<!-- src/content/pages/hosting-and-data-residency.md -->
---
title: Hosting and data residency
summary: Where your data is stored and processed, and whether it ever leaves Australia.
order: 1
lastReviewed: 2026-10-07
---

## Where the service runs

LawManage runs on Microsoft Azure.

> **To confirm before publishing:** the Azure region for production, and whether backups, log storage and any
> AI processing stay in the same region.

## What is stored

- Matter, contact and intake records, in a dedicated database per environment.
- Documents and files, in Azure blob storage.
- Email and calendar data synchronised from Microsoft 365, where a firm has connected it.

## Environments

Production holds live firm data. A separate sandbox environment exists for evaluation and training and is never
loaded with production data unless a firm asks for it.


---

<!-- src/content/pages/security.md -->
---
title: Security
summary: How accounts, access and data in transit and at rest are protected.
order: 2
lastReviewed: 2026-10-07
---

## Signing in

- Every sign-in requires a password and a one-time code sent by email.
- Access is granted per firm. A person removed from a firm, or whose seat is unassigned, can no longer sign in to
  that firm, even if their password is still valid.

## Roles and permissions

Each user holds one or more roles within their firm. What a role can see and do is set by the firm's administrators.

## Data in transit and at rest

- All traffic between your browser, the Word and Outlook add-ins and LawManage is encrypted with TLS.
- Databases and file storage are encrypted at rest by Azure.

> **To confirm before publishing:** TLS minimum version, key management, and whether any field-level encryption
> applies to integration credentials such as InfoTrack logins.

## Who at LawManage can see firm data

> **To confirm before publishing:** who holds production access, how it is granted and logged, and under what
> circumstances support staff open a firm's data.


---

<!-- src/content/pages/backups-and-continuity.md -->
---
title: Backups and continuity
summary: How often data is backed up, how long it is kept, and how you get it back.
order: 3
lastReviewed: 2026-10-07
---

## Backups

> **To confirm before publishing:** backup frequency, retention period, geographic location of backups, and how
> often a restore is tested.

## Getting your data out

A firm can export its matters and contacts at any time. On leaving LawManage, a firm can request a full export of its
records and documents.

> **To confirm before publishing:** the export formats available today and how long data is retained after a firm
> closes its account.

## Availability and incidents

> **To confirm before publishing:** the uptime target, whether a status page exists, and how firms are told about an
> outage or a security incident.


---

<!-- src/content/pages/sub-processors.md -->
---
title: Sub-processors
summary: The third parties that process data on LawManage's behalf, and what each one does.
order: 4
lastReviewed: 2026-10-07
---

LawManage relies on the following providers to run the service. Each one receives only the data it needs for its
purpose. We update this list when a provider is added or removed.

| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Microsoft Azure | Hosting, database, file storage, backups | All firm data | To confirm |
| Microsoft 365 (Graph) | Email and calendar sync, Word and Outlook add-ins | Mail, calendar and documents the firm connects | Firm's own tenancy |
| Stripe | Subscription billing | Firm name, billing contact, payment method | To confirm |
| Email delivery provider | Sign-in codes, invitations, notifications | Recipient address and message content | To confirm |
| InfoTrack | Property and company searches ordered from a matter | Matter reference, search results, firm's InfoTrack credentials | Australia |

> **To confirm before publishing:** which email provider is live in production (Azure Communication Services or
> SendGrid), the region for each provider, and whether any AI model provider processes firm content.


---

<!-- src/content/pages/privacy-and-legal.md -->
---
title: Privacy and legal
summary: Privacy obligations, how a data breach would be handled, and the documents that govern the service.
order: 5
lastReviewed: 2026-10-07
---

## Privacy

LawManage is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Firms remain responsible
for the personal information they hold about their clients; LawManage processes it on the firm's instructions.

## Notifiable data breaches

If a breach is likely to result in serious harm, LawManage notifies the affected firms and the Office of the
Australian Information Commissioner in line with the Notifiable Data Breaches scheme.

> **To confirm before publishing:** the target time for notifying firms, and who the point of contact is.

## Documents

- Privacy policy: to be linked.
- Terms of service: to be linked.
- Data processing terms for firms that need them: to be confirmed.


---

<!-- src/content/pages/contact-and-disclosure.md -->
---
title: Contact and disclosure
summary: How to reach us about security, and how to report a vulnerability.
order: 6
lastReviewed: 2026-10-07
---

## Security questions

Email [security@lawmanage.com.au](mailto:security@lawmanage.com.au). If you have a security questionnaire to complete,
send it through and we will return it with references to the relevant pages here.

> **To confirm before publishing:** that the mailbox exists and who monitors it.

## Reporting a vulnerability

If you believe you have found a security issue in LawManage, email the address above with enough detail for us to
reproduce it. We will acknowledge the report, keep you informed as we investigate, and will not take action against
anyone who reports in good faith and avoids accessing other firms' data.

## Changes to this site

Each page shows the date it was last reviewed. Material changes to sub-processors or data location are listed here.

- 7 October 2026: Trust Centre created.
