FirmShield
Privacy Policy
1. Who we are
FirmShield provides cybersecurity readiness verification for small law firms. This policy describes how we collect, use, and protect information when you use our service.
2. Information we collect
- Account information — name, email address, firm name, and role.
- Microsoft 365 configuration data — security settings, user account metadata, directory roles, mailbox forwarding settings, and sharing configuration, accessed via read-only Microsoft Graph API permissions after admin consent.
- Evidence and attestations — files, policy documents, and manual security attestations you upload.
- Audit logs — actions taken within FirmShield for security and compliance purposes.
- Billing — payment details are processed by Stripe; we store Stripe customer and subscription identifiers.
3. Information we do not collect
- Email message content
- Client matter files or document contents
- Microsoft 365 passwords or user credentials
4. How we use information
We use collected information solely to:
- Verify security control configuration in your Microsoft 365 tenant
- Generate security reports and evidence for your firm
- Support cyber-insurance readiness and client questionnaire workflows
- Maintain audit trails of platform activity
5. Data storage and security
Data is stored in Azure data centers in the United States with encryption in transit (TLS 1.2+) and at rest. Each law firm's data is isolated by tenant. Secrets are stored in Azure Key Vault in production.
6. Data retention
Active account data is retained for the subscription period. Upon account termination, data is deleted within 90 days unless longer retention is required by law.
7. Your rights
You may request access to, correction of, or deletion of your data by contacting us. You may disconnect your Microsoft 365 tenant at any time from the Connection page in FirmShield.
Privacy inquiries: privacy@lawfirmshield.com
