ProbateRisk

Security

How we treat what firms and families give us

Estate planning information is among the most sensitive a family ever writes down, names, birthdates, children, assets, wishes. We treat it the way a law office is supposed to treat it, and this page explains what that means in practice.

How data moves

Information travels encrypted in transit from the client's device to our systems, and from our systems into the practice management tools the firm already runs. Interview sessions are protected by one time sign in codes sent to the client's email, and we never store passwords.

Where data lives

Data is stored with established United States cloud providers, Netlify for hosting and Supabase for the database, with email delivered through Resend and Google Workspace and scheduling through Calendly. Each operates under agreements limiting its use of information to providing services to us.

What we refuse to do

No advertising trackers. No cross site tracking. No selling personal information, ever. The only parties who see a client's information are the systems that operate the platform and the law firm the client is working with.

Access and secrets

Access to production systems is limited to what operating the platform requires, and credentials and keys live in managed environment configuration, never in code or documents.

Ownership and deletion

A firm's client data belongs to the firm and its clients, not to us. Firms and clients may request access, correction, or deletion at any time through info@probaterisk.com, and our Privacy Policy describes those rights in full.

Reporting a concern

If you believe you have found a security issue, tell us at info@probaterisk.com and we will respond promptly. We are grateful for responsible disclosure.

As we grow

Security posture is a practice, not a plaque. As the platform scales, our controls and formal attestations scale with it, and firms evaluating us are welcome to ask exactly where that stands.