Trust

Security at FirmLaunch

Last updated: July 13, 2026

How we protect the intake conversations, documents, and case data that flow through the FirmLaunch platform on behalf of our partner law firms.
01

Overview

This page is maintained by FirmLaunch to answer common questions from law firms about how we protect information across our advertising, AI intake, and case delivery platform. It describes controls we have enabled today. It is not a certification and does not replace an independent audit or a signed Data Processing Addendum.

02

Shared responsibility

Security on FirmLaunch is a shared responsibility. FirmLaunch is responsible for the security of the platform and its underlying infrastructure. Partner law firms are responsible for the security of their own devices, user accounts, matter management systems, and any data they export from the platform. Individual users are responsible for maintaining strong credentials and reporting suspected compromise.

03

Access and authentication

  • All FirmLaunch dashboards require unique user accounts with strong password requirements.
  • Multi-factor authentication (MFA) is enforced on all FirmLaunch employee accounts and available for firm users.
  • Role-based access controls limit dashboard views and exports to what each user needs.
  • Administrative access to production systems is restricted to a small on-call team and requires MFA plus SSO.
  • Employee access is provisioned on hire, reviewed periodically, and revoked immediately upon role change or offboarding.
04

Data protection

  • Data is encrypted in transit using TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256 or equivalent, managed by our infrastructure providers.
  • Sensitive documents (IDs, retainers, police reports) are stored in access-controlled object storage with signed, expiring URLs.
  • Backups are encrypted, monitored, and tested on a recurring schedule.
  • Production databases are logically isolated from lower environments; production data is not used in development or staging.
05

Platform and hosting

FirmLaunch runs on reputable US-based cloud infrastructure providers with SOC 2 Type II and ISO 27001 certifications for their underlying platforms. Application code is deployed through peer-reviewed pull requests, automated testing, and change management controls. Dependencies are continuously scanned for known vulnerabilities.

06

Monitoring and logging

  • Application, API, and infrastructure logs are centralized and retained on a defined schedule.
  • Anomaly detection and alerting on authentication events, privileged actions, and administrative changes.
  • Uptime and performance are monitored 24/7 with on-call rotation.
  • Regular vulnerability scans of internet-facing surfaces and periodic third-party penetration testing.
07

Subprocessors and vendors

FirmLaunch relies on a limited set of subprocessors for hosting, telephony, SMS, e-signature, analytics, and AI model inference. Each subprocessor is reviewed for security posture and contractually bound to appropriate data-protection terms. A current list of subprocessors is available on request under our Data Processing Addendum.

08

Incident response

FirmLaunch maintains a documented incident response process covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed personal data breach affecting a partner firm, we will notify the firm without undue delay and cooperate in good faith to meet applicable notification obligations.

Report a suspected incident to security@firmlaunch.co.

09

Responsible disclosure

We welcome reports from security researchers. Please email security@firmlaunch.co with a clear description, reproduction steps, and any supporting material. We ask that researchers refrain from accessing data that does not belong to them, from degrading service, and from public disclosure until we have had a reasonable opportunity to remediate.

10

Business continuity

FirmLaunch operates in geographically redundant environments with automated failover and encrypted backups. Recovery time and recovery point objectives are set to minimize disruption to intake and case delivery workflows.

11

Compliance and privacy

FirmLaunch aligns its practices with SOC 2 control objectives and US state privacy laws (including CCPA/CPRA) and supports partner firms with their own regulatory obligations under a signed Data Processing Addendum. This page does not itself represent a certification. Copies of security questionnaires, SOC reports from underlying providers, and our DPA are available upon request under NDA.

12

Contact

Security team · security@firmlaunch.co.

Questions about this document? Contact legal@firmlaunch.co.