Security at Esqase.

Law firms hold some of their clients' most sensitive information. Esqase is built to protect it: encrypted in transit, with sensitive data encrypted at rest, guarded by role-based access, and recorded in a full audit trail.

Contact sales

The security program behind every matter

The Esqase security program is aligned to SOC 2 and ISO 27001 and continuously monitored with Vanta, with evidence collected automatically as the platform runs. Data processing is backed by a Data Processing Agreement. Esqase runs on Google Cloud, and access rules are enforced by the database itself: row level security on every table, and the application connecting as a role that cannot bypass it. Signed-in dashboard sessions end after an hour of inactivity, and after twelve hours regardless.

Encryption

Data is encrypted in transit, and sensitive data is encrypted at rest, matching the commitments in our DPA.

Access control

Each role sets view, create, update, and delete permissions per area, enforced by the database, not the interface.

Two-factor authentication

Anyone can turn on 2FA for their own account, and a firm owner can require it for every member.

Audit trail

Every record keeps a timeline of who created, changed, or removed something and when, with no setup required.

Client access by secure link

Clients book, fill forms, pay, and sign through links in their browser, with no portal password to manage.

Built for legal practice

Operating and trust accounts stay separate, and eSignatures are designed to meet ESIGN and UETA requirements.

Read the agreements.

All legal documents

Questions about security?