Security & trust

Security for sensitive
family information.

Heirs’ property work involves personal information, family records, and professional work product. Our platform uses encryption, restricted access, and security monitoring to support the teams handling that information.

The technology platform

How we protect
matter information.

Platform matters can include names, addresses, family information, and uploaded records. These safeguards apply to the technology platform.

01

Encryption

Platform data and backups are encrypted at rest. Data sent through external APIs is encrypted in transit, and API access requires authentication.

02

Controlled access

Multifactor authentication and role-based permissions restrict access to platform data. Production access is highly restricted. Client administrators can manage their organization’s users and permissions.

03

Organization and matter boundaries

The access model is designed around the user, role, organization, and matter. It is designed to separate organizations’ files and keep community intake participants from accessing attorney work product and communications.

04

Development with synthetic data

Developers use synthetic data for development and testing, while access to production data remains restricted.

05

Monitoring and audit logging

GCP-native intrusion monitoring and detailed API and database logs support security investigations. Audit logging is designed to show who viewed or changed information, what changed, and when.

06

Security testing

We maintain written test plans and test logs, conduct vulnerability testing, and perform regular penetration testing. Backup access also requires authentication through restricted administrative controls.

AI and client information

How AI supports
the work.

The platform uses Gemini for document parsing and Anthropic models for contextual evaluation of document content.

Extracted facts, research leads, ownership scenarios, and draft documents require professional review. Attorneys and underwriters remain responsible for the decisions within their roles.

Consent for client-specific fine-tuning

Client information is used for AI fine-tuning only with the client organization’s agreement and agreement from the clients it represents.

Client-specific models and improvements remain segregated. Each client’s model is improved using its own data, for its own benefit.

Discuss AI processing, providers, and the permissions applicable to your engagement before onboarding.

Incident response

Investigation and communication.

When a breach is verified, we notify affected parties while the investigation proceeds, then provide updates as the scope and impact become clearer.

01

Verify the incident

Use monitoring and logs to confirm what occurred and begin assessing the impact.

02

Notify affected parties

Communicate the confirmed breach while root cause analysis is still underway.

03

Investigate and update

Identify the vulnerability, determine which information is affected, and provide targeted updates.

04

Remediate and review

Address the issue and test the response. Share detailed findings with the appropriate parties involved in resolution.

Data access and continuity

Plan for the end
of an engagement.

Client data can be made available in separate archives, together with uploaded documents.

At the end of an agreed pilot, any continued platform access is agreed separately. Your organization can receive a final data extract and deletion confirmation for pilot records and uploads.

Confirm export, retention, deletion, and transition arrangements as part of your engagement, including how they apply to backups.

Website inquiries and report engagements

This page describes the technology platform. General website inquiries are sent through HubSpot, as explained in our website privacy notice.

For a Heirship Diligence Report, agree on the channel for transferring records and the handling of matter information before sending the file.

Please keep website forms to general business inquiries. Do not include client names, confidential details, identification numbers, or documents.

Your organization’s review

Discuss the requirements
for your engagement.

Contact us about access controls, AI processing, security testing, incident communication, or data handling before a pilot or implementation.