Lawcadia is designed as a closed system for legal operations, with tightly controlled access, comprehensive security and audit logging, and a security architecture built specifically for the way in-house legal teams work. Users are authorised, permissions are clearly defined, and activity across the platform is monitored and auditable.
When working with external law firms, Lawcadia supports a controlled exchange of specific instructions and information such as scopes, budgets and invoices.
The platform combines these purpose-built controls with independently assessed information security standards to help legal teams manage sensitive legal work with greater control and oversight.
Under the standard shared tenancy model, client data is stored within the selected AWS region and distributed across multiple Availability Zones for resilience. Data always remains within the selected region.
Private Cloud Infrastructure is available for organisations with additional hosting, isolation or encryption requirements. Managed by Lawcadia, this option provides dedicated infrastructure, separate storage and a dedicated AWS KMS encryption key. Clients can also choose to manage the AWS KMS key used for the cloud level encryption layer.
Private Cloud Infrastructure may be deployed in any AWS region, with platform processing through one of Lawcadia’s supported regional processing hubs. We can also accomodate other data residency requirements upon request.
For Australian clients, all sub-processing is undertaken in Australia.
For clients in other jurisdictions, all key sub-processing occurs in the same location as the regional processing hub, and sub-processing activities related to Lawcadia's first and second level support occur in Australia, although this can be limited if required. Details of applicable sub-processors can be provided as part of a security review.
For Lawcadia AI, AI processing will take place in the jurisdiction of the client's chosen data centre. This means AI processing for Australian-hosted clients will occur in Australia, UK-hosted clients in the United Kingdom, and US-hosted clients in the US.
This includes:
For Single Sign-on (SSO) Lawcadia utilises SAML 2.0 to exchange authentication and authorisation data between your Identity Provider (IdP) including Okta, Auth0, OneLogin, Microsoft Entra ID, Google IdP and our platform.
We support SCIM (System for Cross-domain Identity Management) to synchronise users, roles and group memberships with the client’s identity provider, including both provisioning and deprovisioning. This reduces manual administration and allows access to be updated or removed when an employee’s role or employment status changes.
Lawcadia also supports multifactor authentication (MFA) through supported identity providers and additional authentication controls for administrative users.
Clients can also apply IP range restrictions and country based geo-restrictions.
When specific instructions or a request for information are shared with a law firm, authorised law firm users access that information in real time.
Each request is validated against the client-side user, the law firm, the law firm-side user, the authorised client-to-law firm relationship and the relevant matter before information is returned.
Sharing specific information with a law firm does not create a second copy of the client’s matter information in the law firm’s Lawcadia environment. The law firm environment stores its own user, permission and configuration information, while shared client information is accessed in real time when required.
This keeps the client’s matter record as the authoritative record.
If an engagement ends, a panel relationship changes or a security concern arises, the client-to-law firm pathway can be restricted or revoked, preventing further access to the shared information.
Supported integrations use secure authentication protocols such as OAuth 2.0. Where applicable, Lawcadia matter permissions are carried through to connected systems so that users only access information they are authorised to view. Where organisations use Microsoft sensitivity labels and information protection controls within SharePoint, Lawcadia works with documents in the client’s Microsoft 365 environment, helping maintain the organisation’s existing information governance controls.
Lawcadia APIs support token based authentication, token expiry and revocation, encrypted token storage and audit logging.
Secure API integrations are also available in addition to webhooks. Through these, Lawcadia allows external applications such as CRMs, Integration Platforms (iPaaS), and custom applications to securely exchange information through the Lawcadia Public API.
Proactively fixing issues as they arise supports continuous improvement and allows for positive and more frequent enhancement cycles.
Platform changes are subject to controlled release management, automated and manual code review, static application security testing, dynamic application security testing, unit testing and functional testing.
Relevant events are brought together within Lawcadia’s Security Information and Event Management (SIEM) environment to support alerting, analysis and incident response. Access to security logs is restricted to authorised personnel.
Clients do not need to maintain or operate the underlying backup infrastructure.
Lawcadia’s standard platform uptime service level is 99.9 per cent, excluding scheduled downtime.
Frequently Asked Questions
What security certification does Lawcadia hold?
Lawcadia holds ISO 27001:2022 certification for its Information Security Management System. This is an internationally recognised standard that requires independent third-party assessment, rigorous auditing, penetration testing and continuous security improvement.Â
Lawcadia also holds Cyber Essentials Plus certification.
These certifications provide independent assurance that Lawcadia maintains documented, reviewed and audited information security controls.
Where is Lawcadia data stored?
Lawcadia data is hosted on Amazon Web Services (AWS) infrastructure in Sydney (Australia), London (United Kingdom), or Oregon (United States), depending on the region of the organisation.
