Security and hosting
What a compliance officer is entitled to test.
A firm cannot delegate its duty over client information. Read this as the specification the platform is built to and the position contracted before signature, with unsettled matters named.
- Every production record is held in the United Kingdom, backups and audit trail included. The demonstration runs in London, and the host for a paying firm is chosen against this requirement before signature.
- One firm's records are kept from another's in the database itself. Built today.
- Nothing your firm holds in Bracton trains any model, at Bracton Ltd or at the provider behind the assistant, reached in the London region.
- Bracton Ltd holds a Cyber Essentials certificate in its own name, number ef2524f2, issued by IASME on 5 August 2026. The trust statement says what is certified and what is not.



Illustrative. Three screens from the working software, on invented files. The platform, screen by screen.
How to read this page
Bracton holds live matter files, privileged correspondence, anti money laundering evidence and the ledgers your firm keeps under the SRA Accounts Rules.
The working sits on the page behind this one.
Where your data is held
i.
Your firm is the controller
Bracton Ltd acts on your documented instructions and for no other purpose.
How it works
Your firm decides why client personal data is processed and answers to the Solicitors Regulation Authority for it.
What the processor cannot do
We do not use your matter content for our own development, and we disclose it only where you instruct us or the law compels us, in which case we tell you unless that is unlawful.
The agreement carries the processor terms UK GDPR requires, sub processors are named on a list you see, and you get notice before an addition and a route to object.
ii.
Records stay in the United Kingdom
The database, the backups and the audit trail are all held in the United Kingdom.
How it works
That covers the papers and their files, any queue or cache carrying matter content, and support and engineering, which are United Kingdom based. Any exception is recorded and disclosed.
Where residency goes wrong
Error tracking, monitoring, log aggregation, support tooling and analytics are each configured to a United Kingdom region, excluded outright, or set to strip content first.
iii.
Each firm has its own database
A query that forgets to filter by firm returns nothing rather than returning everything.
How it works
Each firm has a database of its own rather than a share of one, and a query that forgets which firm it asks about reaches the control database and fails loudly. No table carries a column naming the firm.
Where a paper's files are held
A paper's files sit in that firm's database beside the record they belong to, so custody, the hourly backup and destruction at the end of retention travel together. Every file is served through one door that records the reading and refuses a person the file's information barrier excludes, capped at one hundred megabytes.
One separation not yet built
An address of its own for each firm, rather than a shared one, keeps sessions and cookies inside one firm and pairs with passkeys. bracton.app is held for it and the wildcard certificate goes in with the production host. Today there is one address.
Who can reach it
i.
The registered device and the passkey
A registered device gets the whole application, and an unregistered one gets a session that caches nothing and refuses downloads.
How it works
What an unregistered device does
It is unknown whoever is sitting at it, and the session times out after a short inactivity.
Your firm registers and revokes devices itself, revoking one ends every live session on it, and removing a person ends their sessions and registrations at once.
The two factors, and their limit
A passkey is minted inside the person’s own device and bound to the address it was created for. The device also proves the person holding it, by face, fingerprint or PIN, insisted on at registration, at sign in, and when the device’s answer is verified.
No authenticator application is offered. Where your firm signs in through its own Microsoft directory, the factors are your tenant’s policy. Suppressed printing does not stop a person photographing a screen.
ii.
What Bracton Ltd can see
Nobody at Bracton Ltd holds standing access to the production database, and the permission model governs the application rather than the database beneath it.
How it works
Engineers work against the application and against invented data, and reading live client material is not part of anyone's ordinary permissions.
Access granted for a fault
Where a fault requires it, access is requested in writing against that fault, approved by somebody other than the person asking, limited to a window that expires by itself, and recorded statement by statement. The firm's administrator is told where it reaches identifiable data.
What stands below the application
Anyone with access to the underlying database reads everything regardless of what the permission model says.
That approval process, the logging of every use of it, the confidentiality obligations of those who can ask, and a contract making unauthorised access a breach you can enforce stand there instead.
What happens next
i.
The model behind the assistant
No content from your matters is used to train, tune or evaluate any model, and the model provider is named.
How it works
Where the product sends matter content to a language model, that provider is a sub processor of Bracton Ltd. What was sent, for which matter and on whose action is in the audit log you read.
Where the processing happens
In the United Kingdom or the European Union, with the regions named to you, and a firm whose own clients demand it can require United Kingdom only processing.
Retention at the provider is zero or bounded to a short period for abuse monitoring, and the length is disclosed. The data processing agreement with the provider is one you read during due diligence.
No matter content reaches a provider that has not been through this, including the evaluation of a new model during development.
ii.
If your firm leaves
Your data is exportable in a documented format at any time and for ninety days after the agreement ends, at no charge.
How it works
Your matters, documents, correspondence and ledgers belong to your firm. At the end of the contract the data is returned or deleted on your election, evidenced either way.
The money actions, the log, the backups and what happens during an incident are set out behind this page.
Contact
Agree the requirement before signature
If something here falls short, say which part before signature.
Put a security question to us