Security

Security at CabRank Legal

CabRank operates a referral marketplace and intake handoff platform for UK lawyers. Where enabled, it can pass structured intake information to the systems a firm already uses. Security is treated as a structural commitment, not an afterthought. This page documents how we protect data, what infrastructure we depend on, and how we respond when something goes wrong.

Last updated: 25 August 2026. Aligned to the Minimum Viable Security Product (MVSP) standard.


Where your data lives

CabRank’s UK database, file storage, authentication, and serverless functions run on a dedicated London-region (eu-west-2) Supabase instance, never shared with any other country. Referral, intake and client information for UK users is hosted in the United Kingdom by default.

The platform is fronted by Vercel for static hosting and edge routing. Connections use HTTPS only, enforced at the platform level, with TLS 1.2 or higher required. The cabrank.legal and app.cabrank.legal certificates are issued by Let’s Encrypt.


Sub-processors

Sub-processors are third-party services that may process CabRank data in the course of providing the platform. We disclose all of them. Sub-processor changes will be notified to firm administrators by email at least 14 days before taking effect, unless otherwise agreed.

Sub-processorPurposeHosting regionData handled
SupabasePrimary database, authentication, file storage, Edge FunctionsLondon, United Kingdom (eu-west-2)Referral records, intake profiles, OAuth tokens, engagement-document drafts
VercelStatic hosting, edge routing, build pipelineGlobal edge networkPublic marketing pages and signed-in app shell
StripePayment processing for consumer bookings and firm subscriptionsUnited StatesCustomer billing metadata. Card details are handled exclusively by Stripe and never reach CabRank.
AnthropicAI enquiry summarisation, redaction, and (for AI Partner subscribers) pathway intelligenceUnited StatesCall transcripts during the redaction step. Not used for AI training.
ResendTransactional email (bookings, lawyer digests, magic links)United StatesRecipient email address and message body
TwilioSMS notifications and voice-call handling (telephony and speech processing for the voice receptionist)United StatesRecipient mobile number and message body
Microsoft (Graph API)Calendar integration (Bookings mailbox)Multiple regions; tenant-determinedCalendar event metadata for consultation scheduling
ZapierWorkflow platform delivering confirmed intake information to the firm’s chosen practice-management system (Clio, LEAP, Smokeball or Actionstep), where the firm opts inUnited StatesConfirmed intake information (client name, contact details, enquiry summary) and time-limited secure links to engagement documents. The firm’s practice-management login is held by Zapier under the firm’s own authorisation and never reaches CabRank.
Google (Drive API)Bring-your-own storage (per-firm OAuth, alternative to PMS)Per-firm Google account regionFiles written to the firm’s own Drive

Encryption

  • In transit: TLS 1.2 or higher required by the edge proxy. HTTP requests are 308-redirected to HTTPS.
  • At rest: Supabase Postgres data and storage are encrypted with AES-256 (managed by Supabase).
  • Passwords: stored as bcrypt hashes by Supabase Auth. CabRank’s application code never sees raw passwords.
  • OAuth tokens: stored in Supabase, encrypted at rest, never logged, never exposed to client-side code.
  • Edge function secrets: stored in Supabase’s secrets manager and injected into Edge Functions at runtime. Never committed to source.

Access controls

  • Row-level security (RLS) is enforced at the Postgres layer for every multi-tenant table. Firms cannot read or write each other’s data even if a bug in the application code attempts it.
  • Named, least-privilege access governs staff and infrastructure accounts, with strong authentication on the hosting, code and deployment platforms. Service-role credentials are scoped to specific Edge Functions, not granted at large.
  • No shared credentials across systems. Every integration uses its own scoped credentials.
  • The firm’s own logins never reach CabRank — practice-management and storage connections authenticate with the provider directly (OAuth, or a firm-issued key the firm can revoke). CabRank never stores customer PMS passwords.

Data handling principles

CabRank stores referral and intake information for routing, claiming and handoff purposes. It does not maintain the legal file of record.

Pre-claim: CabRank temporarily holds minimal PII for referral routing — name, phone, area of law, jurisdiction, and an AI-generated summary. AI-redacted summaries are shown to claiming lawyers; commercial framing of the intake call is stripped before any lawyer sees the referral.

Post-claim: confirmed intake details are passed to the firm’s own systems — their practice management system (Clio, LEAP, Smokeball and Actionstep via Zapier), their own Google Drive, or email. CabRank retains only the minimum metadata needed for analytics, billing, and audit (referral ID, area of law, state, claim event, paid status) — no client-identifying detail.

This handoff architecture means CabRank does not maintain a parallel file once a firm claims a referral. The file of record lives in the firm’s own system. CabRank is not a practice management system, case management system or system of record for legal matters.


Data deletion

CabRank supports data deletion on request:

  • Firm-level deletion: a firm administrator can request deletion of the firm’s CabRank account and all associated tokens, profiles, and post-claim metadata. We commit to completing deletion within 30 days of a verified request.
  • Per-referral deletion: a firm can request deletion of any specific referral’s CabRank-side metadata. The firm’s own file of record in their PMS or Drive is outside CabRank’s deletion scope.
  • Client-initiated deletion: clients who interacted with the intake channels can request deletion of their personal information via the contact channel below.
  • Disconnection: when a firm disconnects a PMS or storage integration, the stored credentials for it (OAuth tokens or the firm-issued connection key) are removed from CabRank’s database immediately.

Deletion requests are made to support@platfirm.ai.


Incident response

CabRank maintains an internal incident response procedure covering detection, containment, communication, and post-incident review.

  • Notification commitment: material security incidents affecting customer data are notified to affected firm administrators within 72 hours of CabRank becoming aware.
  • Notification channel: primary firm-administrator email; for severe or platform-wide incidents, a public status update at cabrank.legal/security.
  • Post-incident: a written post-mortem is provided to affected firms covering root cause, remediation, and preventive measures.

This commitment is consistent with the notifiable-data-breach scheme under the Privacy Act 1988 (Cth).


Vulnerability disclosure

Security researchers and customer security teams are encouraged to report vulnerabilities to:

security@platfirm.ai

We commit to:

  • Acknowledging receipt within two business days.
  • Triaging the report within five business days.
  • Patching according to the SLAs below.

CabRank does not currently operate a paid bug bounty program. We will publicly acknowledge researchers who report material vulnerabilities responsibly, with their consent.


Patching SLAs

SeverityPatch SLAExamples
Critical72 hoursActive exploitation; broad customer-data exposure
High7 daysNarrow customer-data exposure; no active exploitation observed
Medium30 daysRequires authentication or specific conditions to exploit
LowNext scheduled releaseCosmetic, no customer-data exposure

UK regulatory framework

UK client and referral data is hosted in London on a dedicated database, and we design around the UK GDPR and the Data Protection Act 2018: lawful bases for each processing purpose, UK GDPR rights (access, rectification, erasure, restriction, portability, objection), and the right to complain to the Information Commissioner’s Office. The complete framework, including international transfers, is detailed in our Privacy Policy.


Compliance posture

  • Aligned with the Minimum Viable Security Product (MVSP) standard.
  • UK GDPR and the Data Protection Act 2018 applied to all personal data processed.
  • SOC 2 and ISO 27001 certifications are on the compliance roadmap; not yet in scope.

Contact

Platfirm AI Pty Ltd · ACN 679 859 744 · Level 17 & 18, International Tower 3, 300 Barangaroo Avenue, Sydney NSW 2000, Australia