Security & Privacy

JurisFolio is the processor of the practice book. The advocate is the data fiduciary for the client's file. This page describes the product. It is not a DPDP certification.

On the wire and at rest

Flutter talks to the API over HTTPS. The API talks to Postgres with TLS hostname verification to pg18.tailce422e.ts.net.

PII uses an application envelope: AES-256-GCM, one data key per practice, wrapped by a JurisFolio key-encryption key that is not RxFolio's key. Account email, display name, captions, party names, client contact fields, and notes are ciphertext. CNR, case number, court codes, and dates stay queryable and access-controlled.

Case documents

PDFs are ordinary files in the practice owner's Google Drive or OneDrive. They are readable without the app. JurisFolio does not keep those bytes on the API LXC.

Court passwords

After save, a court password is write-only. The Team screen says the password is never shown again. It is not logged.

Roles

A role is the persona and the security profile. Hidden sections are absent from the payload. A 48-hour read link has no Matter Memory and is not a team seat.

What we do not collect

JurisFolio does not train a model on customer files. See Privacy Policy and Professional disclaimer.