Security at Formata

Security built into the workflow.

Formata is designed to protect confidential legal deadline information through layered account, application and data controls—while collecting less case data in the first place.

Formata is pursuing independent assurance, including SOC 2 and ISO/IEC 27001. Until an examination or certification is formally completed, Formata will describe these as targets—not completed credentials.
Current protections

Controls already implemented.

Hardened multi-factor authentication

MFA is enforced for authenticated users in production. TOTP codes cannot be replayed, secrets support controlled key rotation and recovery codes are securely hashed.

Explicit firm separation

Matters, deadlines and integrations are restricted to the selected firm. Users belonging to multiple firms must explicitly choose their active firm context.

Role-based administration

Owner, administrator, lawyer and assistant capabilities are separated. Firm owners do not receive system-wide platform administration.

Secure invitations and sessions

Revoked invitations cannot be reused. Password and account changes invalidate unfinished authentication, while users can review and revoke their sessions after reauthentication.

Protected integrations

Connected-account tokens are encrypted before storage. Provider requests use approved HTTPS destinations, bounded responses and sanitized errors.

Append-only accountability

Security-sensitive actions and deadline decisions retain data-minimized snapshots. Application controls prevent ordinary alteration or deletion of those audit records.

Browser protections

CSRF validation, secure production cookies, private-page no-store rules, clickjacking protection and nonce-based content security policy reduce common web risks.

Validated application inputs

APIs reject unexpected fields, malformed dates, invalid types and oversized payloads before records are changed.

Reproducible security checks

Dependencies are locked with cryptographic hashes and audited for known vulnerabilities in automated GitHub security workflows.

Data minimization

Store what deadline management needs.

Formata's intended boundary is the minimum information needed to identify, calculate, assign, remind and audit a deadline.

  • Firm, user, role and assignments
  • Client or matter name and file number
  • Jurisdiction, matter type and trigger dates
  • Deadlines, reminders and completion state
  • Audit and synchronization history
  • Encrypted credentials for connections
Not a case-document repository: Formata is not intended to store complete Filevine or Clio files, medical records, correspondence or general case documents. Imports should be one-way and limited to deadline-management fields.
Accountability

Actions leave a decision trail.

Deadline creation, changes, exclusions, overrides, reassignment and completion remain reviewable. Unsupported jurisdiction rules are blocked rather than guessed.

Secure staff lifecycle

Staff activation links are single-use and time-limited. Revocation stops access, and open deadlines can be transferred to a replacement lawyer and assistants before departure.

Deadline review

Calculated deadlines require a server-signed calculation snapshot and approval by an active lawyer or owner before activation.

Controlled synchronization

Filevine imports are strictly inbound-only, cross-firm inconsistencies stop synchronization, and each completed import is recorded.

Independent assurance roadmap

Formal certification targets.

Formata intends to engage qualified independent assessors. Scope, evidence and timing will be confirmed with those assessors before any certification claim is published.

SOC 2

Prepare the control environment and evidence for an independent SOC 2 examination, beginning with Security and adding relevant availability, confidentiality, processing-integrity or privacy criteria based on customer needs.

ISO/IEC 27001

Build and operate an information security management system with defined scope, risk assessment, treatment plan, policies, control ownership, internal audit and management review before the accredited certification audit.

Additional assurance

Evaluate CSA STAR for cloud-security transparency and complete Canadian privacy, vendor-risk and penetration-testing reviews. These support assurance but do not replace legal privacy obligations.

Pilot launch controls

Operational checks still required.

Code controls are one part of a secure launch. These items must be configured and tested before confidential production use.

Email delivery

Configure the notification mailbox and test invitations, reminders, bounce handling and sender authentication.

Live integration validation

Connect the pilot firm's Filevine account with least-privilege access and validate one-way mapping using test matters first.

Recovery and monitoring

Run a database restore test, enable error alerting, document incident contacts and confirm credential rotation.

Rule verification

Every enabled rule and source requires jurisdiction-appropriate legal review. Formata remains a workflow aid, not legal advice.

Pilot acceptance test

Test authentication, permissions, matter entry, calculation review, reminders and audit history with approved scenarios.

Vendor review

Document hosting, database and email providers, retention expectations and access responsibilities.

Security questions

Review Formata with your firm.

We can walk your pilot team through the data boundary, account controls and launch checklist.

Request a security conversation