Security and trust

Specific controls. Honest limits.

EvidenceCanvas does not ask you to trust a vague “secure” claim. Procurement evidence must be tied to the deployed release and final public UAT.

Launch status: the production backend has passed private AWS checks, but the public identity route and final public multi-role UAT remain go-live gates. Real client data must not be admitted before those gates close.
01

Matter grants

Every request is checked against the signed-in user and active matter grant. Changing an identifier must not expose another matter.

02

Workspace separation

Each matter and each portal user/matter execution context has a separate workspace inside the practitioner partition.

03

Draft boundary

Internal drafts are invisible to litigants and McKenzie users until the assigned release owner releases an item to a named user.

04

Audited assistance

A support user acting for an assigned person records both identities. Support access is granted and revocable; it is not impersonation.

05

Upload controls

Production design includes file limits, hashing, allowlisting, rate limits and fail-closed malware scanning before material enters the evidence store.

06

Backup and recovery

The production design creates client-side encrypted backup objects. Independent recovery-key custody and release-specific restore evidence are still go-live gates.

What the founding pilot must prove

  • Allowed and disallowed Cloudflare identities
  • Password and passkey journeys
  • Exact cross-matter page and file denial
  • Upload scanning and file opening
  • Internal draft and named release
  • Grant revocation during an active session
  • Backup verification and separate restore
  • No unintended model API or fallback route

Architecture limits

  • The low-cost MVP uses one dedicated host per practitioner, not one host for unrelated firms.
  • The portal is not a raw mirror of private operator conversations.
  • No system can promise absolute security or uninterrupted availability.
  • A secure portal does not create legal professional privilege.
  • Users must still protect devices, passwords and downloaded files.

Due-diligence material

Suitable practitioner prospects may request the release-specific architecture summary, role matrix, processor/transfer summary, retention information, incident route and current UAT evidence. Documents are shared only after claims are checked against the deployed configuration.