Security & data handling
Built for confidential legal work.
What protects your documents, who can see them, and how we handle data. Written to be pasted into your vendor questionnaire.
Two layers of protection
Your engagement is with a law firm ([Firm Name, PLLC]). That brings the protections a law firm owes you: the duty of confidentiality under its state’s rules of professional conduct (Rule 1.6), attorney–client privilege where it applies, professional-liability insurance, and a bar you can complain to. Icon Partners, which runs the desk, is the firm’s vendor and is bound to the firm by a written confidentiality and data-processing agreement that mirrors those duties.
Where your documents live
Matter documents live in Icon Partners’ company systems — Google Workspace and Slack — and are shared with you through a secure upload link and a private channel per client. Nothing is kept on personal accounts or devices. We do not accept contract documents by ordinary email attachment unless you choose to send them that way. Data is encrypted in transit (TLS 1.2+) and at rest by the platform provider. Access to each matter folder is limited to the people working on that matter.
Who can see them
The responsible attorney at the firm, and the named Icon Partners production and project staff assigned to your matter. Every person with access has signed a personal confidentiality undertaking and works under the attorney’s supervision (Rule 5.3). No offshore subcontractors, no anonymous freelancers, no data brokers. A list of individuals with access to your matter is available to you on request.
Access controls
Multi-factor authentication on every account that touches matter data. Access is granted per matter and removed when the matter closes or the person leaves. Every team member works under a written contract and a signed confidentiality undertaking, and goes through regular internal training on confidentiality and data handling.
Software and AI tools
Your documents do not go into AI tools. Our rule is simple and enforced: client documents and anything that identifies a client stay out of AI systems; AI is used only on anonymised material and on our own templates and playbooks. Every draft is reviewed and approved by the attorney before you see it.
GDPR and data-processing agreement
Icon Partners is established in the European Union and processes personal data in your documents as the firm’s processor under a written data-processing agreement (GDPR Article 28). If your own customers require a DPA that covers your vendors, we sign one with you: the firm as processor, Icon Partners as sub-processor. Sub-processors at this date: Google Workspace, Slack, Cloudflare (website hosting). We give 14 days’ notice before adding one.
Incidents
If we become aware of a security incident affecting your documents, the firm tells you within 48 hours with what we know, what we have done and what we need from you. There has been no such incident to date.
Retention and return
On request, and in any case within 30 days of a matter closing, Icon Partners returns or securely deletes matter documents. The firm keeps its own file for the period its rules require (seven years) and destroys it afterwards.
For your security questionnaire
We keep a maintained master answer set and can return most vendor questionnaires within a few business days. Ask at hello@engross.legal with “security questionnaire” in the subject line.
16 September 2026. This page is a statement of practice, not a contractual commitment; the commitments are in your engagement letter and data-processing agreement.