TRUST CENTER
Security designed for legal work
MYCALP uses layered access, storage, transport, session, provider, and audit controls without claiming certifications it has not earned.
Server-held provider secrets
Vercel provider keys and webhook secrets are read only on the server and are not included in public health or feature responses. The WordPress encrypted BYO-key vault is not claimed as migrated until an equivalent Vercel owner exists.
Matter and workspace access
Authenticated matter reads and writes require workspace membership, feature permission, operation permission, and the applicable owner or creator scope. Client matter access fails closed until a client-assignment relation exists.
Casper tenant binding
Casper requests use signed identity headers bound to the requesting user, tenant, and optional matter. Missing provider or signing configuration stops the request.
Private document storage
Generated and migrated documents use private S3 storage references. Authenticated downloads use short-lived signed access, while recipient document routes require the scoped recipient token.
Scoped recipient links
Signature and service links validate token shape, expiry, recipient state, and envelope state. Completed actions retain consent and audit evidence.
Webhook authentication
Stripe callbacks require the provider signature and the verified MYCALP Stripe account before subscription state is changed.
Authentication and invitations
Auth.js uses database sessions and single-use email verification links. Firm invitations store a token hash, expire after seven days, and bind acceptance to the invited email.
BYO-AI disclosure boundary
The WordPress template described encrypted user-provided AI keys. The Vercel public site does not claim that control until the account connection owner is migrated and verified.
Status, export, and recovery
The public health route returns minimal service state. Matter events and private file metadata support audit and recovery workflows without exposing internal storage paths.
What is not claimed
MYCALP does not claim SOC 2, HIPAA, FedRAMP, PCI certification, or another external certification unless an independently completed assessment is expressly published.