RetainProofRetainProof← Home

Trust & Security

Built for law-firm confidential data.

RetainProof handles your marketing, vendor and retained-matter data with controls designed for professional-services confidentiality — and documented to support a future SOC 2 review.

Encryption in transit

All traffic runs over TLS/HTTPS with Secure, HttpOnly, SameSite cookies and HSTS enforced.

MFA & strong auth

Bcrypt-hashed passwords, optional TOTP two-factor authentication with backup codes, and brute-force lockout.

Role-based access

Granular permissions per role — owner, manager, analyst, viewer — enforced on every endpoint.

Tenant isolation

Every record is scoped to your firm. No firm can ever read or write another firm's data.

Audit logging

Security-relevant actions — logins, MFA changes, admin actions, data changes — are logged with IP and timestamp.

Least-privilege admin

Platform administration is restricted and gated; firm users can never reach super-admin functions.

Data minimization

We don't store SSNs, medical records, full card numbers or case documents. Free-text is scrubbed of sensitive patterns.

Export & deletion

Export your complete data set anytime, and request full deletion of your firm's data on demand.

What we intentionally don't store

RetainProof minimizes sensitive data by design. We do not store Social Security numbers, medical records or PHI, full payment-card numbers (payments run through Stripe), or substantive case documents. Sensitive patterns entered in free-text fields are automatically redacted.

SOC 2 readiness

Our controls are mapped to the SOC 2 Trust Services Criteria across Security, Availability, Confidentiality and Privacy. Encryption at rest, automated backups and continuous monitoring are provided through our managed production infrastructure.

RetainProof™ · Provided by CMD Marketing Enterprises LLC through CMD+DesignLab.
This overview describes current controls and is provided for informational purposes.