Skip to main content

Security & Privacy First

BundleCreator.co implements comprehensive security measures to protect your sensitive legal documents with multiple layers of defence, aligned with UK GDPR and legal professional privilege.

Quick Answer

BundleCreator protects legal documents with AES-256 encryption at rest, TLS 1.3 in transit, UK-hosted infrastructure in the europe-west2 (London) region, and defence-in-depth including Clerk authentication with optional MFA, row-level security in PostgreSQL, CSRF protection, rate limiting, and 7-year audit logging. The platform is tested against the OWASP Top 10 and aligned with UK GDPR and legal professional privilege.

Tested against OWASP Top 10Internal security review covering the full OWASP Top 10, with findings documented and remediated

Defence-in-depth security architecture • UK-based infrastructure • Full audit trails

How We Protect Your Documents

Comprehensive security measures at every level to safeguard your confidential legal documents

Privacy-Preserving Bundle Assembly

Your bundles are assembled entirely in your browser. The server never sees your assembled bundle contents, ensuring maximum privacy for privileged documents.

  • Client-side bundle creation
  • Zero server knowledge of bundle contents
  • Optional AES-256 password protection

Secure Data Storage

Your documents are protected with AES-256 encryption at rest and comprehensive access controls.

  • AES-256 encryption at rest (PostgreSQL cloud infrastructure)
  • Row-Level Security (RLS) isolation
  • UK-based data centres (europe-west2)

Multi-Factor Authentication

Enhanced identity verification protecting Legal Professional Privilege with additional authentication layers.

  • MFA enforcement at launch (5th November 2025)
  • TOTP authenticator app support
  • SMS and backup code options
  • Protection against unauthorised access

Defence-in-Depth Security

Multiple independent security layers ensure your documents remain protected even if one layer is compromised.

  • Network, application, and data layer protection
  • Real-time threat detection and monitoring
  • 7-year security audit log retention

Tested against the OWASP Top 10

Transparent internal review: our own security review documents coverage of the OWASP Top 10, with findings remediated and test results published internally. This is an in-house assessment, not an independent certification.

Defence in depth

Layered

UK-hosted infrastructure

AI

Your data never trains AI

BundleCreator does not use customer documents, bundles, or case details to train AI models — ours or any third party’s. The Mind Map feature uses Claude with zero data retention and client-side PII stripping before any text leaves your browser. Read Aloud uses Google Cloud Text-to-Speech, which does not train on content. Document OCR runs entirely on your device via Tesseract.

Read the full AI transparency statement →

Training on your data

Never

Zero data retention with Anthropic

Defence-in-Depth Security Architecture

Multiple independent layers of protection safeguard your sensitive legal documents

What is Defence-in-Depth?

Unlike single-layer security approaches, our defence-in-depth architecture implements multiple independent security controls at every level. If one layer is compromised, additional layers continue protecting your data. This professional multi-layered approach ensures your sensitive legal documents remain secure even against sophisticated threats.

Layer 1: Transport & Storage Security

  • TLS 1.3 - All data encrypted in transit
  • AES-256 - Database encryption at rest
  • HTTPS Enforced - Secure connections only
  • Signed URLs - Time-limited document access
  • SHA-256 - Document integrity verification

Layer 2: Access Control & Authentication

  • OAuth 2.0 authentication service - SOC 2 Type II certified
  • Multi-Factor Authentication (MFA) - Enforced at launch with TOTP, SMS, and authenticator app support
  • JWT session management - Secure tokens
  • Session timeouts - Automatic logout
  • Account lockout - Failed attempt protection
  • Rate limiting - Prevent brute force attacks

Layer 3: Data Protection

  • Row-Level Security (RLS) - Data isolation
  • RBAC permissions - Role-based access
  • Audit logging - Complete activity tracking
  • Aligned with UK GDPR — data deletion rights honoured
  • Data residency - UK-based servers

Layer 4: Application Security

  • CSRF protection - Request forgery prevention
  • Security headers - XSS and clickjacking protection
  • Input validation - Zod schema validation
  • Content Security Policy - Script injection protection
  • CORS policies - Origin restriction

Advanced Security Certification Preparation

ISO 27001:2022
Preparation for certification in progress

Security controls implemented based on ISO 27001:2022 Annex A framework. Formal certification audit scheduled Q2 2026.

