Appearance
Security & Data Protection Overview β
As a legal practice, your law firm handles some of the most sensitive information in society: privileged communications, corporate trade secrets, litigation strategies, client identification records, and financial transactions.
Under the Advocates Act (Cap 16), common-law principles of Advocate-Client Privilege, and the Kenya Data Protection Act (2019), legal practitioners have an ethical and statutory duty to maintain confidentiality and protect client data from unauthorized access.
What Information Lives in MtaaLex? β
When your law firm uses MtaaLex to manage its daily practice, the system stores:
- Client Records: National ID numbers, corporate incorporation certificates, contact addresses, and KYC documents.
- Litigation & Case Files: Pleadings, witness statements, court orders, case diary entries, and strategy notes.
- Commercial & Conveyancing Instruments: Contracts, title deeds, land search results, and lease agreements.
- Accounting & Billing Data: Itemized fee notes, retainer accounts, disbursement logs, and VAT invoices.
- Internal Firm Notes: Confidential discussions between partners, associates, and pupils.
- AI Research & Drafting Sessions: Legal research queries, precedent searches, and drafted submissions.
Because of this sensitivity, security is not an optional featureβit is the foundation of digital legal practice.
The Shared Responsibility Model β
Security in MtaaLex is a partnership.
No matter how robust the software protections are, the system cannot protect your files if a user shares their login credentials, uses an easily guessable password, or leaves an unlocked computer unattended in a public court corridor.
To help your firm understand how security works, responsibilities are divided into three distinct pillars:
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SHARED RESPONSIBILITY MODEL β
ββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββ€
β π‘οΈ What MtaaLex Protects β β’ System authentication barriers β
β β β’ Workspace & firm data isolationβ
β β β’ Transmission encryption (HTTPS)β
β β β’ Private cloud document vault β
β β β’ Role-based access controls β
β β β’ Internal activity audit logs β
ββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββ€
β π€ What You Protect β β’ Your password and login privacyβ
β β β’ Locking your screen & devices β
β β β’ Recognizing phishing scams β
β β β’ Avoiding untrusted public PCs β
β β β’ Verifying recipient details β
ββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββ€
β βοΈ What Your Firm Admin β β’ Assigning appropriate roles β
β Protects β β’ Deactivating departing staff β
β β β’ Reviewing firm access & logs β
β β β’ Authorizing client matters β
ββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββββ1. What MtaaLex Protects β
MtaaLex implements technical safeguards within the software itself:
- Strict Workspace Isolation: Ensuring one law firm cannot view or access another firm's matters.
- Modern Authentication: Verifying cryptographic tokens on every single request through our identity provider (Clerk).
- Encrypted Transmission: Using modern TLS encryption so data cannot be intercepted between your browser and our servers.
- Private Document Storage: Storing court pleadings and evidence in secure object storage accessed only via time-limited, signed authorization links.
- Role-Based Controls: Restricting access within the firm so users only see what their role permits.
2. What You Protect (Every Practitioner) β
As an individual advocate, paralegal, or staff member, you are responsible for:
- Choosing a strong, unique password that you do not use on any other website.
- Never sharing your login credentials with colleagues, trainees, or family members.
- Locking your computer whenever you step away from your desk.
- Signing out immediately when using shared office computers or court registry terminals.
- Remaining vigilant against phishing emails and deceptive messages claiming to be MtaaLex.
3. What Your Firm Administrator Protects β
Managing Partners and designated Firm Administrators hold administrative oversight:
- Ensuring that only authorized staff members receive accounts in your firm workspace.
- Assigning the principle of least privilege (e.g., giving junior pupils access only to assigned files, rather than full administrative rights).
- Immediately deactivating accounts when an advocate, associate, or legal assistant departs the firm.
- Regularly reviewing firm activity and billing permissions.
Next Steps β
Explore the following guides to understand how MtaaLex safeguards your files and how your team can uphold best security practices:
