Security and Data Protection
Designed for regulated and complex environments.
SECURITY MATTERS
Security Designed for Legal Operations
Legal teams manage privileged, confidential and commercially sensitive information across internal stakeholders, external law firms and service providers.

Lawcadia is designed as a closed system for legal operations, with tightly controlled access, comprehensive security and audit logging, and a security architecture built specifically for the way in-house legal teams work. Users are authorised, permissions are clearly defined, and activity across the platform is monitored and auditable.

When working with external law firms, Lawcadia supports a controlled exchange of specific instructions and information such as scopes, budgets and invoices.

The platform combines these purpose-built controls with independently assessed information security standards to help legal teams manage sensitive legal work with greater control and oversight.
Data security
Private Cloud
SECURITY CONTROLS
Independently Assessed Security
Lawcadia operates an ISO 27001:2022 certified Information Security Management System and holds Cyber Essentials Plus certification. Our security controls are supported by regular independent audits, annual penetration testing and additional testing before major platform releases. Independent penetration testing is undertaken by a CREST certified security provider.
ISO 27001 certified Information Security Management System
Cyber Essentials Plus certified
Independent penetration testing
Continuous monitoring and security improvement
SecurityScorecard A rating
DATA HOSTING
Data Hosting And Residency
Lawcadia is hosted on Amazon Web Services. Clients who opt for standard shared tenancy may select data hosting in Sydney, Australia, London, United Kingdom, and Oregon, United States.

Under the standard shared tenancy model, client data is stored within the selected AWS region and distributed across multiple Availability Zones for resilience. Data always remains within the selected region.

Private Cloud Infrastructure is available for organisations with additional hosting, isolation or encryption requirements. Managed by Lawcadia, this option provides dedicated infrastructure, separate storage and a dedicated AWS KMS encryption key. Eligible clients may also manage the AWS KMS key used for the cloud level encryption layer.

Private Cloud Infrastructure may be deployed in other AWS regions with platform processing through one of Lawcadia’s supported regional processing hubs.
Secure Platform
Content Manager
SUB-PROCESSING
Sub-Processing And Data Location
Lawcadia deliberately limits its use of sub-processors and considers data location as part of how services are selected and managed.

For Australian clients, all sub-processing is undertaken in Australia.

For clients in other jurisdictions, including the United Kingdom, Canada and the United States, some sub-processing may occur in Australia. This includes services provided by Lawcadia Pty Ltd and certain Microsoft services. Details of applicable sub-processors can be provided as part of a security or procurement review.

For Lawcadia AI, AI processing will take place in the jurisdiction of the client's chosen data centre. This means AI processing for Australian-hosted clients will occur in Australia, UK-hosted clients in the United Kingdom, and similarly for other supported data centre locations.
ENCRYPTION
Data Encryption
Lawcadia encrypts information while it is being transmitted and utilises dual-layer encryption while it is stored. This includes:
Data in-transit: Protected using TLS encryption
Data at-rest: Protected through dual layer AES 256 encryption
Cloud encryption layer: Managed using AWS Key Management Service
Application encryption layer: Applied by Lawcadia before information is written to storage
Client information is not written to persistent storage as plain text
Information Barriers
Data Subject Access Rights Workflows
ACCESS CONTROLS
Access Management
Lawcadia integrates with enterprise identity and access management (IAM) systems to help organisations maintain consistent access policies.

For Single Sign-on (SSO) Lawcadia utilises SAML 2.0 to exchange authentication and authorisation data between your Identity Provider (IdP) including Okta, Auth0, OneLogin, Microsoft Entra ID, Google IdP and our platform.

We support SCIM (System for Cross-domain Identity Management) to synchronise users, roles and group memberships with the client’s identity provider. This reduces manual administration and allows access to be updated or removed when an employee’s role or employment status changes.

Lawcadia also supports multifactor authentication (MFA) through supported identity providers and additional authentication controls for administrative users.

Clients can also apply IP range restrictions and country based geo-restrictions where additional controls are required.
PROTECTIONS
Network And Application Protection
Lawcadia uses an enterprise Web Application Firewall and content delivery network to protect the platform’s public perimeter. These controls help identify and block malicious requests before they reach the Lawcadia application, including:
Distributed denial of service protection
Web Application Firewall rules
Protection against common OWASP vulnerabilities
API protection
Bot detection and management
Rate limiting
Threat intelligence
HTTP Strict Transport Security
Cybersecurity Ranking
Security Designed For The Client-To-Law Firm Relationship
Controlled, Real-Time Access
Lawcadia has a two-sided architecture, with separate environments for clients and law firms.

