Trustworthy by construction.
A record is only as good as its integrity. Here are the design choices that keep Candor's record trustworthy, written plainly and without vague reassurance.
Screening stays on your device
The confidentiality pre-check runs in your browser. The text you screen is not uploaded, not logged, and not stored by Candor. We keep only that a check happened and which categories of sensitive data it found, never the content itself.
The record is yours to take
Any firm can export everything Candor holds for it, at any time, without asking. A sealed export stays encrypted and restores exactly, hash chain and all. A readable export can be opened in ten years with no Candor and no software of ours, and still carries the hashes so the chain can be checked by hand. A record you cannot get out is a record you do not really own.
Your case management stays yours
When a firm connects Clio, MyCase, or another practice system, Candor reads the matter list when it needs it and does not keep it. Your client list is never copied into our storage. Access tokens are held encrypted, your administrator grants them on the platform's own site, and your firm can revoke them from your side at any time.
Sign offs say who, provably
Where a firm signs in through its own identity provider, the person recorded on an entry is the person the session proved, not a name typed into a box. If somebody enters a sign off on a partner's behalf, the record shows that too.
We store the fact, not the file
By default Candor records actions, not their contents: a use was logged, a review happened, a check ran. Retaining any underlying content is an explicit choice a firm turns on, never a silent default.
Append only, and provably so
Logs and sign offs are never edited in place. Corrections are new entries that reference the ones before them, and the entries are hash chained: each is sealed with a fingerprint of the one prior, so any edit, deletion, or reordering is detectable. A one click integrity check rechecks the whole record.
Each firm is walled off
Every record is scoped to the firm that owns it. The design goal is that no bug could let one firm's data surface in another's account.
Encrypted in transit and at rest
Data moves over TLS and is encrypted where it's stored. Access follows least privilege: code and people get only what a task requires.
Your firm owns its record
The whole point is a portable record you control. You can export it, and it goes with you. We don't sell data, and we don't train models on your firm's content.
Honest about what we are
Candor is software, not counsel. It doesn't provide legal advice, decide whether you're compliant, or guarantee that any AI output is accurate. It gives your attorneys the record they use to make those calls.
Where we are
Candor has not launched yet, and is building with a small group of design partner firms. Before any firm's real client data is onboarded we complete a security review, and we're glad to walk a firm's IT or risk lead through the architecture in detail. Found something or have a question? Email jesse@candor.legal.