Our Commitment to Security
Law firm data is among the most sensitive data there is. We take the security of the information you share with Scalomation seriously, and we design the implementations we deliver around the ABA Formal Opinion 512 requirements and your firm's own security obligations. This page sets out what that looks like in practice.
Encryption & Data Protection
All data transmitted to and from Scalomation systems is protected using:
- 256-bit SSL/TLS encryption for all communications
- AES-256 encryption for data at rest
- Secure key management and rotation protocols
- End-to-end encryption for sensitive documents
Compliance Approach
Enterprise infrastructure, firm-approved tools. We design and implement AI systems on enterprise platforms that maintain their own SOC 2 and equivalent security certifications. Where your firm has existing security and data-handling requirements, our Statement of Work names the tools approved for use, and anything outside that list is written out of scope before work begins.
Our approach aligns with recognised standards:
- Data minimisation by design: our implementations are built to route confidential information only through firm-approved, confidentiality-compliant tools, supporting your firm's GDPR and CCPA posture.
- Standard alignment: our internal security protocols draw on the NIST Cybersecurity Framework and ABA Formal Opinion 512 requirements for legal technology.
Access Controls
We implement strict access controls to protect your data:
- Role-based access control (RBAC)
- Multi-factor authentication (MFA) for all staff
- Principle of least privilege for data access
- Comprehensive audit logging of all data access
- Regular access reviews and revocation procedures
Infrastructure Security
Our infrastructure is designed with security as a foundational principle:
- Hosted on enterprise-grade cloud infrastructure
- Redundant systems and failover mechanisms
- Regular security patching and updates
- Intrusion detection and prevention systems
- DDoS protection and mitigation
Data Handling Practices
We are honest about what data Scalomation touches and what it does not.
- Operational data from your firm (names, emails, firm information submitted through forms on our website) is processed through standard web infrastructure and email tooling to fulfil your request, then retained according to the policies in our Privacy Policy.
- Confidential client information from your firm's matters is not submitted to Scalomation through any standard workflow, and our implementations are designed so that it does not pass through Scalomation systems. Any exceptions are named explicitly in the Statement of Work and require your express consent.
- Implementations we design and hand off operate inside your firm's existing tool stack, under your firm's control, after handoff.
- We do not share data with third parties beyond the service providers required to deliver the engagement, and we do not sell data under any circumstances.
Incident Response
If a security incident occurs that materially affects your firm's data:
- Notification within 24 hours of discovery via email and phone
- A written incident report identifying scope, cause, and remediation steps
- Coordination with your firm's own incident response protocols and, if applicable, your cyber insurance carrier and counsel
- Post-incident review and documented changes to prevent recurrence
Third-Party Platforms
Our implementations integrate with the practice management, email, and AI platforms your firm approves for use. We vet the platforms we recommend, but data security within those platforms remains the responsibility of the platform providers and of your firm under its existing agreements with them.
Before work begins, we document which platforms are in scope, what data passes through them, and which security responsibilities sit with Scalomation, with the platform, and with the firm. We do not introduce new platforms into your stack without your written approval.
- Security assessment of every platform we recommend
- Contractual clarity on where security responsibilities sit
- No new platforms added to your stack without written approval
- Immediate notification if we identify a security concern in the implementation
Employee Security Training
All Scalomation employees undergo regular security training:
- Annual security awareness training
- Phishing simulation and testing
- Data protection and privacy training
- Incident response drills
Implementation Integrity
Every AI implementation we deliver goes through rigorous testing before handoff:
- Functional and security testing on every custom implementation
- Logic-gate verification to prevent unintended data exposure
- Continuous validation of implementation integrity during delivery
- Rapid remediation of any identified issues prior to handoff
Contact & Reporting
If you have security concerns or wish to report a vulnerability, please contact us at security@scalomation.com. We take all security reports seriously and will investigate promptly.
Updates to Security Standards
We regularly review and update our security standards to reflect evolving threats and industry best practices. This page will be updated to reflect any material changes.