If you run supplier due diligence for a law firm or a public sector body, information security sits right near the top of the checklist. Before a new tool goes anywhere near matter data, client records or case files, someone has to answer for how that data is handled – to clients, to regulators, and to a risk committee that will reasonably want more than a supplier’s word for it.
We’re delighted to share that we have now achieved ISO 27001 certification, audited by Perry Johnson Registrars against the ISO/IEC 27001:2022 standard. The certification is UKAS-accredited.
Certification won’t change how we work day to day. It validates the standards we’d already built into the business, and gives us a framework to keep improving on them as we grow. What it changes is our ability to show that work to the people who are right to ask about it.
What ISO 27001 certification means if you’re evaluating suppliers
And they are certainly right to ask. When we talk to heads of IT, COLPs and operations leads, questions about a tool’s capability come up far less often than questions about confidence. Firms need to know they can stand behind how client data is handled once a supplier is inside the tent. Your regulator holds you accountable for that choice, so putting a supplier’s security posture under proper scrutiny is what good due diligence looks like. Certification is one of the concrete ways we can meet it.
It matters, too, because of how our tools are built. They connect to the case management and productivity systems firms already run (such as Actionstep, Aderant, MatterSphere, LEAP, Microsoft 365) rather than asking anyone to move off them. That approach keeps disruption low, and it also means client data moves between our tools and systems you already trust. The point where our security has to hold up is the point where we connect into your environment, so how we manage that connection carries real weight. Certification covers exactly that: the data that flows across the join, and the controls that govern it.
It’s also not a one-off. The standard requires ongoing review and re-audit rather than a single sign-off, so our controls stay live as our products develop, as we take on new clients, and as the systems we integrate with change. What gives a certificate like this its weight is everything underneath it – the risk assessments, the access controls, the incident processes and the audit that keeps them current.
The legal and public sector organisations we work with are accountable for their clients’ data every day. Achieving ISO 27001 is how we hold ourselves to that same standard, and how we intend to keep operating as we grow: building tools that earn a place in firms handling sensitive work, and being able to account for how we treat the data that runs through them.