Security and hosting
How the controls work on an ordinary day.
This page carries the working, from the moment money moves to what an incident looks like from your side, and what is still undecided.
- Five actions ask for the second factor again at the moment they are approved rather than at the start of the session.
- The log records who looked, not only who changed something, and your administrator can search and export it without asking us.
- Backups cannot be deleted by anyone, including an administrator of the hosting account and including Bracton Ltd, until their period expires.
- What is undecided is named rather than answered plausibly, and each item will be settled before any firm is asked to sign.



Illustrative. Three screens from the working software, on invented files. The platform, screen by screen.
The working, control by control
Each can be tested during due diligence, and where a control cannot be tested from outside, the entry says how to get assurance instead.
Proof again when money moves
Five actions ask for the second factor again at the moment of approval.
The five actions that ask again
Approval of a payment out of the client or office account, a change to bank details already held for a client, a payee or a supplier, a transfer between the client and office accounts, the release of a bill, and the service or disclosure of a document.
What the approver sees
Bracton treats a change to an account number already on file as a money action.
The amount, the payee, the account number and the matter appear at the point of approval, approving one payment never approves the next, and every approval is written to the audit log against the action it authorised.
The log records who looked
An information barrier is breached the moment somebody on the wrong side opens a document, with nothing about the file changing to show it.
What each entry carries
The person, the act, the firm, the file or ledger record it touched, the moment, and beside those the sitting it was done in, the device the firm vouched for, the network address, the browser, and whether the act was done or refused.
Refusals, and the store beneath
Refusals are kept as carefully as successes, and the monitor reads them for one person meeting many in a day.
The log is append only, written to a store the application can add to and cannot alter or delete, and your own administrator can search and export it without asking us.
Which of the two products your firm needs is a separate question.
Find out which one fits, two minutesBackups a stolen password cannot delete
Backups are immutable for a defined period, so once written nobody can alter or delete them before it expires, including an administrator of the hosting account and including Bracton Ltd.
Where the copies are held
Copies are held in a separate United Kingdom facility and do not leave the country.
How restores are tested
Restores run on a schedule into a clean environment, with the time taken and the result recorded and signed by a named person. The first firm to sign can ask for the test record from the outset.
The tests include restoring a single firm rather than only the whole platform.
If something goes wrong
On confirming an incident we establish what happened, which firms are affected and what categories of data are in scope, and contain it before investigating the cause. Affected firms are told within twenty four hours of Bracton Ltd becoming aware.
Your firm has seventy two hours from becoming aware to notify the Information Commissioner where the breach is likely to risk people's rights.
What the notification tells you
What happened, when it started and when it was detected, which of your matters and clients are affected, what has been done, what remains at risk and what to do next, with a named contact and an interval for updates.
We then supply extracts from the audit log, the list of affected records and a timeline you can attach to your own report.
Who reports, and to whom
You report to the Information Commissioner and decide whether to tell the people affected, because that obligation belongs to the controller.
Your compliance officer for legal practice has a separate duty to report serious breaches to the Solicitors Regulation Authority, on a different test and a different timescale, and we supply the same evidence pack without offering a view on whether the threshold is met.
What is not settled yet
The hosting provider and the specific United Kingdom regions, for production and for the separated backup copy. The model provider. Whether a firm can supply and hold its own key material, so that we cannot decrypt your data without your participation.
The contractual recovery point and recovery time objectives, and the default retention period for the audit log with the range a firm can set.
Two further points are commitments rather than settled facts. Telling an affected firm within twenty four hours of our becoming aware is a service level we intend to give and have not yet contracted.
Telling a firm when privileged access has reached its data carries an operational cost.
If your firm needs something on this page settled before it will buy, say so at the review stage, because a requirement raised early can be written into the agreement.
Encryption, and who holds the keys
Everything is encrypted in transit and at rest.
Traffic is encrypted in transit with current transport security, older versions refused. Every backup is sealed under AES-256 with a key the platform holds and the hosting company does not, and one is restored weekly to test it. Encryption of the running database at rest is the hosting company's.
The honest position on keys
Two keys exist today, one sealing the backups and one guarding the mail tokens in each firm's custody, both read from the server's environment rather than a managed key service. There is no key for each firm and no rotation.
So the strongest sentence about deletion is that a firm's database is dropped and its backups expire, evidenced on the trail. A key for each firm, in a managed service and rotated, goes in with the production host.
Certification, stated plainly
Bracton Ltd holds a Cyber Essentials certificate in its own name, whole organisation in scope, verifiable on the register.
Verify this certificate on the IASME register
Awarded by IASME on 5 August 2026 against version 3.3 of the scheme, recertification due 5 August 2027, number ef2524f2-b1ad-4d5f-bfb2-0702fa956a88. It evidences that a defined set of controls exists and has been examined by somebody independent, and the trust statement says what is not held.
The cyber cover attached
Certification carries the cyber cover IASME attaches to it, underwritten by American International Group UK Limited and running to 5 August 2027, insuring Bracton Ltd under its own certificate, confirmed in writing by the certification body on 10 September 2026, limit twenty five thousand pounds in the aggregate including defence costs.
It is not the technology errors and omissions and cyber cover the software agreement requires before your firm signs. That cover is described in the business continuity policy and is not yet bound.
Independent testing, and no dates
Penetration testing is required, by an external party before the first firm goes live and at least annually after, with the separation between firms and the sign in route in scope. The summary letter is available during due diligence.
Cyber Essentials Plus comes first and ISO 27001 follows an operating history, and no target date appears because none is committed.
Due diligence
Give this page to your COLP
It is written for the person who signs the supplier assessment. Where it falls short, raise the gap before signature.
Contact
Send us your due diligence questionnaire
Send your supplier assessment form and it comes back completed, with blanks left where we do not hold something.
Put a security question to us