Encryption in transit and at rest
All traffic to Lawmox is served over TLS 1.2+. Data at rest in our managed database and object storage is encrypted with AES-256 keys managed by the cloud provider. Authentication credentials are stored as salted, one-way hashes — never as recoverable plaintext.
Role-based access control
Access is enforced at the row level inside the database, not just in the UI. Attorneys, paralegals, intake specialists, bookkeepers, and clients each see exactly the matters and fields they are entitled to. Permissions can be tightened per matter when extra confidentiality is required (e.g., conflict walls).
Tenant isolation
Lawmox is multi-tenant with strict logical isolation per firm. Every read and write is scoped by firm at the database layer. There is no commingling of records, documents, or backups between firms.
Audit logging
Every meaningful action — record creation, edits, document access, deadline changes, exports, and authentication events — is captured in an immutable audit log with user, timestamp, and source IP. Owner-level admins can review and export the log for bar inquiries or internal investigations.
Backups & business continuity
Encrypted automated backups are taken daily with point-in-time recovery for the past 7 days. Backups are stored in a geographically separate region from primary storage. Disaster-recovery procedures are tested on a defined cadence.
Data residency
Customer data is stored in U.S.-based cloud regions. We do not move client data outside of the United States without an explicit, written customer request.
Texas Bar cloud-storage alignment
The State Bar of Texas Professional Ethics Committee (Op. 680) permits cloud storage of confidential client information when the lawyer exercises reasonable care in vendor selection and configuration. Lawmox is built around the controls — encryption, access control, audit logs, breach notification, and exportability — that are the substance of "reasonable care" under that opinion. Lawyers remain responsible for selecting appropriate configurations for their practice.
Breach notification
In the event of a confirmed security incident affecting customer data, Lawmox will notify affected customers without undue delay and in any case within the timeline required by applicable law. Customers receive the facts known about the incident, the data categories involved, and the steps Lawmox is taking in response.
Data ownership and exportability
Firms own their data. At any point during or after the engagement, you can export matters, contacts, time entries, invoices, documents, and the audit log in standard formats. There is no hostage clause and no per-export fee.
No unauthorized practice of law
Lawmox is software, not a law firm. The Texas Lawbot AI assistant is a research and drafting aid; it does not give legal advice. Attorneys remain solely responsible for legal judgment, strategy, deadlines, and client representation.
Texas-based support
Onboarding and support are run from Texas during business hours. You talk to people who understand the practice environment, not an offshore queue.