Zero-Trust Architecture for a Legal Document Management Platform
Let's Connect
Overview
What we built
A legal technology platform let any signed-in user open any document, which no serious law firm could accept. We rebuilt it on zero-trust principles, and unauthorised access incidents fell from 6 per month to zero.
In plain terms: the company sold document management to law firms, whose case files are among the most sensitive material any business holds, yet its platform trusted everyone equally. Once a user was signed in, every document was within reach, whichever client or matter it belonged to. Unauthorised access was happening 6 times a month, and the enterprise law firms the company wanted to win would never clear a platform built that way through security due diligence.
We replaced that blanket trust with a zero-trust architecture: every single request to open a document is checked at the moment it happens, each document carries its own encryption key, every step of a document's life is recorded, and any downloaded copy is watermarked with the identity of the person who took it. The platform went on to pass security due diligence for 4 Am Law 100 firms, achieved ISO 27001 certification first in its category, and saw enterprise contract value rise by 60%.
The Problem
Every user could open every document
The flat permission model came from the platform's initial architecture, built when a small and familiar user base made blanket trust feel safe. As law firms brought real case files onto the system, that assumption became the product's biggest liability: any authenticated user could access any document, regardless of which client, case or firm it belonged to.
For legal work this was close to disqualifying. Law firms are bound by client confidentiality and by ethical walls between matters, yet unauthorised document access incidents were occurring on the platform at a rate of 6 per month. Every one of them cut against exactly the duty a firm exists to uphold, and every one was a conversation no vendor wants to have with a client.
The commercial ceiling was just as hard. Enterprise law firms subject every vendor to security due diligence before sensitive files move, and a flat permission model fails that review at the first question. The clients that would define the platform's future were the ones its architecture ruled out before a conversation could even begin.
Flat permission model
Any authenticated user could open any document on the platform, with no boundaries between clients, matters or firms once the login screen was passed.
Recurring access incidents
Unauthorised document access was happening 6 times per month, each incident cutting against the confidentiality duties law firms owe their clients.
No document accountability
The platform could not show a document's full history, who had viewed, changed, shared or downloaded it, which is the first record a firm's reviewers request.
Uncontrolled downloads
Once a file left the platform there was nothing tying the copy to the person who took it, making any leak effectively untraceable.
What it was costing them
Each of the 6 monthly unauthorised access incidents carried the risk of a confidentiality breach serious enough to lose a client relationship outright. Above that ran the opportunity cost: the enterprise law firms that anchor a legal technology company's growth could not pass the platform through security due diligence, capping contract values and leaving the most valuable segment of the market out of reach.
The Solution
Zero-trust document security architecture
We rebuilt the platform's security model on zero-trust principles: no request is trusted because of who made it or where it came from. Every attempt to open, change or share a document is evaluated on its own, at the moment it is made, against the requester, the document and the context of the request, so standing permissions no longer exist to be abused.
Encryption followed the same per-document logic. Rather than one key protecting the whole store, each document is sealed under its own managed encryption key, so access to one file confers nothing about any other, and revoking access to a single document is a precise operation rather than a blunt instrument applied to everything.
Around that core we built the accountability layer law firms audit for. A full document lifecycle audit trail records every event from creation onwards, and downloads carry dynamic watermarking with the recipient's identity embedded in the copy, so a file that leaves the platform remains attributable to the person who took it out.
Key decisions
Evaluate every request
Access is decided per request at the moment it happens, replacing the standing trust that had let any authenticated user reach any document.
One key per document
Per-document encryption key management means each file is sealed individually, so no single credential or breach unlocks the wider document store.
Record the whole lifecycle
The audit trail follows each document from creation onwards, giving firms a complete, reviewable history of every view, change and share.
Watermark every download
Dynamic watermarking embeds the recipient's identity in every downloaded copy, so files remain attributable long after they leave the platform's control.
Measurable Impact
What changed after launch
The incident line moved first and furthest: unauthorised document access incidents fell from 6 per month to zero. The architecture then carried the platform through the reviews that had been out of reach, passing security due diligence for 4 Am Law 100 law firm clients and becoming the first product in its category to achieve ISO 27001 certification.
The commercial result followed the security one. With certification in hand and enterprise reviewers satisfied, enterprise client contract value increased by 60%. Security moved from the platform's disqualifying flaw to its clearest differentiator, and the company now sells to the law firms its old architecture had ruled out.
Access control
Any authenticated user could open any document
Every request evaluated at the moment of access
Access incidents
Unauthorised access recorded 6 times per month
Reduced to zero after the zero-trust rebuild
Document accountability
No reliable history of who touched what
Full lifecycle audit trail and identity-watermarked downloads
Enterprise standing
Unable to pass law firm security due diligence
Cleared by 4 Am Law 100 firms, contract value up 60%
Headline results
Platform passed security due diligence for 4 Am Law 100 law firm clients
Unauthorised document access incidents reduced to zero from 6 per month
Platform became the first in its category to achieve ISO 27001 certification
Enterprise client contract value increased by 60% following security certification
Ready to Build your Legal Technology Business with secure-software-architecture
Ask Byte
Ask Byte
Typically replies instantly
just Now
Hi! I'm OrganByte's assistant. How can I help you today?
AI-generated content may be incorrect

