JuriOS Security
Security & Compliance

Your clients' data is held to the
same standard as their trust funds.

JuriOS handles confidential client information and trust account data — two of the most sensitive categories of data a Canadian law firm manages. This page explains exactly how we protect them.

Canada only
All data stored and processed in Canadian data centres. No US routing.
SOC 2 Type II
Independently audited annually. Report available on request.
AES-256
Encryption at rest for all data. TLS 1.3 in transit.
PIPEDA
Compliant with Canada's federal privacy legislation. Audited annually.
Data residency

Canadian servers only.
No exceptions.

This is the most important security question for Canadian law firms. Your client data — names, matters, communications, financial records — is subject to Canadian privacy law. If it passes through US infrastructure, it can be subject to US law, including the CLOUD Act, which allows US government access to data held by US companies regardless of where the data is physically stored.

JuriOS is architected to prevent this. Every component — application servers, databases, backups, email delivery, file storage — runs on Canadian infrastructure. We do not use US-based cloud providers. Our primary provider is a Canadian data centre operator with facilities in Toronto and Montreal. No data processing occurs outside Canada.

This matters for your Law Society compliance. Law Societies across Canada have issued guidance that client data stored outside Canada may require client consent and may create professional obligations. JuriOS eliminates this concern entirely.

JuriOS infrastructure — Canada
Toronto, Ontario
Primary data centre · all active data
Primary
Montreal, Quebec
Secondary · disaster recovery · encrypted backups
DR / Backup
United States
No data ever processed here
Blocked
Network-level controls enforce Canadian routing. Egress to non-Canadian endpoints is blocked by default at the infrastructure layer — not just by policy.
Encryption

Technical controls.
Specific, not vague.

We know lawyers are trained to read fine print. Here are the actual technical controls, not marketing language.

TLS 1.3 in transit

All data in transit — between your browser and JuriOS servers — is encrypted using TLS 1.3, the current industry standard. TLS 1.0 and 1.1 are disabled.

TLS 1.3 · HSTS enforced
AES-256 at rest

All data stored on JuriOS servers — databases, file storage, backups — is encrypted at rest using AES-256-GCM. This is the same standard used by Canadian financial institutions.

AES-256-GCM · key rotation quarterly
Trust data — separate encryption

Trust account data — balances, transaction history, client ledgers — is encrypted with a separate key set from general practice data. A breach of one does not expose the other.

Separate key hierarchy · HSM protected
Database-level encryption

Beyond filesystem encryption, JuriOS applies field-level encryption to sensitive database columns — client identifiers, trust balances, and financial figures are encrypted within the database itself.

Field-level · column encryption
Zero-knowledge backups

Backups are encrypted before leaving the primary data centre. The backup provider cannot decrypt your data — only JuriOS's key management service can. Backups run every 4 hours.

4-hour RPO · 7-year retention
API key security

API keys are hashed using PBKDF2 before storage — the raw key is never stored. Keys are rotated automatically on a quarterly schedule. Each key has the minimum permissions required for its function.

PBKDF2 hashed · quarterly rotation
Access controls

Who can access
your data. Exactly.

This is the question most lawyers ask first. The answer is specific.

Your team — roles you define

Every JuriOS user has a role: admin, lawyer, paralegal, or read-only. Admins control what each role can see and do. You define the access model for your firm.

JuriOS support — only when you invite us

Our support team cannot access your account without an explicit invitation from your admin. When support access is granted, it is time-limited (48 hours maximum) and logged in your audit trail.

JuriOS staff — no access by default

No JuriOS employee — including engineering and operations — can access your practice data without an explicit support invitation. This is enforced technically, not just by policy.

Third parties — never

We do not share your data with advertisers, data brokers, analytics companies, or any third party. Our sub-processors (payment processing, email delivery) receive only the minimum data required for their specific function.

MFA & Authentication
MFA required for all user accounts — no exceptions
Supports TOTP authenticator apps and hardware keys
Single Sign-On (SSO) via SAML 2.0 on Growth plan
Session timeout configurable per-firm (default: 8h)
IP allowlisting available on Growth plan
Audit trail

Every action in JuriOS is logged: who, what, when, and from which IP address. The audit log is immutable — even admins cannot delete entries. Trust account transactions have an enhanced audit trail that meets Law Society requirements.

