How LegalCaseManager protects attorney–client privilege, personal information under POPIA, and your sensitive case data.
Legal professional privilege is preserved. Attorney–client communications, draft pleadings, work-product and strategy notes stored on the Platform remain privileged. The Platform is used by your firm as a confidential tool for the purposes of legal advice and litigation, and disclosure to Platform infrastructure providers under a written confidentiality obligation does not constitute a waiver.
All data moving between your browser and the Platform is encrypted over TLS 1.2 or higher (HTTPS). Unencrypted connections are refused at the edge.
All case records, documents, statements, testimonies, analyses and uploaded files are encrypted at rest using AES-256 on managed database and object storage.
Passwords are never stored in plain text. We hash every password with bcrypt (cost factor 12) and one-time verification codes are stored as single-use hashes with short expiry windows.
TLS certificates are renewed automatically and the Platform enforces HSTS for all sessions.
Your matters live behind a hard ring-fence designed around how a law firm actually works:
The ring-fence is enforced by the application for every request \u2014 it is not a setting that can be disabled from the UI.
Your matters are never used to train any AI model.
LegalCaseManager is built to support your firm’s obligations under the Protection of Personal Information Act 4 of 2013 (POPIA) as a responsible party. In the relationship between your firm (responsible party) and LegalCaseManager (operator), we process personal information only on the documented instructions that arise from your use of the Platform.
The full POPIA statement, including the Information Officer contact details and lawful basis mapping, is set out at /popia-compliance.
Every action that touches a matter is written to an append-only audit log:
Each entry captures the actor, the resource, the timestamp and the outcome. Audit entries cannot be edited or removed through the application, and they are retained for a minimum of 12 months so that the trail is available for a professional complaint, a disciplinary review, or a court-ordered forensic inspection.
Firm administrators with the audit-log role can filter and export the log as CSV from within the Platform.
Access to data is controlled by the role each user holds on a matter:
Every data-fetching API double-checks the caller’s role against the matter before returning results. A user without a role on a matter cannot see that the matter exists.
Every sign-in requires a second factor. After a valid email and password, we send a one-time code to the registered email address. The code is short-lived, single-use, and is checked against a hashed copy — never compared in plain text.
LegalCaseManager runs on managed, production-grade cloud infrastructure with enterprise certifications (including ISO 27001 and SOC 2 reporting from the underlying providers). The Platform is deployed as a closed, single-purpose application:
Infrastructure providers who necessarily process data to host the Platform (hosting, managed database, object storage, email delivery) are bound by written confidentiality and data-processing obligations. They do not have a legal right to read, repurpose or train on your matter data.
If you believe you have found a vulnerability, or you would like more detail on any control set out on this page, please contact us at [email protected] with the subject line [SECURITY]. We acknowledge reports within 48 hours.
See also: POPIA Compliance · Privacy Policy · Terms of Service