Security

Your clients’ matters,
separated from everyone else’s.

A practice is being asked to put its client list, its matters and its ledger into someone else’s system. This page says how that is kept apart, and names the file each answer comes from.

One organisation per firm

Every firm is its own organisation, with its own offices and departments. Forty-six of the fifty-two tables carry an organisation_id, and queries filter on it — 253 explicit filters across the endpoints.

app/models/models.py

Eight roles, not four

SUPER_ADMIN, ADMIN, SUB_ADMIN, AUTHORIZED_MEMBER, RESTRICTED_MEMBER, CLIENT_CONTACT, CLIENT and JUDGE. A member sees the offices and departments they belong to, and nothing else.

app/core/auth_context.py

A sub-admin is deliberately short of three powers

They cannot remove an Admin, create offices or departments, or grant admin control to another member. Those three are refused at their own endpoints rather than left to convention.

is_full_admin, app/core/auth_context.py

A judge login is sandboxed

A judge sees their own profile, the cases they preside over and the proceedings on those cases. Everything else returns 403.

app/core/auth_context.py

A client sees only their own matters

A client contact logs in to a portal scoped to the matters they are attached to. Access is granted deliberately, per person, per matter.

app/core/dependencies.py

Accounts records who did what

Every write in the Accounts module records the person, the time, and — on updates and deletes — a snapshot of the record before and after. A closed period then refuses further writes, with an explicit admin bypass.

app/core/accounts_audit.py, app/core/period_close.py

Plainly

What we do not claim

Separation is row-level, not physical.
Firms share one database and one schema. Separation is enforced by organisation_id filters in the application’s queries. That is a normal architecture, and it is the one in use — not separate databases per firm.
The audit trail belongs to Accounts.
Before-and-after snapshots are recorded for money. Other modules keep activity logs, which are not the same thing.
No certification.
There is no SOC 2, ISO or comparable audit, and no published uptime commitment. When there is one, it will be named here with its date.

Read it on your own matters

Five days, a full workspace, and every control on this page in front of you.

Start your 5-day trial