Skip to main content

Trust Centre

Security, privacy and compliance

Law firms hold some of the most sensitive information there is. This page sets out how we look after it, and how to get the documentation your compliance team needs.

  • ISO/IEC 27001 Certified
  • Cyber Essentials Certified

ISO 27001 certified

Our information security management system is independently certified to ISO/IEC 27001.

Cyber Essentials certified

Independently certified against the UK Cyber Essentials security standard.

UK GDPR

Data protection is designed in, from erasure handling to a Data Processing Agreement for customers.

UK data residency

Customer data is stored in UK data centres.

Certification

Superlawyer Ltd is certified to ISO/IEC 27001:2022 by INTERCERT Inc., under certificate number IC-IS-2603159. The certificate covers the design, development, maintenance, sales and operation of our cloud-based legal technology platform and related SaaS services.

You can check the full scope and authenticity on INTERCERT's certificate verification page using certificate number IC-IS-2603159. Our supporting policies are available to customers and prospective customers as part of vendor due diligence.

If your firm runs a supplier assessment process, we're used to completing security questionnaires. Ask and we'll turn it around promptly.

Security in the platform

  • Microsoft Entra single sign-on, helping firms enforce stronger authentication and manage access centrally
  • Fully customisable user roles, so administrators decide which people can see and do what
  • More than 100 individual permissions to support practical separation of duties and matter access
  • Enterprise branch management supports data isolation, with a permission-gated consolidated view for firm-wide oversight
  • Restricted and confidential matters with per-file access controls
  • Append-only financial records with a full audit trail; corrections are made by reversal with a reason, never by deletion

Data protection

Customer data lives in UK data centres.

A Data Processing Agreement is available for all customers. Our privacy policy covers how this website itself handles personal information.

Financial integrity

Superlawyer's accounts engine is built around shared client money controls, with support for regulator-specific requirements: three-way bank reconciliation with reminders and immutable sign-off, a breach register that can't be quietly emptied, client-account overdraft prevention, segregation of duties, and period locking. Compliance evidence is produced by the system as your team works, not assembled by hand before an audit.

Vendor due diligence

Bring us your security questionnaire

Email the team at [email protected] for the ISO 27001 certificate, our Data Processing Agreement or help completing a supplier assessment - we'll come back to you quickly.