How we protect your firm’s billing data
Your billing data carries client identities and matter descriptions. That makes it confidential under ABA Model Rule 1.6 and often privileged. This page describes exactly how it is handled — including the parts still in progress.
The short version
Read-only, always
Scopient connects to your practice management system through its own OAuth authorization and retrieves a copy of your billing data. It cannot create, edit or delete anything in your source system. You can revoke access at any time from your side.
Encrypted in transit and at rest
TLS 1.2+ for everything moving between your browser and our servers, with HSTS. Stored data is encrypted at rest with AES-256 by our database provider. Practice-management tokens are separately encrypted with AES-256-GCM.
Your data is scoped to your firm
Scopient is multi-tenant. Every record carries a firm identifier stamped server-side, and every request is authenticated and scoped to your firm before it touches data. No other customer can query your data.
Never used to train AI models
Time entry narratives and matter descriptions are processed only to generate your own analytics and reporting. They are not used to train any AI model, ours or a vendor's.
Never used for another customer
We do not use one firm's data to benefit another, to build features for another, or to produce benchmarks sold to anyone else. Your numbers work for you.
You own your data, and you can leave with it
Your data remains yours at all times. Export it in a standard format whenever you like. On request or termination we delete or anonymize it within 90 days, and sooner where we reasonably can.
You can see when we look
Privileged actions taken by Scopient personnel are written to the same audit log your firm can export, tagged with the firm, the actor and the action. Your administrators see our access to your data, not just your own team’s.
Why we write this down in detail
Most vendors publish a security page that says "bank-level encryption" and stops. That is not useful to a lawyer deciding whether to route billing data through a third party.
Your billing data is not ordinary business data. Time entry narratives routinely contain client identities and descriptions of the work — material that is confidential under ABA Model Rule 1.6 and frequently privileged. A firm evaluating this product is making a decision about its own professional obligations, not just a software purchase. So this page describes what is actually true, including the parts that are still in progress.
Design principle: Scopient is built to work from outputs, not raw detail. What we routinely see of your firm is the analysis the product produces for you — your dashboards and reports — rather than your underlying client and matter records.
Infrastructure
- Hosting. Vercel, United States region.
- Database. Neon Postgres, encrypted at rest with AES-256, with continuous point-in-time recovery.
- Transport. HTTPS only. TLS 1.2 or higher, with HTTP Strict Transport Security.
- Data residency. Your data is processed and stored in the United States.
- Recovery objectives. Recovery point objective of five minutes or less, backed by continuous write-ahead-log recovery. Recovery time objective of four hours or less for full service restoration. The application layer is stateless and redeployable from source at any time.
Authentication and access
- Identity is managed by Clerk, our authentication subprocessor. Scopient never sees or stores your password in plain text.
- Password policy. Minimum-strength enforcement and rejection of passwords found in known breach corpora, applied at sign-up and at every password change.
- Two-factor authentication is available using time-based one-time passwords (RFC 6238). It is currently opt-in per user; firm-wide enforcement is on our roadmap.
- Sessions are short-lived and expire after 30 minutes of inactivity.
- Failed-login throttling and per-IP rate limiting are applied to the authentication flow, with bot protection on sign-in.
- Role-based access. The product supports distinct roles — administrator, partner, billing, associate and viewer — so a firm can decide who sees what. Authentication is enforced server-side on every API call. Routes requiring elevated privileges evaluate the caller’s role inside the route handler itself — never in the client, and never inferred from what the interface rendered. An unresolved role is denied, not allowed.
Tenant isolation
Scopient is a multi-tenant platform: your data lives in a shared database and is logically separated from every other customer's by a firm identifier that is stamped server-side and never accepted from the browser. Every request is authenticated and scoped to your firm before any data is read or written.
One administrative surface inside Scopient operates across firms, so that we can quality-check the reports we generate before they reach you. We would rather describe it than let you discover it. Access is restricted to an allowlisted super-admin role, enforced inside each route handler rather than by hiding a button, and every action taken through it is written to an append-only audit record naming the firm, the actor and the action.
That record is not a private log. It is the same audit log your firm administrators can export, which means your access review shows ours too. We are additionally working toward database-level row security, so that cross-firm access becomes structurally impossible to express rather than correctly guarded everywhere.
How we handle your data
What we ask you not to send
We do not require, and we ask that you do not import, privileged attorney-client communications, the substance of legal advice, protected health information, Social Security numbers, or other special-category personal data. The product is designed to analyze the economics of your billing — rates, hours, realization, collections — not the content of your legal work.
