Skip to content
Docket Build

Trust

Immigration files are the most sensitive documents your firm holds.

Passports, alien registration numbers, financial records, and in humanitarian matters, accounts of abuse protected by statute. Handing that to a vendor is a Rule 1.6 decision, and it deserves specifics rather than reassurance.

Certification
SOC 2 Type II
Hosting
ISO 27001
Encryption
AES-256
Model training
Zero
Docket Build data handling architecture showing the encrypted processing boundary and what never leaves it

Controls

Six areas, specified.

Encryption

  • AES-256 at rest across all document stores
  • TLS 1.3 in transit with HSTS enforced
  • Envelope encryption with per-tenant data keys
  • Keys rotated on a 90-day schedule

Model training exclusion

  • Contractual exclusion in the DPA, not a policy page
  • Covers pre-training, fine-tuning and evaluation
  • No cross-tenant context at inference time
  • Verified in the SOC 2 Type II report

Access control

  • Matter-scoped permissions, not firm-wide
  • Role-based access for attorneys, paralegals and admins
  • SSO/SAML and SCIM provisioning on Scale
  • Restricted workspaces for 8 USC 1367 matters

Infrastructure

  • ISO 27001 certified data centres
  • US and India data residency, selectable per firm
  • Isolated tenant storage with no shared buckets
  • Annual third-party penetration test

Audit and retention

  • Full audit log of every document action
  • Firm-set retention, 180-day default after export
  • Matter-level retention on Scale
  • Purge on demand with a certificate of destruction

Programme

  • SOC 2 Type II — security, availability, confidentiality
  • Documented incident response with 24-hour notification
  • Vendor and subprocessor review annually
  • Background checks on all staff with production access

Attorney ethics

The rules do not prohibit vendors. They impose obligations.

Model Rule 1.6(c) requires reasonable efforts to prevent unauthorised disclosure. Rule 5.3 extends supervisory responsibility to non-lawyer assistance, and Comment 3 makes clear that includes vendors outside the firm. Rule 1.1 Comment 8 adds a duty to keep abreast of the benefits and risks of relevant technology.

None of that makes using software improper. It makes doing the diligence, documenting it, and re-checking it annually part of the job.

Open the trust center

The diligence checklist we answer in writing

  • Is exclusion from model training in the contract, or only in a policy page?
  • Does the exclusion cover fine-tuning and evaluation as well as pre-training?
  • Where is data stored, and can residency be constrained?
  • What is the retention default, and can the firm set it per matter?
  • Can data be purged on demand with a certificate of destruction?
  • Is there a current SOC 2 Type II report, and does it cover these controls?
  • Which subprocessors touch client content, and are they disclosed?
  • What is the breach notification obligation and its timeline?

All eight are answered in the Rule 1.6 and 5.3 compliance memo, available under NDA.

FAQ

Security and ethics.

Something not covered here? Write to security@docketbuild.com.

Rule 1.6(c) requires reasonable efforts to prevent unauthorised disclosure. Comment 18 weighs sensitivity of the information, likelihood of disclosure, and the cost and difficulty of safeguards. Immigration files sit at the sensitive end, so we implement matter-scoped access, AES-256 at rest, TLS 1.3 in transit, isolated tenant storage, full audit logging and firm-controlled retention, and we document all of it so the firm has evidence of its diligence on file.

Start free trial

Stop losing flat-fee profit to manual PDF formatting.

Upload one messy client folder. Get back an audit-ready, Bates-stamped exhibit packet with a two-tier index and a matched cover letter — in about three minutes.

14-day free production trial · no card · real matters · no watermark

Software for licensed attorneys. Not legal advice.

Docket Build is legal technology software designed for use by licensed attorneys and legal professionals. Docket Build does not provide legal advice, does not practice law, and does not create an attorney–client relationship. All legal theories, filings, and petitions must be reviewed and approved by a qualified attorney.