Under the standard shared tenancy model, client data is stored within the selected AWS region and distributed across multiple Availability Zones for resilience. This geographic distribution supports data sovereignty requirements.Â
Does Lawcadia offer private cloud hosting?
Yes. Private Cloud Infrastructure is available for organisations requiring dedicated infrastructure, separate storage or additional control over encryption keys.
Private Cloud data storage can be deployed in any AWS region. Processing must occur through one of Lawcadia’s supported regional processing hubs.
Can clients manage their own encryption keys?
Clients using eligible Private Cloud Infrastructure may use their own AWS KMS key for the cloud level encryption layer.
Lawcadia’s separate application level encryption continues to apply.
How does Lawcadia encrypt client information?
Lawcadia applies encryption controls to protect information both in transit and at rest. Client data is not written to persistent storage as plain text. Further information can be provided during a security review.
How does Lawcadia control user access?
Lawcadia supports role-based access control (RBAC) to ensure users can only access information relevant to their role and responsibilities. Information barriers can be applied at matter level for highly sensitive work.
Access can be managed through SAML 2.0 single sign on, SCIM user provisioning and supported multifactor authentication controls.
Can access be restricted by country or IP address?
Yes. Clients can apply country based geo-restrictions and IPv4 or IPv6 range controls where additional geographic or network restrictions are required.
How does Lawcadia control law firm access?
Law firms access Lawcadia through their own enterprise accounts. Law firms can only access the specific external counsel information shared with them, such as instructions, RFPs, scopes, budgets and invoices. They cannot access the client’s internal emails, documents, activities or workflows.
Law firm access is also subject to the relevant client, law firm, user and matter-specific relationship. If that relationship is restricted or removed, access to the associated information is also revoked.
Does Lawcadia undertake penetration testing?
Yes. Lawcadia undertakes independent penetration testing at least annually and before major platform releases. Testing is performed by a CREST certified third party provider.
More information may be made available to authorised organisations as part of a formal security review.
How does Lawcadia monitor security events?
Lawcadia monitors infrastructure, network, application, access and audit events.
Relevant logs are fed into Lawcadia’s Security Information and Event Management (SIEM) environment to support centralised alerting, investigation and incident response.
What is Lawcadia's SecurityScorecard rating?
Lawcadia holds an ‘A’ grade on SecurityScorecard, an independent cybersecurity rating platform used by over 70,000 organisations globally. SecurityScorecard assesses security performance across ten risk factors. Lawcadia consistently outperforms competitors.
How are backups managed?
Backups and infrastructure recovery controls are managed by Lawcadia as part of the SaaS service.
Restoration and data export requests can be supported through an approved support and governance process.Â
Can Lawcadia support regulated corporate and government organisations?
Yes. Lawcadia is designed for organisations operating in complex and regulated environments, including financial services, government, infrastructure and healthcare-adjacent industries.Â
Lawcadia combines independently certified security controls with granular permissions, regional hosting, information barriers, audit logging and relationship-based access governance.
More detailed architecture and assurance documentation can be provided as part of an organisation’s security, privacy and procurement review.
Does Lawcadia support Microsoft Purview sensitivity labels?
Yes. Lawcadia’s SharePoint integration respects and preserves Microsoft sensitivity labels applied through Microsoft Purview Information Protection.
Where organisations use sensitivity labels and information protection controls within Microsoft 365, Lawcadia works with documents stored in the client’s SharePoint environment while maintaining the organisation’s existing governance settings. This helps legal teams manage matters and collaborate without bypassing established information protection controls.
What is Lawcadia’s platform availability commitment?
Lawcadia’s standard platform uptime service level is 99.9 per cent, excluding scheduled downtime.
Planned downtime is never scheduled during normal regional business hours.
Can clients extract their data at the end of the contract?
Yes. Lawcadia supports structured JSON exports, matter-based folder exports containing documents and emails in their original formats, and metadata exports in formats such as CSV.
Where clients use SharePoint, iManage or OpenText Content Manager as their document repository, the files remain within that connected enterprise repository.
How are Lawcadia integrations secured?
Supported integrations use secure authentication protocols such as OAuth 2.0.
For integrations including SharePoint and iManage, access is aligned with Lawcadia’s matter permissions so that users only see information they are authorised to access.
Does Lawcadia use sub-processors and where are they located?
Lawcadia uses a limited number of sub-processors.
For Australian clients, all sub-processing is undertaken in Australia.
For clients in other jurisdictions, all key sub-processing occurs in the same location as the regional processing hub, and sub-processing activities related to Lawcadia’s first and second level support occur in Australia, although this can be limited if required. Details of applicable sub-processors can be provided as part of a security review.Â
For Lawcadia AI, AI processing will take place in the jurisdiction of the client’s chosen data centre. This means AI processing for Australian-hosted clients will occur in Australia, UK-hosted clients in the United Kingdom, and US-hosted clients in the US.