Attorney-Client Privilege
Data belongs to your firm. We never share, sell, or use it beyond providing the FirmFirst service. Full data export and deletion on demand.
Trust & Security
FirmFirst is built with attorney-client privilege and data security at the core. Here's how we protect your practice.
FirmFirst mobile dashboard
Sarah Johnson
Family law consultation request
Security isn't a feature — it's the foundation everything else is built on.
Data belongs to your firm. We never share, sell, or use it beyond providing the FirmFirst service. Full data export and deletion on demand.
AES-256 encryption at rest, TLS 1.3 in transit. Application-level encryption for tokens, keys, and sensitive credentials.
Hosted on Google Cloud Platform (us-central1). SOC 2 certified infrastructure. Data never leaves the United States.
Role-based access with least-privilege principles. Multi-factor authentication required for all team members. Audit logging on every access.
24/7 automated monitoring. Defined incident response procedures. Breach notification within 72 hours per GDPR requirements.
All sub-processors sign DPAs and meet SOC 2 or equivalent standards. Vendor security reviewed annually.
GDPR and CCPA compliant. Data minimization — we collect only what's needed. No tracking beyond essential analytics.
Daily automated backups. Point-in-time recovery capability. Disaster recovery procedures tested regularly.
Third-party audit of security, availability, and confidentiality controls.
Data Processing Agreements available. Right to access, rectification, erasure, and portability supported.
California Consumer Privacy Act compliance for California-based prospects.
Signal analysis and verification workflows help attorneys meet 'reasonable inquiry' obligations.
Your firm owns all prospect data. FirmFirst stores it on your behalf to provide the service. You can export or delete it at any time.
Only with vendors required to provide core features (email validation, phone validation, enrichment). All vendors sign Data Processing Agreements (DPAs) and are GDPR/CCPA compliant. We never sell or market with your data.
All data is stored in Google Cloud Platform (GCP) in US-based data centers (us-central1). Data never leaves the United States.
Prospect data is retained as long as your FirmFirst account is active. After account cancellation, data is deleted within 30 days unless you request immediate deletion.
Yes. You can export all inquiry data as CSV or JSON at any time from your dashboard.
Contact us for our full security documentation, DPA, or compliance questions.