SOC 2 Type II
Preparation for certification in progress

Trust Service Criteria framework adopted with professional security controls. Formal audit planned Q2 2026.

Current Status: Professional security controls implemented, working towards formal certification

Standards & Certification Roadmap

Designed around recognised standards for legal data protection, with a clear roadmap for formal certification

GDPR

Aligned with UK GDPR

Data handling practices aligned with UK data protection law

In Progress
SOC2

SOC 2 Type 2

Working towards certification. Trust Services Criteria framework adopted. Formal audit planned Q2 2026.

In Progress
ISO

ISO 27001:2022

Working towards certification. Security controls based on Annex A framework. Formal audit Q2 2026.

🔐

Privacy-Preserving Client-Side Architecture

Privacy by design: Your bundles are assembled in your browser. The server never sees your assembled bundle contents.

Client-Side Bundle Creation

  • ✓ Client-side processing in your browser
  • ✓ Bundle assembly never occurs on our servers
  • ✓ Maximum Legal Professional Privilege protection
  • ✓ Zero server knowledge of bundle contents

Optional AES-256 Password Protection

  • ✓ Password protection applied in your browser
  • ✓ AES-256 encryption for password protection
  • ✓ Only you know the password
  • ✓ Additional layer for external sharing

How it works: When you create a bundle, encrypted documents are downloaded to your browser, decrypted and assembled entirely on your device, and optionally password-protected before being saved to your computer. This privacy-preserving architecture ensures your privileged legal documents remain confidential throughout the entire process.

OWASP Top 10: internal review

Transparent self-assessment: our own security review covers the OWASP Top 10 risks. Findings are documented internally and remediated. This is an in-house assessment, not an independent certification.

UK legal framework alignment

  • ✓ Aligned with the UK Data Protection Act 2018
  • ✓ Legal professional privilege protections
  • ✓ Bundles built around Practice Direction 27A
  • ✓ Designed with the SRA Principles in mind
  • ✓ Designed with the BSB Core Duties in mind

Security practices

  • ✓ Internal review covering OWASP Top 10:2025
  • ✓ Defence-in-depth architecture
  • ✓ Regular internal security reviews
  • ✓ Penetration testing (scheduled)
  • ✓ Cyber Essentials (certified); ISO 27001 (in progress)

Enterprise & On-Premise Deployment

Yes, we're cloud-based but we don't have to be. Contact us about our Enterprise solutions.
Our technology can be housed within your secure environment, for the ultimate assurance.

Deployment Options

  • ✓ Private cloud (your AWS/Azure/GCP account)
  • ✓ On-premise within your data centre
  • ✓ Hybrid cloud/on-premise models
  • ✓ Air-gapped environments

Enterprise Benefits

  • ✓ Complete infrastructure control
  • ✓ Custom security integration
  • ✓ Regulatory compliance flexibility
  • ✓ Data sovereignty assurance

We deliver secure, state-of-the-art innovation with clean, modern designs.
Get in touch

Tailored solutions for law firms requiring maximum control and security

Professional Infrastructure Security

All our critical infrastructure providers maintain recognised security certifications (SOC 2, ISO 27001, Cyber Essentials), independently audited and verified:

Cloud Infrastructure

  • PostgreSQL Database: SOC 2 Type II + ISO 27001 certified
  • Google Cloud Platform: SOC 2 + ISO 27001/27017/27018
  • Cloud Storage: Full compliance suite (SOC 2, ISO 27001)

