Skip to content

Security Limitations & Risk Awareness

Honesty and realistic risk assessment are essential components of responsible legal technology.

At MtaaLex, we do not make exaggerated marketing claims such as "unhackable", "100% secure", or "completely immune to risk". No cloud software, bank, or government judiciary in the world can make such guarantees.


"No online system can guarantee zero risk. MtaaLex uses modern security controls designed to significantly reduce risk, but protecting confidential legal information fundamentally depends on how users, physical devices, and law firms use the system."

Why Absolute Security Does Not Exist:

  1. The Human Factor: If a practitioner accidentally writes down their password, falls victim to an elaborate social engineering scheme, or allows an unauthorized person to view their screen, technical software barriers cannot prevent unauthorized disclosure.
  2. Endpoint Vulnerabilities: If an advocate's personal laptop is infected with malware or a keystroke logger from an unrelated website, the malware can record passwords as they are typed.
  3. Evolving Threat Landscape: Digital security requires continuous vigilance, testing, and updates. Security is a continuous process of risk mitigation, not a one-time guarantee.

Status of MtaaLex Security Controls

To ensure complete transparency with managing partners and compliance officers, here is the clear distinction between what is currently implemented, what is recommended practice, and our future roadmap:

Security DomainStatus in MtaaLexPractical Meaning for Your Law Firm
Workspace & Firm IsolationCurrently ImplementedDatabase queries are strictly scoped by Organization ID. Firms cannot view or query each other's files.
Transmission Encryption (TLS/HTTPS)Currently ImplementedAll web traffic is encrypted in transit using Let's Encrypt TLS 1.2/1.3.
Private Document StorageCurrently ImplementedDocuments are housed in private object storage, accessible only via temporary, authenticated presigned URLs.
Granular Roles & Collaborator RulesCurrently ImplementedComprehensive role matrix and collaborator restrictions prevent unauthorized internal file sharing.
Identity & Session VerificationCurrently ImplementedToken-based cryptographic validation powered by Clerk on every protected endpoint.
Security Audit TrailsCurrently ImplementedLogs key events (actor, email, action, timestamp) viewable by administrators.
Individual Multi-Factor Authentication (MFA)🟡 Recommended User PracticeUsers can enable two-factor authentication (SMS/Authenticator App) within their Clerk account profile settings.
Enforced Firm-Wide Mandatory MFA🔵 Future Roadmap ImprovementAbility for Managing Partners to programmatically require MFA for all invited staff before granting workspace entry.
Automated Client Document Watermarking🔵 Future Roadmap ImprovementAutomated dynamic stamping of firm name and viewing timestamp across confidential PDF previews.

Our Commitment to Your Practice

MtaaLex is engineered to provide African legal practitioners with a resilient, modern, and compliant operating environment. We continually monitor server health, update software dependencies, and adhere to industry standards to protect your firm's standing, reputation, and client trust.

If your firm requires a custom Data Processing Agreement (DPA) or specific compliance documentation under the Kenya Data Protection Act, please contact our legal and security team at info@mtaalexsolutions.co.ke.

Empowering African Legal Practice through Technology & Compliance.