Authenticated staff access
Staff-only routes require an authenticated account and an active staff record.
Security and data handling
WWW Legal is designed to support legal-intake workflows while keeping public submissions, staff access, and private documents separated. Security depends on both the software and the firm’s deployment, access, retention, and operating procedures.
These controls describe the product design. They are not a certification, legal opinion, or guarantee that every deployment is risk-free.
Staff-only routes require an authenticated account and an active staff record.
Uploaded files are intended to remain private and be accessed through authorized, time-limited download paths.
Public forms and uploads use validation, file-type restrictions, size limits, and abuse controls.
Public endpoints include rate-limiting controls to reduce automated abuse and excessive submissions.
Public submission paths are kept separate from protected staff review routes.
The software organizes information; lawyers and authorized staff remain responsible for legal decisions.
A firm should retain ownership of its client information and define who may access, export, retain, or delete it under the pilot agreement.
Before real confidential documents are used, the production environment should be reviewed for access, retention, backups, incident handling, and firm-specific privacy obligations.
WWW Legal does not claim SOC 2, ISO 27001, Law Society approval, guaranteed compliance, or immunity from cyber incidents.
Responsible pilot use