CyberFiduciary
Clear about trust

A secure foundation must be earned.

See what is available in this preview and the controls that must be implemented and verified before real client use.

Current status: controlled document pilot. The owner-only pilot uses ChatGPT sign-in, saved matter records and private original-file storage. AI requires a separate activation. Start with fictional or redacted files; client production use is not approved.
Production connection / verification required

Encryption

Verify protection in transit and at rest, key handling, and every storage and processing path.

Production connection / verification required

Private storage

Keep originals outside public URLs, with private object storage and time-limited authorized downloads.

Production connection / verification required

Authentication

Connect account registration, sign-in, recovery, multifactor authentication, and session controls.

Production connection / verification required

Access controls

Enforce organization and matter permissions on the server for every read, change, and download.

Production connection / verification required

Audit logs

Retain durable events for access, changes, approvals, exports, and permission changes.

Production connection / verification required

Data segregation

Verify that each organization and matter can retrieve only authorized records and AI context.

Production connection / verification required

Privacy

Review provider processing, training, retention, deletion, and subprocessors before making privacy claims.

Production connection / verification required

Secure collaboration

Enforce scoped invitations, revocation, role changes, and document-level access as appropriate.

Production connection / verification required

Backup & recovery

Define recovery objectives, configure backups, test restoration, and apply retention controls.

Production connection / verification required

Cybersecurity practices

Verify file scanning, dependency management, monitoring, incident response, and independent testing.

Privacy notice · Draft for legal review

The fictional /demo workspace keeps records in page memory. The separate /workspace pilot stores matter records and originals on the hosting platform with server-side ownership checks. Pilot records remain until a managed deletion process is implemented; self-service deletion is not yet available. Exported files remain on your device. The access-request form prepares a local draft and sends nothing. Hosting and browser services may process technical request information under their own terms. AI processing, when enabled and requested, sends selected documents to OpenAI with response storage disabled; provider retention terms still apply. Production retention policies, deletion, malware scanning, recovery testing and security review remain unfinished.

Claims follow evidence

No SOC 2, HIPAA, FINRA, SEC, or other certification or regulatory compliance status is claimed. Specific encryption standards, security protections, and provider privacy settings must be implemented and verified before they are described as operational.