Skip to main content

Security

Security and confidentiality for law firms.

Detailed security documentation is prepared with BASG and shared during evaluation. This page shows the questions it will answer and what the operating model already makes true.

  • Human oversight by design
  • Documentation shared in evaluation
  • Direct review with BASG
What the documentation covers

Eight questions every firm should ask.

A managing partner, an IT consultant, or an outside reviewer will raise the same topics. Each one is listed here with the question it answers. We do not state answers on this page until they are verified.

Access and roles

Question answered: Who at the firm and at BASG can see matter data, and how are permissions set and removed?

Status: Documentation in preparation. Confirmed during security review.

Audit trail

Question answered: Which actions are recorded, who can read the record, and how long does it last?

Status: Documentation in preparation. Confirmed during security review.

Data handling and retention

Question answered: Where is firm data stored, how long is it kept, and how is it returned or deleted when a firm leaves?

Status: Documentation in preparation. Confirmed during security review.

Model training policy

Question answered: Is firm data ever used to train or improve models, for the firm or for anyone else?

Status: Documentation in preparation. Confirmed during security review.

Subprocessors

Question answered: Which outside vendors touch firm data, for what purpose, and how are they vetted?

Status: Documentation in preparation. Confirmed during security review.

Incident response

Question answered: What happens if something goes wrong, who is told, and how quickly?

Status: Documentation in preparation. Confirmed during security review.

Encryption

Question answered: How is data protected when it is stored and when it moves between systems?

Status: Documentation in preparation. Confirmed during security review.

Infrastructure and isolation

Question answered: Where does the platform run, and how is one firm's data kept apart from another's?

Status: Documentation in preparation. Confirmed during security review.

What the design makes true today

Human oversight is part of the operating model.

These rules describe how work is assigned and approved. They do not depend on any technical control listed above.

  1. Tier 1 Automated

    Automated

    Internal preparation the firm has approved for the platform to complete on its own.

    • Sorting files
    • Tagging document types
    • Extracting dates
    • Indexing records
  2. Tier 2 Review Required

    Review Required

    Prepared by the platform and reviewed by your team before anything is used outside the firm.

    • Client messages
    • Drafts
    • Document packages
    • Records requests
  3. Tier 3 Attorney-Controlled

    Attorney-Controlled

    Professional decisions stay with attorneys. The platform prepares materials for them.

    • Legal advice
    • Strategy
    • Filing decisions
    • Non-standard terms

Exceptions are flagged, approval rules are set by the firm, and attorneys make the decisions.

What we ask of you

Keep client details off the website.

Website forms

Please do not send confidential client information through the forms on this site. Forms here are for contact details and general questions about your firm's needs.

If you need to share sensitive material during evaluation, ask first. We will agree on a method with you before anything is sent.

How a review request works

Submit the form below and say who will be reviewing. A member of the team replies to schedule a call with BASG.

Bring your questionnaire if you have one. Documentation is shared during evaluation, and each answer is confirmed with BASG before we rely on it.

  • Tell us who is reviewing and by when.
  • Send your security questionnaire or list of questions.
  • Meet with BASG to go through the topics above.
Questions

Honest answers about security.

Have a questionnaire ready? Request a security review.

Documentation is being prepared with BASG and is shared during evaluation. Request a security review and tell us who will read it. Every statement is confirmed with BASG before we share it, so you receive verified information rather than marketing claims.

A locked steel filing cabinet drawer with a key in the lock in a bright records room.

Request a security review.

Tell us who is reviewing and what they need to see. We will set up a call with BASG and share documentation as it is confirmed.

  • Bring your IT consultant or reviewer
  • Send your questionnaire with your request
  • Please do not include confidential client information

Please do not include confidential client or privilege matter information in this inquiry form.