Legal · Vertical Microsite

Built for South African legal practices — where privilege is a feature, not a footnote.

POPIA for attorneys, Legal Practice Council compliance, FICA AML automation, and matter-scoped secure client portals. For commercial firms, sole practitioners, advocates' chambers, conveyancers, and corporate legal — engineered with the rigour the profession demands.

Commercial Firms Sole Practitioners Advocates' Chambers Conveyancers Corporate / In-House Counsel Multi-Office Practices

Four pillars. Non-negotiable.

Every legal practice system we ship is anchored to the frameworks that govern South African legal work. These are not optional. They are how we build.

POPIA for Attorneys

Lawful processing of client personal information with section 7 litigation-privilege exemptions preserved. Information Officer registration, PAIA manual, and breach notification workflows hard-wired in.

Compliance Verified

LPC / Legal Practice Act

Aligned to Legal Practice Council rules — trust account integrity (Rule 54), client identification, fidelity fund obligations, and conduct standards baked into the workflow.

Advisory Alignment

Trust Account Safeguards

Trust ledgers reconciled nightly against bank, every receipt and disbursement matter-tagged, auditor packs generated on demand, and section 86(4) interest reporting automated.

Audit-Ready

FICA AML

Customer Due Diligence at intake — SA Home Affairs ID verification, PEP and sanctions screening, source-of-funds capture, risk rating, and goAML-ready STR workflow.

Operationally Embedded

Six modules. One coherent practice.

Deploy as a full Practice-In-a-Box for legal, or layer individual services on top of what you already run.

Secure Client Matter Portal

End-to-end encrypted matter rooms with explicit consent ledgers, document vaults, and privileged-recipient watermarking. Client sees only what is theirs.

  • Matter-scoped access control
  • Encrypted document vault per matter
  • Privileged-recipient watermarking
  • Consent + access audit ledger
Request Quote →

E-Signature & ID Verification

ECTA-compliant electronic signing with Home Affairs ID verification, biometric capture where required, and full chain-of-custody for affidavits and contracts.

  • ECTA section 13 compliant
  • Home Affairs ID lookup integration
  • Liveness / biometric capture
  • Court-admissible audit trail
Request Quote →

Conflict Check & Intake

Automated conflict-of-interest search across current and historical matters, paired with FICA-aligned client onboarding — CDD, PEP screening, and risk rating in one flow.

  • Cross-matter conflict search
  • FICA Schedule 1 CDD
  • PEP & sanctions screening
  • Source-of-funds capture
Request Quote →

Matter Management & Billing

Full matter lifecycle — file opening, time capture, disbursement tracking, billing, and trust account integration. Six-minute units, fee narratives, and party-and-party costs.

  • Six-minute unit time capture
  • Disbursement & trust integration
  • Bill of costs (party-and-party / attorney-client)
  • SARS-compliant tax invoicing
Request Quote →

Secure Email Gateway

All correspondence with opposing counsel and external parties routes through a metadata-stripping, TLS-enforced gateway that prevents accidental privilege waiver via document metadata.

  • Metadata scrub on outbound attachments
  • TLS-enforced delivery to recipients
  • Spear-phishing and BEC protection
  • Privileged-tag retention
Request Quote →

POPIA + LPC Audit

Engineering-grade compliance audit — data-flow mapping, POPIA 8-condition gap analysis, LPC Rule 54 trust account readiness review, and regulator-ready remediation plan.

  • Data-flow + asset inventory
  • POPIA 8-condition gap analysis
  • LPC Rule 54 audit readiness
  • Information Officer registration
Request Quote →

Most "law firm software" treats privilege as a label on a folder.

We treat it as a structural property of the system. Every design decision — from how matter rooms are partitioned, to how metadata is stripped from attachments, to who can see access logs — starts from the question: does this protect the privileged relationship between attorney and client?

That changes the answer at every layer. Storage, access control, audit logging, even who at the firm can see whose calendar — all reconsidered through the privilege lens.

If your IT was built for generic professional services and then "configured for legal", you're carrying privilege risk you may not have inventoried.

What privilege-first means in practice

Matter-scoped access by default No firm-wide search reveals privileged content. Access is granted per matter, per role, with explicit consent capture and full audit trail visible to the lead attorney only.
Outbound metadata stripping Every attachment sent to opposing counsel passes through a metadata scrubber — author, edit history, tracked changes, hidden text, and comments removed before send. Accidental privilege waiver prevented at the wire.
Practitioner-only audit logs Audit logs for matter access are visible to the supervising attorney only — not to firm-wide IT admin. Investigating leaks does not require exposing privileged matter detail.
Privileged-recipient watermarking Every privileged document carries an embedded watermark identifying its intended recipient. If it leaks, you know from whom.
SA-resident hosting All client and matter data hosted on SA soil. Cross-border transfer requires explicit authorisation under POPIA section 72. No silent foreign-data-centre fallback.
Retention & destruction certificates Matter files retained per LPC Rule 56 timeframes. When destruction is due, the system issues a signed destruction certificate — auditable proof that closed-matter obligations have been discharged.

Engineering posture, legal posture.

8/8 POPIA conditions covered
100% SA-resident hosting
5–10 Business days to live portal
0 Privilege carve-outs in our SLAs

The questions attorneys actually ask.

How does your client portal protect attorney–client privilege?

Privilege protection is built into the architecture, not bolted on. Matter rooms are end-to-end encrypted, access is matter-scoped with explicit consent ledgers, attachments to opposing counsel route through a metadata-stripping gateway, and every privileged document carries a watermark identifying the recipient. Audit logs are practitioner-only and not exposed to firm-wide admin by default.

Are you POPIA-compliant for an attorneys' practice specifically?

Yes. Our POPIA implementations for legal practices treat the firm as a Responsible Party while preserving litigation privilege exemptions under section 7. We map client personal information flows, set lawful processing bases per matter type, register your Information Officer with the Information Regulator, and ship a regulator-ready PAIA manual aligned to the legal practice context.

Can your platform handle FICA AML obligations end-to-end?

Our client intake automation runs Customer Due Diligence (CDD) at onboarding — ID verification via SA Home Affairs lookup, PEP and sanctions screening, source-of-funds capture, and risk-rating per FICA Schedule 1. Suspicious Transaction Report (STR) workflow flags trigger an evidence pack ready for FIC submission via goAML.

How do you handle trust account audit readiness?

We integrate trust account ledgers with your firm's matter management so every receipt and disbursement is matter-tagged and time-stamped. Reconciliations to bank statements run nightly. The system generates auditor-ready packs aligned to LPC Rules 54.14 trust account audit requirements, with section 86(4) interest reporting automated.

What if I am an advocate in chambers, not a firm?

Our chambers stack is leaner — a referral-only intake portal, instructing-attorney correspondence vault, brief management with diary integration, and discreet billing. Chambers share infrastructure cost without sharing matter visibility — each advocate's data is isolated by default.

What happens to my matter data if I leave?

Your matter files are yours. Every legal engagement includes a data portability clause — full encrypted export in standard formats (PDF/A for documents, structured JSON for matter metadata and time entries, SQL dumps for relational data), plus a 90-day supervised handover window. Privileged material remains under your control end-to-end.

Where can I read the detailed cybersecurity write-up?

See our long-form law firm cybersecurity reference at law-firm-cybersecurity-south-africa and the verifiable regulatory framework alignment on the Trust & Compliance Hub.

Let's build the practice your clients trust you with.

A 30-minute diagnostic call. No deck, no sales script — just an engineer and a practitioner working out what the right infrastructure looks like for your specific practice.

Practice Diagnostic