Enterprise-grade security designed for sensitive legal documents and case data.
We take security seriously. Whether you are generating witness statements, analysing insurer correspondence, or reviewing case law, your sensitive legal data is protected with industry-leading security measures and compliance standards.
Email verification, strong password policies, and leaked password protection (HIBP).
Row-level security ensures your company's data is completely isolated from others.
Personal identifiers are automatically masked before text reaches our AI provider, privacy by design. This applies to every uploaded document and every tool, including the Witness Statement Generator's document extraction pipeline.
Designed to support UK GDPR with data minimisation, lawful processing, and robust security measures.
Text-based PDFs have their text extracted in your browser, on the drafting tools and the Witness Statement document slots alike. Word documents are different: on the drafting tools drop zone they are read in your browser, but Word files submitted to the Witness Statement document slots are reduced to text on our server and masked there before any AI processing. That extracted text is sent to our server, where the personal identifiers we can detect are masked before anything goes to the AI. Scanned or image-only PDFs are sent to our server to be read, held in memory for the length of that read, and discarded when it finishes. They are never written to our file storage. The one place a scanned original is written to storage is the clinical negligence medical pagination tool, where the source files sit in private per-firm storage, are read, and are deleted as soon as the bundle is built. The finished bundle is then removed automatically within one hour. Generated outputs are deleted shortly after they are produced, with a continuous purge so case data is never retained beyond 24 hours. So a crashed tab does not cost you your work, your typed and confirmed details are kept as a recovery draft in your own browser for up to 48 hours and then deleted. Documents are never stored in the browser, and signing out clears every recovery draft at once.
CaseFlow Automation, which operates LegalDocs-Assist, holds Cyber Essentials certification covering the whole organisation.
| Organisation certified | CaseFlow Automation, 7-9 Macon Court, Crewe CW1 6EA |
|---|---|
| Scope | Whole organisation |
| Certificate number | 176bba48-8fb4-4f1a-a685-32d86b40fe3f |
| Profile version | 3.3 (Danzell) |
| Date of certification | 7 August 2026 |
| Recertification due | 7 August 2027 |
| Certification body | IT Cyber Solutions |
| Accreditation partner | IASME, the National Cyber Security Centre's delivery partner for the scheme |
Whole organisation scope matters. Some certificates cover a narrow slice of a business, a single office or one product. Ours covers everything CaseFlow Automation runs, including LegalDocs-Assist.
Cyber Essentials is a UK Government backed scheme delivered by IASME on behalf of the National Cyber Security Centre. It assesses an organisation against five technical controls.
Boundary and device firewalls block unapproved inbound traffic by default, with any exception documented and justified.
Devices and software ship with convenient defaults rather than safe ones. This control covers removing what is not needed, changing default credentials and hardening what remains.
Software is supported, licensed and patched. High risk and critical updates are applied within defined timescales, and unsupported software is removed.
Accounts belong to named individuals, access is granted on need, administrative privileges are separated from day to day accounts, and access is removed when someone leaves.
Devices are protected against malicious code through anti-malware software, application allow listing, or sandboxing.
This is worth separating out, because they get conflated and a law firm will spot it.
Cyber Essentials is about technical controls. Data protection is about lawful basis, purpose, retention, the rights of the people whose data it is, and the contractual chain between controller and processor. A certificate for one does not discharge the other.
For LegalDocs-Assist engagements we work to a data processing agreement, and where a firm's use case calls for it we complete a data protection impact assessment alongside it. Those are the documents that govern what happens to your clients' data. Cyber Essentials sits underneath them as evidence that the technical baseline is in place.
If your firm has a supplier due diligence pack, send it. We would rather answer it properly than have you assume.
We would rather be straight about the limits of this than let a badge do work it cannot do.
Cyber Essentials is a verified baseline, not an exhaustive audit. It confirms the five controls above were in place at the point of assessment. It is not Cyber Essentials Plus, which adds a hands on technical audit, and it is not ISO 27001, which certifies a whole information security management system.
The certificate itself carries this wording, and it is worth repeating rather than burying: it confirms the organisation's ICT defences were assessed as satisfactory against commodity based cyber attacks at the time of testing, and does not guarantee those defences will remain satisfactory against a cyber attack.
Security is a practice, not a certificate. The certificate is evidence that we take the practice seriously enough to be assessed on it every year.
Do not take a badge on a website as proof of anything. Anyone can put an image in a footer.
Every Cyber Essentials certificate is recorded on an independent registry. Ours is published at the link below, and the entry shows as active while the certification is current and lapses if it is not renewed.
Check our certificate on the official registry: https://registry.blockmarktech.com/certificates/176bba48-8fb4-4f1a-a685-32d86b40fe3f/active/
Granular permissions ensure team members only access what they need. Managers oversee their team, while handlers focus on their cases.
Full transparency. Read our policies and technical documentation.
Comprehensive compliance posture and certifications
AI governance, anti-hallucination controls, prompt security
Plain-English, step-by-step walkthrough of what happens to your data
DPIA-ready technical reference for the masking gateway
One-page overview for compliance and decision-makers
Jargon-free overview for non-technical users
Architecture and technology stack for IT teams
Platform terms and conditions
For a plain English walkthrough of what happens to uploaded material, see How We Protect Your Data, and our Privacy Policy.
Yes. LegalDocs-Assist is operated by CaseFlow Automation, which holds Cyber Essentials certification with whole organisation scope. Certificate number 176bba48-8fb4-4f1a-a685-32d86b40fe3f, certified on 7 August 2026 and due for recertification on 7 August 2027.
CaseFlow Automation, the company that builds and operates LegalDocs-Assist. The scope is the whole organisation, so it covers this product.
This is Cyber Essentials. Cyber Essentials Plus adds an independent hands on technical audit on top of the same five controls. We hold the base certification and we are not going to describe it as anything else.
No, and anyone telling you otherwise is overselling. Cyber Essentials covers technical controls. Data protection compliance is governed by the data processing agreement between your firm and us, and where appropriate a data protection impact assessment. Ask us for both.
IT Cyber Solutions, a certification body working under IASME, which delivers the scheme on behalf of the National Cyber Security Centre.
Twelve months. Ours runs to 7 August 2027, at which point the organisation is reassessed rather than simply renewed.
Use the registry link on this page. It is maintained independently of us and shows the certificate as active only while the certification is current.
Join legal practitioners across the UK who trust LegalDocs Assist with their witness statements, case documents, and dispute workflows.