When specific instructions or a request for information are shared with a law firm, authorised law firm users access that information in real time.

Each request is validated against the client-side user, the law firm, the law firm-side user, the authorised client-to-law firm relationship and the relevant matter before information is returned.

Client Data Stays With the Client
The client retains its matter information within Lawcadia.

Sharing specific information with a law firm does not create a second copy of the client’s matter information in the law firm’s Lawcadia environment. The law firm environment stores its own user, permission and configuration information, while shared client information is accessed in real time when required.

This keeps the client’s matter record as the authoritative record.
Enterprise Grade Security
Access Can Be Restricted
Law firms can only access the specific external counsel information shared with them, such as instructions, RFPs, scopes of work, budgets and invoices. They cannot access the client’s internal emails, documents, activities or workflows.

If an engagement ends, a panel relationship changes or a security concern arises, the client-to-law firm pathway can be restricted or revoked, preventing further access to the shared information.

Integrations
INTEGRATIONS
Secure Integrations
Lawcadia provides native integrations with Microsoft Outlook, Word, SharePoint, iManage and other enterprise systems.

Supported integrations use secure authentication protocols such as OAuth 2.0. Where applicable, Lawcadia matter permissions are carried through to connected systems so that users only access information they are authorised to view. Where organisations use Microsoft sensitivity labels and information protection controls within SharePoint, Lawcadia works with documents in the client’s Microsoft 365 environment, helping maintain the organisation’s existing information governance controls.

Lawcadia APIs support token based authentication, token expiry and revocation, encrypted token storage and audit logging.

Secure API integrations are also available in addition to webhooks. Through these, Lawcadia allows external applications such as Salesforce, Integration Platforms (iPaaS), and custom applications to securely exchange information through the Lawcadia Public API.

Secure Information Management
Quality Assurance
SecurityScorecard
Independent security ratings company SecurityScorecard calculates cybersecurity scores based on 10 factors that reflect different cybersecurity practices and risks. Lawcadia has an 'A' grading and consistently out-performs competitors.
Frequent Platform Updates
Frequent Platform Updates & Improvements
Regular platform updates and necessary patches are released in the cloud environment without downtime. Releases are tested in separate environments before being approved for production deployment.

Proactively fixing issues as they arise supports continuous improvement and allows for positive and more frequent enhancement cycles.
Automate Workflows
Secure Platform Development
Security controls are incorporated throughout Lawcadia’s software development and release processes.

Platform changes are subject to controlled release management, automated and manual code review, static application security testing, dynamic application security testing, unit testing and functional testing.

Real Time Monitoring
Continuous Monitoring
Lawcadia monitors cloud infrastructure, network activity, application events, security events and audit logs.

Relevant events are brought together within Lawcadia’s Security Information and Event Management (SIEM) environment to support alerting, analysis and incident response. Access to security logs is restricted to authorised personnel.

Back Ups
Backups & Recovery
Platform backups, infrastructure recovery and associated operational controls are managed by Lawcadia as part of the SaaS service.

Clients do not need to maintain or operate the underlying backup infrastructure. Where required, Lawcadia can support approved restoration and data export requests and custom backup arrangements.

Web Application Firewalls
Availability & Downtime
Most platform updates are deployed without service interruption. Where downtime is required, planned maintenance is scheduled outside normal business hours and managed through Lawcadia’s change management process.

Lawcadia’s standard platform uptime service level is 99.9 per cent, excluding scheduled downtime and applicable contractual exclusions.

Frequently Asked Questions

Lawcadia holds ISO 27001:2022 certification for its Information Security Management System. This is an internationally recognised standard that requires independent third-party assessment, rigorous auditing, penetration testing and continuous security improvement. 

Lawcadia also holds Cyber Essentials Plus certification.

These certifications provide independent assurance that Lawcadia maintains documented, reviewed and audited information security controls.

Lawcadia data is hosted on Amazon Web Services (AWS) infrastructure in Sydney (Australia), London (United Kingdom), or Oregon (United States), depending on the region of the organisation.

