Trust Centre
Last updated 10 October 2026
A law firm's records are its clients' confidences. This page sets out how Docavra keeps them, and is kept current as the measures change.
On this page
Separation
Each firm's records sit in a database of the firm's own, never pooled with another firm's, so one firm's data cannot reach another's through a fault in the code.
Access
- Permissions set by the firm for each role, granted only by someone who holds them.
- Information walls that close a matter to the people the firm names.
- Two-step sign-in, by authenticator app or emailed code, and single sign-on with Google or Microsoft.
- Sign-outs after inactivity, a lock screen, and a list of each person's sessions they can end.
- An audit trail of every change to a record the firm relies on, which no one can edit.
Protection in transit and at rest
Every connection is encrypted with TLS. The database, files and backups are encrypted at rest by our providers. Uploaded files are scanned for malware and held apart until they are clean.
Backups and recovery
Backups run continuously, with point-in-time recovery, and a restore is rehearsed on a schedule so recovery is proven before it is needed. The firm can export all its data at any time in open formats.
Incidents
Errors and unusual activity are monitored. We follow a written incident response plan: contain, investigate, restore and notify, telling an affected firm without undue delay and within 72 hours of learning of a breach of its data.
Reporting a weakness
If you find a security weakness, write to [email protected] with the details. We answer within two working days and ask that you give us time to fix it before telling anyone else.
Providers
The services we use to run the platform, and what each handles, are on the Subprocessors page.