Trust boundary

Private by default. Shared only with your authorization.

Original evidence and personal communications deserve controls that match their sensitivity.

Evidence accessPrivate
ConsumerCan view originals
Internal reviewAuthorized and audited
AttorneyAuthorization required

Case-file security model

These controls describe the account-based case-file system. That system is separate from the public checker and is not yet open for public evidence uploads.

01Storage boundary

Private evidence

Objects are stored in a private environment-specific bucket and are never exposed through an unauthenticated URL.

02Evidence record

Integrity metadata

The original filename, MIME type, size, upload time, uploader, storage environment, and SHA-256 hash are retained.

03Upload gate

Malware scanning

Uploads fail closed through file validation and malware scanning before becoming available.

04Access gate

Short-lived access

Authorized users receive an application-signed, expiring access link. Access is checked again and audited when used.

05Sharing boundary

Named-recipient sharing

An internal assignment grants no access. The consumer first sees the named firm and authorizes a fixed snapshot.

06Future access

Revocation

Revocation blocks future platform access. It cannot erase copies a firm lawfully downloaded and independently retains.

Current public boundary

The public checker does not accept files or expose case-file access. The controls above are not a third-party certification and will be independently reviewed before real evidence is accepted publicly.