Operator access, described honestly
As the operator of the platform, authorized Scopient personnel have administrative access to the systems where your data is stored. This is true of essentially every software provider, including the practice management system you already use, and we would rather say so than imply otherwise. Our policy:
- We access client- and matter-level data only to provide and operate the Service, to generate and quality-check your reports, to support or troubleshoot at your request, or to meet a legal or security obligation.
- We do not browse client or matter detail for any other purpose, and never for marketing, resale, or another customer's benefit.
- Product demonstrations, development, testing and quality assurance are performed on our own demonstration and test accounts — not on customer data.
- Where operating the Service requires access to your specific data, we limit it to what the task requires and will tell you when we have done so, at your request.
Retention and deletion
We retain your data while your account is active. On termination or written request we delete or anonymize your data within 90 days, and sooner where reasonably practicable, except where law requires retention. You may request a portable export before deletion.
Deletion means every store, not just the obvious ones. Account deletion covers all 27 firm-scoped tables — clients, matters, invoices, time entries and the audit log, and also every Signal report ever written about your firm, retained draft text, your Clio connection records and encrypted access tokens, sync logs, payments, firm profiles, memberships, imports and benchmarks. An automated test checks that list against the live schema, so a new table cannot quietly escape deletion later. Disconnecting your practice management system also revokes our access at the source.
Breach notification
If we become aware of a security incident compromising the confidentiality, integrity or availability of your billing data, we will notify you without undue delay and, where feasible, within 72 hours of confirming the incident — with what happened, what data was involved, and what we are doing about it.
Subprocessors
We use a small set of providers to operate the Service. Firm data is processed only by:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and edge delivery (US region) |
| Neon | Managed Postgres storage, encrypted at rest, point-in-time backups |
| Clerk | Authentication, identity, multi-factor enrolment and session issuance |
| Cloudflare | Bot-protection challenge presented during authentication |
| Anthropic, PBC | Powers the in-product AI assistant and written reporting. Prompts are sent only when a feature is invoked, and are not used to train third-party models. |
We will update this list before adding or changing a subprocessor that handles billing data. A current authoritative list and advance-notice terms are included with our data processing agreement — email security@scopient.io.
Application security
- Content Security Policy with framing denied and a script policy of
'self'plus a per-request nonce withstrict-dynamic— no inline script execution is permitted at all. Plusnosniff, a strict referrer policy, and a permissions policy denying camera, microphone and geolocation. - Same-origin CORS — the API surface rejects cross-origin requests.
- CSRF protection via origin verification on every mutating request.
- Imported text is sanitized at the validation boundary.
- Cookies are HttpOnly, Secure and SameSite-restricted.
- Secrets are held as server-side environment variables and are never exposed to the browser.
- Automated test, type and lint gates run on every change before it can ship. Dependencies are monitored for known advisories, and security patches are prioritized over feature work.
What we have not done yet
We would rather tell you this than have you find out later.
- No completed third-party penetration test. One is planned, to recur annually. We will not claim one until a report exists.
- SOC 2 Type I is in readiness assessment, not attested. Type II follows once a sufficient observation window has elapsed. We hold neither report today.
- Multi-factor authentication is available but not mandatory. Firm-wide enforcement is on the roadmap.
- Disaster recovery is not yet game-day tested. The recovery objectives above reflect current provider capabilities rather than a rehearsed full failover.
- Scopient is in beta. The security program continues to mature. This page describes what is in place today and will be updated as that changes.
Vulnerability disclosure
If you believe you have found a security issue, email security@scopient.io with reproduction steps and any artifacts. Please do not test against other firms' data — contact us and we will arrange a dedicated test tenant.
Our commitments on inbound reports:
- Acknowledgement within 24 hours.
- A substantive status update within 5 business days.
Our target remediation timelines, measured from confirmation of a valid report:
| Severity | Target |
|---|---|
| Critical / High | Remediated or mitigated within 7 days |
| Medium | Within 30 days |
| Low | Within 90 days, or the next scheduled release |
We will not penalize good-faith research conducted within these guidelines.
Regulatory posture
You — the firm — are the data controller for the billing and matter data you bring to Scopient. We act as your processor, handling that data only to provide the Service and on your instructions. We do not sell personal information, and we do not "share" it as that term is defined under the California Consumer Privacy Act.
We maintain a plan for compliance with GDPR, CCPA and PIPEDA as applicable to our customers, and a data processing agreement is available on request. Full detail is in our Privacy Policy.
Questions
Security questions, questionnaires, DPA requests: security@scopient.io. Anything else: hello@scopient.io.
If your firm has a security review process, send it over. We would rather answer it properly than have you guess.