Application Services

  • OAuth 2.0 Authentication Service: SOC 2 Type II certified
  • Payment Processing: PCI DSS Level 1 + SOC 2 + ISO 27001
  • All providers: UK GDPR compliant

Supply Chain Security: All critical infrastructure providers reviewed and verified on 5th November 2025 as part of our ISO 27001:2022 A.5.22 control implementation

G-Cloud 15 FrameworkRM1557.15

NCSC 14 Cloud Security Principles

BundleCreator is designed to meet all 14 National Cyber Security Centre Cloud Security Principles, demonstrating our commitment to UK government security standards.

All 14 Principles: Compliant

PrincipleStatus
1. Data in Transit ProtectionCompliant
2. Asset Protection & ResilienceCompliant
3. Separation Between CustomersCompliant
4. Governance FrameworkCompliant
5. Operational SecurityCompliant
6. Personnel SecurityCompliant
7. Secure DevelopmentCompliant
8. Supply Chain SecurityCompliant
9. Secure User ManagementCompliant
10. Identity & AuthenticationCompliant
11. External Interface ProtectionCompliant
12. Secure Service AdministrationCompliant
13. Audit Information for UsersCompliant
14. Secure Use of the ServiceCompliant

UK Data Residency

All user data stored exclusively in London, UK data centres (europe-west2). No data transfer outside the United Kingdom.

Defence-in-Depth

Multiple independent security layers at network, application, and data levels ensure protection even if one layer is compromised.

7-Year Audit Retention

Comprehensive audit logs retained for 7 years to meet UK legal requirements. Tamper-evident logging architecture.

Security Certification Roadmap

CE
Cyber Essentials
Q1 2026
Certified
ISO
ISO 27001
Q3 2026
In progress
SOC2
SOC 2 Type II
Q4 2026
Planned

Reference: NCSC Cloud Security Principles • G-Cloud 15 Framework (RM1557.15)

Comprehensive Activity Logging

Complete transparency with detailed audit trails for every action

Everything is Tracked

Our comprehensive activity log provides complete visibility into all bundle activities, essential for compliance, security audits, and team collaboration.

User Activities

  • ✓ Login/logout times and locations
  • ✓ Failed login attempts
  • ✓ Password changes
  • ✓ Permission modifications
  • ✓ Account settings updates

Document Actions

  • ✓ Document uploads and deletions
  • ✓ Page reordering and edits
  • ✓ Redaction applications
  • ✓ OCR processing status
  • ✓ Version history tracking

Bundle Operations

  • ✓ Bundle creation and deletion
  • ✓ Export and download events
  • ✓ Compression activities
  • ✓ Template usage
  • ✓ Format checks against court rules

Sharing & Access

  • ✓ Bundle sharing events
  • ✓ Access grant/revoke actions
  • ✓ External viewer activities
  • ✓ Download permissions
  • ✓ Link expiration tracking

Note: All activity logs are immutable and retained for record-keeping purposes. Logs can be exported for security audits or legal requirements.

Our Privacy Commitment

Our Privacy Principles:

  • Your data is encrypted at rest
  • No sharing with third parties for marketing
  • Data handling aligned with UK GDPR
  • Legal professional privilege respected
  • Comprehensive audit trails
  • Data deletion upon request
  • Minimal data collection
  • Transparent security practices

Important Note: While your documents are protected with industry-standard encryption at rest and in transit, authorised system administrators may access data for support and maintenance purposes under strict confidentiality agreements.

Your trust is our foundation. Security and privacy aren't just features - they're fundamental to everything we do.

Found a security issue?

We welcome responsible disclosure from the security research community. Our users are often people who cannot afford solicitors. Your work helps protect them.

Safe harbour applies under our disclosure policy for good-faith research.

Experience Secure Document Management

Trusted security and compliance features designed specifically for legal professionals

Aligned with UK GDPR • 7-day free trial • Cancel anytime