SOC 2 Type II

Independently audited.
Annually.

SOC 2 Type II certification means an independent auditor spent six months reviewing our security controls in practice — not just in documentation — and concluded that our controls are designed and operating effectively.

Our SOC 2 audit covers five trust service criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The annual audit is conducted by an independent Canadian CPA firm. We share the executive summary with any firm that requests it.

SOC 2 Type II Executive Summary
Available on request · security@jurios.io
PIPEDA Compliance

Canada's privacy law.
Met, not just acknowledged.

PIPEDA — Canada's Personal Information Protection and Electronic Documents Act — governs how we handle personal information. Our compliance is audited annually.

Key PIPEDA obligations we meet: explicit consent for data collection, data minimization (we collect only what we need), the right to access and correct personal information, the right to have data deleted, and breach notification within 72 hours of discovery.

For Quebec-based firms: JuriOS also complies with Law 25 (Quebec's updated privacy legislation), which has more stringent requirements than PIPEDA on several points.

Incident response

If something goes wrong.
Specific obligations.

We hope this section is never relevant. If it is, here is exactly what happens:

0–1h
Incident detected and contained. Affected systems isolated.
4h
Affected firm admins notified directly by email and phone.
24h
Full incident report delivered. Root cause, scope, and remediation steps.
72h
Mandatory PIPEDA notification filed if personal information was exposed. We file on your behalf and provide supporting documentation for any Law Society notification you may need to make.
Penetration testing

External eyes.
Every year.

Annual third-party penetration tests are conducted by an independent Canadian security firm. Scope covers web application, API, infrastructure, and social engineering vectors.

Test results inform our security roadmap for the following year. Critical and high findings are remediated within 14 days of report delivery. We share our remediation summary with firms that request it.

We also operate a responsible disclosure program. If you discover a security issue in JuriOS, email security@jurios.io. We will acknowledge within 24 hours, investigate, and keep you informed of our remediation. We do not pursue legal action against good-faith security researchers.

Responsible disclosure
security@jurios.io · PGP key available on request
Security FAQ

Questions lawyers ask
about their data's safety.

Can JuriOS staff read my client files or trust account records?
No. Access to your firm's data by JuriOS staff is technically blocked by default. The only exception is when your admin explicitly invites support access — which is time-limited to 48 hours, logged in your audit trail, and revocable at any time. No JuriOS employee — including our CEO — can access your data without this invitation process.
What happens to my data if JuriOS is acquired?
Our terms of service include change-of-control provisions that protect your data. In the event of an acquisition: you receive 90 days notice, you can export all your data during that period at no cost, and the acquirer is bound by our existing privacy commitments for the duration of your contract. We cannot be acquired by a non-Canadian entity without triggering these protections. This is written into our investor agreements.
How long is my data retained after I cancel?
Your data remains accessible and exportable for 90 days after cancellation. After 90 days, all data is permanently deleted from our systems — including backups — on a rolling schedule. Trust account data is retained for 7 years as required by Law Society regulations, even after cancellation, unless you provide written instruction to delete earlier. You can download a complete export of your data at any time during the 90-day window.
Do you share data with any third parties?
No, with two narrow exceptions: payment processing (we use a Canadian-regulated payment processor; they receive transaction amounts and payment method tokens only, never client data) and transactional email delivery (our email provider receives recipient addresses for invoice delivery only). We do not share data with advertisers, analytics companies, data brokers, or any other party. A complete list of sub-processors is available at privacy@jurios.io.
What if I'm audited by my Law Society?
JuriOS produces Law Society-ready reports on demand. Your trust reconciliation report, client ledger summaries, and transaction history are all exportable in the format your Law Society expects. We have worked with firms undergoing LSO, LSBC, and LSA audits and have not had a firm cited for a software-related compliance issue. If you are facing an audit, contact support@jurios.io immediately — we will prioritize your export and can provide a letter confirming the integrity and Canadian residency of your data.

Questions about security?

Our security team answers directly. No sales process, no runaround.