For compliance officers

What a COLP or COFA must be able to prove.

You are not asking whether the software is clever. You are asking whether you can supervise it, whether confidentiality survives it, and whether you can show the regulator the evidence.

  • A qualified fee earner signs off every output before it leaves the firm.
  • Supervision produces an artefact, a standing report of files showing drift.
  • The software refuses and names the provision on wills, client money and approvals, and some refusals name nobody who can override them.
  • The SRA's warning notice of 17 August 2026 is met concern by concern.
The breach that names its rule, a screen from the working software
The breach that names its rule
The morning list, a screen from the working software
The morning list
Every date carries its rule, a screen from the working software
Every date carries its rule

Illustrative. Three screens from the working software, on invented files. The platform, screen by screen.

What the regulator will ask

The SRA's warning notice on AI

The notice of 17 August 2026 names two risks it will pursue, invented authorities and client information placed into open tools. It says the solicitor remains accountable and requires governance, systems and controls.

Answered in full: Supervision, the warning notice.

Supervising what it does

Drafts arrive as drafts and time entries wait for acceptance, so nothing is sent, filed or posted without a qualified fee earner approving it. The audit trail records what was proposed, who approved it and when.

The drift report and escalation log

The files showing drift reach a supervising partner as a standing report, and every escalation a junior triggers is logged.

Answered in full: The platform.

Where client data sits

Every production record is held in the United Kingdom, one firm's records are separated from another's in the database, and nobody at Bracton Ltd holds standing access. The host for a paying firm is not yet chosen.

Answered in full: Security and hosting.

Whether it trains on your files

No content from your matters trains, tunes or evaluates any model, at Bracton Ltd or at the provider behind it. That provider is a sub processor processing in the United Kingdom or the European Union, under a data processing agreement you can read.

Retention, and what the log shows

Retention is zero or a short disclosed period, and the audit log shows what was sent and on whose action.

Answered in full: Questions before signing.

What it refuses to do

Four refusals come from the running software: the will emailed out for signature, the transfer where no bill has been delivered, the receipt banked to the office account, the payment approved by the person who raised it. Each names the provision, the remedy and the decision holder.

Why one refusal names nobody

The first names nobody who can override it, because a rule is not a permission.

Answered in full: Where it says no.

The controls day to day

Cyber Essentials is held in Bracton Ltd's own name, the whole organisation in scope. Insurance, escrow and a service level are open.

What the controls page shows

The money actions, the log, the backups and the incident route sit behind the security page.

Answered in full: The controls.

The policies you can read

Seven policies are published and downloadable: data protection, information security, artificial intelligence, business continuity, accessibility, the environment and modern slavery, alongside the privacy and cookie notices.

Answered in full: Policies.

What exists today, working now, in build, committed before signature or not yet decided, is on the product status page.

Contact

Put the awkward question

Every question you put has an answer, and where ours is unattractive it is on the security page.

Put a security question to us