Law Hired

Law Hired

Security at Law Hired

Law Hired is built for attorneys who handle confidential client information. Every layer of our platform — infrastructure, database, networking, and payments — is designed around security and your ethical obligations as a licensed attorney.

Last updated: May 2025

Infrastructure Certifications

Law Hired is built on certified infrastructure. The following certifications cover the platforms that store and process your data.

Supabase — SOC 2 Type II
Oracle Cloud Infrastructure — SOC 2 Type II
Oracle Cloud Infrastructure — ISO 27001
Stripe — PCI DSS Level 1
AES-256 at rest
TLS 1.2+ in transit

How We Protect Your Data
Encryption at Rest

Law Hired encrypts stored application data using the controls provided by its Oracle infrastructure. Authentication is provided separately by Supabase. Access to encryption keys is restricted and operational controls are reviewed as the platform evolves.

Encryption in Transit

All data between your browser and our servers is encrypted with TLS 1.2 or higher. We enforce HTTPS across every endpoint — unencrypted connections are automatically rejected at the edge.

Database-Enforced Tenant Isolation

Firm data is separated at the database layer, not just in application code. Our production database uses Oracle Virtual Private Database (VPD): row-level predicates are attached to every query based on the authenticated user's identity and firm, so a lawyer can only reach their own firm's cases, clients, documents, and billing data. Application-layer checks run in addition to this as defense in depth.

Certified Infrastructure Providers

Some infrastructure providers publish independent security certifications for their own services. Those certifications belong to the providers and do not certify Law Hired. Law Hired itself is not currently SOC 2 or ISO 27001 certified, and we do not claim to be.

DDoS Protection & Edge Security

Law Hired uses hosting and network-layer controls intended to reduce common availability and application-security risks. Specific providers and controls may change; current details are available during vendor due diligence.

Payment Security

Card and bank-payment details are handled by configured payment providers rather than entered into Law Hired application records. Provider availability varies by account. A provider's PCI status applies to that provider and does not certify Law Hired.

AI Privacy & Model Training

AI-powered tools (deposition prep, document drafting, smart summaries) call third-party LLM APIs under commercial terms that prohibit using your inputs to train their models. Law Hired never uses your client data to train any model. Note that for compliance and reviewability, Law Hired keeps an append-only AI audit log of prompts and responses, visible only to the submitting user and firm administrators — so AI activity is retained on our side by design.

IOLTA Trust Account Segregation

The platform keeps trust-ledger and operating-ledger records separate. Payment-provider configuration and the lawyer's own procedures determine whether funds are routed correctly; Law Hired does not guarantee a lawyer's ethical compliance.


Sub-Processors

The following third-party services process data on behalf of Law Hired. No other sub-processors are authorized to handle your data.

Supabase ↗

Authentication services

SOC 2 Type II
United States
Oracle Cloud Infrastructure ↗

Application hosting, compute & object storage

SOC 2 Type II · ISO 27001
United States
Stripe ↗

Payment processing

PCI DSS Level 1
United States

Security Policies
Data Retention & Deletion

A confirmed account-deletion workflow exists, but complete deletion must account for Oracle application records, authentication records, backups, audit evidence, legal holds, and financial or professional-retention obligations. Law Hired does not currently publish a universal purge deadline. Request an export and deletion scope review through legal@lawhired.com before closing an account.

Breach Notification

Law Hired will investigate suspected incidents and provide notices required by applicable law and binding agreements without unreasonable delay. A specific 72-hour customer-notification promise applies only where a signed agreement expressly creates it; regulatory reporting deadlines do not automatically become an identical contractual deadline to every customer.

Access Control

Production access is intended to be limited to authorized personnel and logged. Support or security personnel may need narrowly scoped access to customer content for an authorized support request, incident response, abuse investigation, or legal obligation; Law Hired does not claim that employee access is technically impossible.

Vulnerability Disclosure

If you discover a security vulnerability, please report it to security@lawhired.com. We will acknowledge your report within 48 hours and provide a resolution timeline. We do not pursue legal action against good-faith security researchers.


Security Questions & Vulnerability Reports

To report a security vulnerability, email security@lawhired.com. For general security questions, contact legal@lawhired.com. We respond to all security inquiries within 48 hours.

We use essential cookies to operate this platform, and optional analytics cookies (PostHog) to understand how it is used. We do not use advertising cookies. Cookie Policy · Privacy Policy