secure, and we do not claim otherwise.
- Report a suspected vulnerability to us directly.
Controls we use
- Private document storage, not public links
- Time-limited signed URLs for file access
- Role-based permissions at the database level
- Multi-factor authentication for staff accounts
- Audit logging of sensitive actions
- Encryption in transit
- Monitoring and alerting
- Separation between internal analysis and anything shown externally
Your part
- Use a strong, unique password
- Never share your login
- Give each adviser their own account
- Remove access when someone no longer needs it
- Tell us immediately if you think an account has been compromised
If something goes wrong
We have an internal process for containing an incident, investigating it, taking legal advice and deciding on notification. Where the law requires us to notify affected people, we do.
Reporting a vulnerability
If you believe you have found a security problem, contact our contact page with enough detail for us to reproduce it. Please do not access other people's data or disrupt the service while testing.
This document is a draft prepared for review by qualified Wisconsin counsel.
