Built for Security & Trust

Enterprise-grade security designed for sensitive legal documents and case data.

Enterprise-Grade Security

Your Data is Protected

We take security seriously. Whether you are generating witness statements, analysing insurer correspondence, or reviewing case law, your sensitive legal data is protected with industry-leading security measures and compliance standards.

Secure Authentication

Email verification, strong password policies, and leaked password protection (HIBP).

Data Isolation

Row-level security ensures your company's data is completely isolated from others.

PII Redaction Gateway

Personal identifiers are automatically masked before text reaches our AI provider, privacy by design. This applies to every uploaded document and every tool, including the Witness Statement Generator's document extraction pipeline.

GDPR Compliant

Designed to support UK GDPR with data minimisation, lawful processing, and robust security measures.

Document Processing & Masking

Text-based PDFs have their text extracted in your browser, on the drafting tools and the Witness Statement document slots alike. Word documents are different: on the drafting tools drop zone they are read in your browser, but Word files submitted to the Witness Statement document slots are reduced to text on our server and masked there before any AI processing. That extracted text is sent to our server, where the personal identifiers we can detect are masked before anything goes to the AI. Scanned or image-only PDFs are sent to our server to be read, held in memory for the length of that read, and discarded when it finishes. They are never written to our file storage. The one place a scanned original is written to storage is the clinical negligence medical pagination tool, where the source files sit in private per-firm storage, are read, and are deleted as soon as the bundle is built. The finished bundle is then removed automatically within one hour. Generated outputs are deleted shortly after they are produced, with a continuous purge so case data is never retained beyond 24 hours. So a crashed tab does not cost you your work, your typed and confirmed details are kept as a recovery draft in your own browser for up to 48 hours and then deleted. Documents are never stored in the browser, and signing out clears every recovery draft at once.

Our Cyber Essentials certification

CaseFlow Automation, which operates LegalDocs-Assist, holds Cyber Essentials certification covering the whole organisation.

Cyber Essentials certified
Organisation certifiedCaseFlow Automation, 7-9 Macon Court, Crewe CW1 6EA
ScopeWhole organisation
Certificate number176bba48-8fb4-4f1a-a685-32d86b40fe3f
Profile version3.3 (Danzell)
Date of certification7 August 2026
Recertification due7 August 2027
Certification bodyIT Cyber Solutions
Accreditation partnerIASME, the National Cyber Security Centre's delivery partner for the scheme

Whole organisation scope matters. Some certificates cover a narrow slice of a business, a single office or one product. Ours covers everything CaseFlow Automation runs, including LegalDocs-Assist.

What Cyber Essentials actually covers

Cyber Essentials is a UK Government backed scheme delivered by IASME on behalf of the National Cyber Security Centre. It assesses an organisation against five technical controls.

Firewalls

Boundary and device firewalls block unapproved inbound traffic by default, with any exception documented and justified.

Secure configuration

Devices and software ship with convenient defaults rather than safe ones. This control covers removing what is not needed, changing default credentials and hardening what remains.

Security update management

Software is supported, licensed and patched. High risk and critical updates are applied within defined timescales, and unsupported software is removed.

User access control

Accounts belong to named individuals, access is granted on need, administrative privileges are separated from day to day accounts, and access is removed when someone leaves.

Malware protection

Devices are protected against malicious code through anti-malware software, application allow listing, or sandboxing.

Cyber Essentials and data protection are not the same thing

This is worth separating out, because they get conflated and a law firm will spot it.

Cyber Essentials is about technical controls. Data protection is about lawful basis, purpose, retention, the rights of the people whose data it is, and the contractual chain between controller and processor. A certificate for one does not discharge the other.

For LegalDocs-Assist engagements we work to a data processing agreement, and where a firm's use case calls for it we complete a data protection impact assessment alongside it. Those are the documents that govern what happens to your clients' data. Cyber Essentials sits underneath them as evidence that the technical baseline is in place.

If your firm has a supplier due diligence pack, send it. We would rather answer it properly than have you assume.

What Cyber Essentials does not cover

We would rather be straight about the limits of this than let a badge do work it cannot do.

Cyber Essentials is a verified baseline, not an exhaustive audit. It confirms the five controls above were in place at the point of assessment. It is not Cyber Essentials Plus, which adds a hands on technical audit, and it is not ISO 27001, which certifies a whole information security management system.

The certificate itself carries this wording, and it is worth repeating rather than burying: it confirms the organisation's ICT defences were assessed as satisfactory against commodity based cyber attacks at the time of testing, and does not guarantee those defences will remain satisfactory against a cyber attack.

Security is a practice, not a certificate. The certificate is evidence that we take the practice seriously enough to be assessed on it every year.

Verifying this certificate yourself

Do not take a badge on a website as proof of anything. Anyone can put an image in a footer.

Every Cyber Essentials certificate is recorded on an independent registry. Ours is published at the link below, and the entry shows as active while the certification is current and lapses if it is not renewed.

Check our certificate on the official registry: https://registry.blockmarktech.com/certificates/176bba48-8fb4-4f1a-a685-32d86b40fe3f/active/

Role-Based Access Control

Granular permissions ensure team members only access what they need. Managers oversee their team, while handlers focus on their cases.

  • Manager & Senior company dashboards

Security Features

  • Encrypted data at rest and in transit
  • Secure invite-only registration
  • Automatic PII masking before AI processing
  • AI provider does not train on your data
  • Compromised password detection
  • Audit logging for compliance
  • Source attribution recorded against every extracted fact, full audit trail by default

Cyber Essentials, frequently asked questions

Is LegalDocs-Assist Cyber Essentials certified?

Yes. LegalDocs-Assist is operated by CaseFlow Automation, which holds Cyber Essentials certification with whole organisation scope. Certificate number 176bba48-8fb4-4f1a-a685-32d86b40fe3f, certified on 7 August 2026 and due for recertification on 7 August 2027.

Whose name is on the certificate?

CaseFlow Automation, the company that builds and operates LegalDocs-Assist. The scope is the whole organisation, so it covers this product.

Is this Cyber Essentials or Cyber Essentials Plus?

This is Cyber Essentials. Cyber Essentials Plus adds an independent hands on technical audit on top of the same five controls. We hold the base certification and we are not going to describe it as anything else.

Does Cyber Essentials mean you are UK GDPR compliant?

No, and anyone telling you otherwise is overselling. Cyber Essentials covers technical controls. Data protection compliance is governed by the data processing agreement between your firm and us, and where appropriate a data protection impact assessment. Ask us for both.

Who carried out the assessment?

IT Cyber Solutions, a certification body working under IASME, which delivers the scheme on behalf of the National Cyber Security Centre.

How long is Cyber Essentials valid for?

Twelve months. Ours runs to 7 August 2027, at which point the organisation is reassessed rather than simply renewed.

How do I check the certificate is genuine?

Use the registry link on this page. It is maintained independently of us and shows the certificate as active only while the certification is current.

Ready to See How We Protect Your Data?

Join legal practitioners across the UK who trust LegalDocs Assist with their witness statements, case documents, and dispute workflows.