Security

A practical security review for legal software vendors

Questions every firm should ask before placing confidential client information in a new platform.

← All resources

Begin with your data

Document what the vendor will receive, who can access it, where it is stored, and what happens when the relationship ends. Sensitivity and professional obligations should drive the depth of review.

Review the control areas

  • Identity, MFA, roles, and administrator controls.
  • Encryption during transmission and storage.
  • Logging, monitoring, incident response, and notification.
  • Backups, recovery testing, and service continuity.
  • Subprocessor review, contracts, and data locations.
  • Export, retention, and verified deletion.

Ask for evidence, not slogans

A certification can be useful, but it is not the entire review. Ask for current documentation, scope, exceptions, remediation practices, and the contractual commitments that actually apply to your firm.

Document the decision

Record the reviewer, evidence considered, risks accepted, required configurations, and renewal date. Revisit the assessment after material product changes or security incidents.

Follow the data through the service

Document what information enters the product, where it is stored, which integrations receive it, which vendor personnel can access it, and how exports and deletion work. A broad statement that data is encrypted does not answer these operating questions.

Pay special attention to backups, support access, analytics, artificial-intelligence features, and subprocessors. These areas often involve copies or uses of data that are not obvious from the primary workflow.

Match evidence to the risk

A low-risk scheduling tool may need a concise review. A system holding client files, credentials, payment information, or firm-wide communications deserves deeper evidence, contract review, and technical testing.

Ask for current documentation and record its date. Independent audit reports, penetration-test summaries, recovery-test results, and incident-response procedures are more useful when the firm also records exceptions and planned follow-up.

Make the decision reusable

  • Name the business owner and approved use.
  • Record data types and prohibited data.
  • List required configuration, such as SSO or MFA.
  • Track contract commitments and unresolved exceptions.
  • Set a review date based on risk and material changes.
  • Document an exit and data-return path.

Turn the review into practical safeguards

Approval should produce a short set of instructions people can follow. Record who may use the service, which information may be placed in it, which sign-in protections must be enabled, and where staff should report a concern. If the review identifies a restriction, put that restriction near the workflow instead of leaving it buried in a procurement file.

Assign one person to own the relationship and another appropriate person to review security questions. The business owner watches how the service is used; the reviewer tracks material changes, incidents, contract dates, and unresolved findings. This division keeps security from becoming a one-time questionnaire that no one revisits.

Finally, plan the exit while the relationship is healthy. Confirm how the firm can export useful records, how access will be removed, what must be retained for legal or professional reasons, and how deletion requests are handled. A workable exit plan is part of protecting client information because it prevents rushed decisions when a contract ends.

Related resources

Explore a more connected firm.

See how LegalsOne brings intake, matters, documents, billing, training, and reporting into one configurable platform.

Book a conversation