Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
By problem · Confidentiality rules

Show the reasonable steps your rules ask for

Law and accounting firms answer to their own professional rules on client confidentiality. Those rules ask for reasonable steps, and name no checklist. We give you a dated outside view of your firm, and put each finding in the terms your rules use.

Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before your assessment is released.

Read-only, from outsideNothing tested or logged intoReviewed by a person
What the rules askRead-only
Lawyers in Canada
Understand the risks of the technology you practise on, and take all reasonable steps to safeguard client confidential information
Lawyers in the US
Make reasonable efforts to prevent unauthorized access to client information
Tax preparers in the US
Keep a written information security plan
Any firm in Canada
Keep a record of every breach of your security safeguards
Reviewed by a person before release. Every finding carries a check anyone can run.
01 · What we check

What the rules ask, and what the outside view can show.

01
Reasonable steps, not a checklist

Law society and bar conduct rules name no specific control. They ask what a reasonable firm would do, so the question is what you can show, not whether you broke a rule.

02
In the terms your rules use

The Rules and Insurance Briefing names the rules that apply to a firm like yours in your country, such as your law society or state bar conduct rules, your CPA body’s rules of professional conduct and, for US tax preparers, the FTC Safeguards Rule, and sets each finding beside them.

03
A dated record

The Signed Assessment Record dates what was open from outside on the day. It is a record you can show when a client, an insurer or your regulator asks.

04
Evidence toward the duty

An outside check helps with your confidentiality duty. It is evidence toward it, never proof of it, because much of the duty sits inside your firm.

02 · What we read

The outside view, in plain words.

Your public surfaces
The same outside view as every assessment: mail records, look-alike domains, shared addresses in monitored breach databases, website software and sign-in pages.
The rules
Quoted from the rule text itself. Where a rule says “should”, so do we.
What it cannot see
Your files, your devices or how your staff handle client information. We log into nothing and test nothing.
03 · What we never say

Your regulator decides. You decide with the facts.

We do not tell you that your firm meets its rules, or that a finding breaks them. Your regulator and your counsel decide those. What we give you is the outside view, dated, and the steps your IT provider follows to change it.

How we are different

Next to the people you already work with.

Your IT provider

Keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We are paid by no one who sells the fixes, so every finding is independent.

A penetration test

Tries to break in and needs access. We read only what is already public, from outside, and log into nothing.

Your insurer's scan

Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.

For your firm

See what your firm shows from outside, dated, in the terms your rules use.

The External Exposure Check: your outside reading, with what we found and a check you can run yourself. No access, nothing tested.

Check my firm