Hardened multi-factor authentication
MFA is enforced for authenticated users in production. TOTP codes cannot be replayed, secrets support controlled key rotation and recovery codes are securely hashed.
Formata is designed to protect confidential legal deadline information through layered account, application and data controls—while collecting less case data in the first place.
MFA is enforced for authenticated users in production. TOTP codes cannot be replayed, secrets support controlled key rotation and recovery codes are securely hashed.
Matters, deadlines and integrations are restricted to the selected firm. Users belonging to multiple firms must explicitly choose their active firm context.
Owner, administrator, lawyer and assistant capabilities are separated. Firm owners do not receive system-wide platform administration.
Revoked invitations cannot be reused. Password and account changes invalidate unfinished authentication, while users can review and revoke their sessions after reauthentication.
Connected-account tokens are encrypted before storage. Provider requests use approved HTTPS destinations, bounded responses and sanitized errors.
Security-sensitive actions and deadline decisions retain data-minimized snapshots. Application controls prevent ordinary alteration or deletion of those audit records.
CSRF validation, secure production cookies, private-page no-store rules, clickjacking protection and nonce-based content security policy reduce common web risks.
APIs reject unexpected fields, malformed dates, invalid types and oversized payloads before records are changed.
Dependencies are locked with cryptographic hashes and audited for known vulnerabilities in automated GitHub security workflows.
Formata's intended boundary is the minimum information needed to identify, calculate, assign, remind and audit a deadline.
Deadline creation, changes, exclusions, overrides, reassignment and completion remain reviewable. Unsupported jurisdiction rules are blocked rather than guessed.
Staff activation links are single-use and time-limited. Revocation stops access, and open deadlines can be transferred to a replacement lawyer and assistants before departure.
Calculated deadlines require a server-signed calculation snapshot and approval by an active lawyer or owner before activation.
Filevine imports are strictly inbound-only, cross-firm inconsistencies stop synchronization, and each completed import is recorded.
Formata intends to engage qualified independent assessors. Scope, evidence and timing will be confirmed with those assessors before any certification claim is published.
Prepare the control environment and evidence for an independent SOC 2 examination, beginning with Security and adding relevant availability, confidentiality, processing-integrity or privacy criteria based on customer needs.
Build and operate an information security management system with defined scope, risk assessment, treatment plan, policies, control ownership, internal audit and management review before the accredited certification audit.
Evaluate CSA STAR for cloud-security transparency and complete Canadian privacy, vendor-risk and penetration-testing reviews. These support assurance but do not replace legal privacy obligations.
Code controls are one part of a secure launch. These items must be configured and tested before confidential production use.
Configure the notification mailbox and test invitations, reminders, bounce handling and sender authentication.
Connect the pilot firm's Filevine account with least-privilege access and validate one-way mapping using test matters first.
Run a database restore test, enable error alerting, document incident contacts and confirm credential rotation.
Every enabled rule and source requires jurisdiction-appropriate legal review. Formata remains a workflow aid, not legal advice.
Test authentication, permissions, matter entry, calculation review, reminders and audit history with approved scenarios.
Document hosting, database and email providers, retention expectations and access responsibilities.
We can walk your pilot team through the data boundary, account controls and launch checklist.
Request a security conversation