Under the standard shared tenancy model, client data is stored within the selected AWS region and distributed across multiple Availability Zones for resilience.

This geographic distribution supports data sovereignty requirements and ensures continuity in the event of a regional disruption.

Yes. Private Cloud Infrastructure is available for organisations requiring dedicated infrastructure, separate storage or additional control over encryption keys.

Private Cloud data storage can be deployed in any AWS region, subject to technical assessment. Processing must occur through one of Lawcadia’s supported regional processing hubs.

Clients using eligible Private Cloud Infrastructure may use their own AWS KMS key for the cloud level encryption layer.

Lawcadia’s separate application level encryption continues to apply.

Data in-transit is protected using TLS encryption.

Data at-rest is protected through dual layer AES 256 encryption, combining AWS KMS cloud level encryption with Lawcadia application level encryption. Client data is not written to persistent storage as plain text.

Lawcadia supports role-based access control (RBAC) to ensure users can only access information relevant to their role and responsibilities. Information barriers can be applied at matter level for highly sensitive work.

Access can be managed through SAML 2.0 single sign on, SCIM user provisioning and supported multifactor authentication controls.

Yes. Clients can apply country based geo-restrictions and IPv4 or IPv6 range controls where additional geographic or network restrictions are required.

Law firms access Lawcadia through their own enterprise accounts. Law firms can only access the specific external counsel information shared with them, such as instructions, RFPs, scopes, budgets and invoices. They cannot access the client’s internal emails, documents, activities or workflows.

Law firm access is also subject to the relevant client, law firm, user and matter-specific relationship. If that relationship is restricted or removed, access to the associated information is also revoked.

Yes. Lawcadia undertakes independent penetration testing at least annually and before major platform releases. Testing is performed by a CREST certified third party provider.

More information may be made available to authorised organisations as part of a formal security review.

Lawcadia monitors infrastructure, network, application, access and audit events.

Relevant logs are fed into Lawcadia’s Security Information and Event Management (SIEM) environment to support centralised alerting, investigation and incident response.

Lawcadia holds an ‘A’ grade on SecurityScorecard, an independent cybersecurity rating platform used by over 70,000 organisations globally. SecurityScorecard assesses security performance across ten risk factors. Lawcadia consistently outperforms competitors.

Backups and infrastructure recovery controls are managed by Lawcadia as part of the SaaS service.

Restoration and data export requests can be supported through an approved support and governance process. Bespoke backup arrangements may also be considered where a client has specific retention or recovery requirements.

Yes. Lawcadia is designed for organisations operating in complex and regulated environments, including financial services, government, infrastructure and healthcare-adjacent industries. 

Lawcadia combines independently certified security controls with granular permissions, regional hosting, information barriers, audit logging and relationship-based access governance.

More detailed architecture and assurance documentation can be provided as part of an organisation’s security, privacy and procurement review.

Yes. Lawcadia’s SharePoint integration respects and preserves Microsoft sensitivity labels applied through Microsoft Purview Information Protection.

Where organisations use sensitivity labels and information protection controls within Microsoft 365, Lawcadia works with documents stored in the client’s SharePoint environment while maintaining the organisation’s existing governance settings. This helps legal teams manage matters and collaborate without bypassing established information protection controls.

Lawcadia’s standard platform uptime service level is 99.9 per cent, excluding scheduled downtime and other contractual exclusions.

Planned downtime is not scheduled during normal regional business hours without prior client approval.

Yes. Lawcadia supports structured JSON exports, matter-based folder exports containing documents and emails in their original formats, and metadata exports in formats such as CSV.

Where clients use SharePoint, iManage or OpenText Content Manager as their document repository, the files remain within that connected enterprise repository.

Supported integrations use secure authentication protocols such as OAuth 2.0.

For integrations including SharePoint, Outlook and iManage, access is aligned with Lawcadia’s matter permissions so that users only see information they are authorised to access.

Lawcadia uses a limited number of sub-processors.

For Australian clients, all sub-processing is undertaken in Australia. For clients in other jurisdictions, some sub-processing may occur in Australia, including through Lawcadia Pty Ltd and certain Microsoft services.

For Lawcadia AI, AI processing will take place in the jurisdiction of the client’s chosen data centre, helping clients maintain control over where their information is processed.

Further information about applicable sub-processors can be provided as part of a security or procurement review.