Security
How BRON handles your data and your decisions.
This is the short version. Each section links to the full text in our privacy notice and sub-processor list, which say exactly what's in place.
Who can see a matter
Your firm decides. Roles, matter membership and ethical walls are checked on the server for every request, and the database itself refuses records a person isn't entitled to. Clients see only documents an attorney has reviewed and shared. Privileged and work-product material never reaches the client portal.
Privacy notice: privileged material and the client portalWhat reaches AI vendors
A reviewed list in BRON's code names every model vendor allowed to receive client content. A vendor that isn't on the list gets nothing, and adding one takes a code change, not a setting. Zero-retention and no-training terms are agreements between companies. BRON records which vendors are covered, but it can't see what a vendor keeps.
Sub-processorsWhat needs an approval
Nothing is sent, signed or filed, no trust money moves, and no matter changes phase until someone on the matter approves that exact action. Phase changes, deadlines and sharing documents with a client need a licensed attorney. A document whose citations can't be confirmed is held until a licensed attorney releases it with a recorded reason.
Firm controlsYour own AI tools
Tools your firm connects get scoped access. They can read within that scope, add notes and propose actions. They can't send, file, sign, serve, calendar or move money.
MCP server documentationEncryption and storage
Connections are encrypted, and production refuses a plain request that carries data rather than redirecting it. Data at rest is encrypted by the managed database and storage platform. Keys your firm supplies for its own model vendors or integrations are encrypted by BRON before they're stored. Files are private and served only through signed links.
Privacy notice: security measuresThe audit record
Sends, signatures, phase changes, trust ledger entries, privilege and classification changes, conflicts decisions, deadline changes and litigation holds are written to an append-only log. The database refuses edits and deletions, and each entry is chained to the one before it, so a removed or altered entry can be detected.
Privacy notice: the audit recordTaking your work with you
Exports carry a manifest a recipient can check without a BRON account. An owner or admin can export the whole firm, and the preview lists anything that can't be included. A matching file proves the bytes match. It doesn't prove that nothing is missing.
Verify an exportQuestions and incidents
If your firm needs a security questionnaire answered, or you suspect an incident, email contact@bronlaw.com. We tell the affected firm through the contact on its account and follow the incident terms in its services agreement.