Security

    Security & Confidentiality at Lawmox

    Legal data is privileged. Lawmox is built on a security model that treats confidentiality and access control as core requirements, not add-ons — and aligned with Texas Bar guidance on cloud storage of client information.

    Encryption in transit and at rest

    All traffic to Lawmox is served over TLS 1.2+. Data at rest in our managed database and object storage is encrypted with AES-256 keys managed by the cloud provider. Authentication credentials are stored as salted, one-way hashes — never as recoverable plaintext.

    Role-based access control

    Access is enforced at the row level inside the database, not just in the UI. Attorneys, paralegals, intake specialists, bookkeepers, and clients each see exactly the matters and fields they are entitled to. Permissions can be tightened per matter when extra confidentiality is required (e.g., conflict walls).

    Tenant isolation

    Lawmox is multi-tenant with strict logical isolation per firm. Every read and write is scoped by firm at the database layer. There is no commingling of records, documents, or backups between firms.

    Audit logging

    Every meaningful action — record creation, edits, document access, deadline changes, exports, and authentication events — is captured in an immutable audit log with user, timestamp, and source IP. Owner-level admins can review and export the log for bar inquiries or internal investigations.

    Backups & business continuity

    Encrypted automated backups are taken daily with point-in-time recovery for the past 7 days. Backups are stored in a geographically separate region from primary storage. Disaster-recovery procedures are tested on a defined cadence.

    Data residency

    Customer data is stored in U.S.-based cloud regions. We do not move client data outside of the United States without an explicit, written customer request.

    Texas Bar cloud-storage alignment

    The State Bar of Texas Professional Ethics Committee (Op. 680) permits cloud storage of confidential client information when the lawyer exercises reasonable care in vendor selection and configuration. Lawmox is built around the controls — encryption, access control, audit logs, breach notification, and exportability — that are the substance of "reasonable care" under that opinion. Lawyers remain responsible for selecting appropriate configurations for their practice.

    Breach notification

    In the event of a confirmed security incident affecting customer data, Lawmox will notify affected customers without undue delay and in any case within the timeline required by applicable law. Customers receive the facts known about the incident, the data categories involved, and the steps Lawmox is taking in response.

    Data ownership and exportability

    Firms own their data. At any point during or after the engagement, you can export matters, contacts, time entries, invoices, documents, and the audit log in standard formats. There is no hostage clause and no per-export fee.

    No unauthorized practice of law

    Lawmox is software, not a law firm. The Texas Lawbot AI assistant is a research and drafting aid; it does not give legal advice. Attorneys remain solely responsible for legal judgment, strategy, deadlines, and client representation.

    Texas-based support

    Onboarding and support are run from Texas during business hours. You talk to people who understand the practice environment, not an offshore queue.

    Core capabilities

    TLS 1.2+ in transit

    All traffic encrypted end-to-end between client and server.

    AES-256 at rest

    Database and object storage encrypted with provider-managed keys.

    Row-level access control

    Permissions enforced at the database, not just the UI.

    Audit log

    Immutable, exportable log of every meaningful action per user.

    Daily encrypted backups

    7-day point-in-time recovery, stored in a separate region.

    Tenant isolation

    Logical separation per firm at the storage and query layer.

    Session controls

    Configurable session timeouts and forced logout on role change.

    U.S. data residency

    Customer data stored in U.S. cloud regions by default.

    Exportable on demand

    Firms own their data and can export it at any time.

    Who it's built for

    • Firms handling privileged client data (every firm)
    • Practices subject to bar audit
    • Firms moving off shared Dropbox or email attachments
    • Offices that have ever lost a laptop
    • Practices with confidentiality walls or matter-specific access needs

    Frequently asked questions

    Where is data hosted?

    On hardened U.S.-based cloud infrastructure with strict tenant isolation and encrypted backups stored in a separate region.

    Is Lawmox aligned with Texas Bar cloud-storage guidance?

    Yes. The controls Lawmox provides — encryption, access control, audit logs, breach notification, and exportability — are designed around the "reasonable care" framework in Texas Bar Op. 680.

    Do you offer an SLA?

    Yes. SLA terms (uptime, support response, data restoration) are provided as part of the engagement.

    Can I export my data?

    Yes, at any time, in standard formats. No hostage clause, no per-export fee.

    How are security incidents communicated?

    Affected customers are notified without undue delay with the facts known about the incident, the data involved, and Lawmox's response.

    Does Texas Lawbot give legal advice?

    No. Texas Lawbot is a research and drafting aid. It does not give legal advice. Attorneys remain solely responsible for legal judgment.

    Ready to see it in action?

    Reach out and we'll walk you through it.