JuriOS handles confidential client information and trust account data — two of the most sensitive categories of data a Canadian law firm manages. This page explains exactly how we protect them.
This is the most important security question for Canadian law firms. Your client data — names, matters, communications, financial records — is subject to Canadian privacy law. If it passes through US infrastructure, it can be subject to US law, including the CLOUD Act, which allows US government access to data held by US companies regardless of where the data is physically stored.
JuriOS is architected to prevent this. Every component — application servers, databases, backups, email delivery, file storage — runs on Canadian infrastructure. We do not use US-based cloud providers. Our primary provider is a Canadian data centre operator with facilities in Toronto and Montreal. No data processing occurs outside Canada.
This matters for your Law Society compliance. Law Societies across Canada have issued guidance that client data stored outside Canada may require client consent and may create professional obligations. JuriOS eliminates this concern entirely.
We know lawyers are trained to read fine print. Here are the actual technical controls, not marketing language.
All data in transit — between your browser and JuriOS servers — is encrypted using TLS 1.3, the current industry standard. TLS 1.0 and 1.1 are disabled.
TLS 1.3 · HSTS enforcedAll data stored on JuriOS servers — databases, file storage, backups — is encrypted at rest using AES-256-GCM. This is the same standard used by Canadian financial institutions.
AES-256-GCM · key rotation quarterlyTrust account data — balances, transaction history, client ledgers — is encrypted with a separate key set from general practice data. A breach of one does not expose the other.
Separate key hierarchy · HSM protectedBeyond filesystem encryption, JuriOS applies field-level encryption to sensitive database columns — client identifiers, trust balances, and financial figures are encrypted within the database itself.
Field-level · column encryptionBackups are encrypted before leaving the primary data centre. The backup provider cannot decrypt your data — only JuriOS's key management service can. Backups run every 4 hours.
4-hour RPO · 7-year retentionAPI keys are hashed using PBKDF2 before storage — the raw key is never stored. Keys are rotated automatically on a quarterly schedule. Each key has the minimum permissions required for its function.
PBKDF2 hashed · quarterly rotationThis is the question most lawyers ask first. The answer is specific.
Every JuriOS user has a role: admin, lawyer, paralegal, or read-only. Admins control what each role can see and do. You define the access model for your firm.
Our support team cannot access your account without an explicit invitation from your admin. When support access is granted, it is time-limited (48 hours maximum) and logged in your audit trail.
No JuriOS employee — including engineering and operations — can access your practice data without an explicit support invitation. This is enforced technically, not just by policy.
We do not share your data with advertisers, data brokers, analytics companies, or any third party. Our sub-processors (payment processing, email delivery) receive only the minimum data required for their specific function.
Every action in JuriOS is logged: who, what, when, and from which IP address. The audit log is immutable — even admins cannot delete entries. Trust account transactions have an enhanced audit trail that meets Law Society requirements.
SOC 2 Type II certification means an independent auditor spent six months reviewing our security controls in practice — not just in documentation — and concluded that our controls are designed and operating effectively.
Our SOC 2 audit covers five trust service criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The annual audit is conducted by an independent Canadian CPA firm. We share the executive summary with any firm that requests it.
PIPEDA — Canada's Personal Information Protection and Electronic Documents Act — governs how we handle personal information. Our compliance is audited annually.
Key PIPEDA obligations we meet: explicit consent for data collection, data minimization (we collect only what we need), the right to access and correct personal information, the right to have data deleted, and breach notification within 72 hours of discovery.
For Quebec-based firms: JuriOS also complies with Law 25 (Quebec's updated privacy legislation), which has more stringent requirements than PIPEDA on several points.
We hope this section is never relevant. If it is, here is exactly what happens:
Annual third-party penetration tests are conducted by an independent Canadian security firm. Scope covers web application, API, infrastructure, and social engineering vectors.
Test results inform our security roadmap for the following year. Critical and high findings are remediated within 14 days of report delivery. We share our remediation summary with firms that request it.
We also operate a responsible disclosure program. If you discover a security issue in JuriOS, email security@jurios.io. We will acknowledge within 24 hours, investigate, and keep you informed of our remediation. We do not pursue legal action against good-faith security researchers.
Our security team answers directly. No sales process, no runaround.
security@jurios.io