Security & data handling

Trustworthy by construction.

A record is only as good as its integrity. Here are the design choices that keep Candor's record trustworthy, written plainly and without vague reassurance.

Screening stays on your device

The confidentiality pre-check runs in your browser. The text you screen is not uploaded, not logged, and not stored by Candor. We keep only that a check happened and which categories of sensitive data it found, never the content itself.

The record is yours to take

Any firm can export everything Candor holds for it, at any time, without asking. A sealed export stays encrypted and restores exactly, hash chain and all. A readable export can be opened in ten years with no Candor and no software of ours, and still carries the hashes so the chain can be checked by hand. A record you cannot get out is a record you do not really own.

Your case management stays yours

When a firm connects Clio, MyCase, or another practice system, Candor reads the matter list when it needs it and does not keep it. Your client list is never copied into our storage. Access tokens are held encrypted, your administrator grants them on the platform's own site, and your firm can revoke them from your side at any time.

Sign offs say who, provably

Where a firm signs in through its own identity provider, the person recorded on an entry is the person the session proved, not a name typed into a box. If somebody enters a sign off on a partner's behalf, the record shows that too.

We store the fact, not the file

By default Candor records actions, not their contents: a use was logged, a review happened, a check ran. Retaining any underlying content is an explicit choice a firm turns on, never a silent default.

Append only, and provably so

Logs and sign offs are never edited in place. Corrections are new entries that reference the ones before them, and the entries are hash chained: each is sealed with a fingerprint of the one prior, so any edit, deletion, or reordering is detectable. A one click integrity check rechecks the whole record.

Each firm is walled off

Every record is scoped to the firm that owns it. The design goal is that no bug could let one firm's data surface in another's account.

Encrypted in transit and at rest

Data moves over TLS and is encrypted where it's stored. Access follows least privilege: code and people get only what a task requires.

Your firm owns its record

The whole point is a portable record you control. You can export it, and it goes with you. We don't sell data, and we don't train models on your firm's content.

Honest about what we are

Candor is software, not counsel. It doesn't provide legal advice, decide whether you're compliant, or guarantee that any AI output is accurate. It gives your attorneys the record they use to make those calls.

Where we are

Candor has not launched yet, and is building with a small group of design partner firms. Before any firm's real client data is onboarded we complete a security review, and we're glad to walk a firm's IT or risk lead through the architecture in detail. Found something or have a question? Email jesse@candor.legal.

Want the technical walkthrough?