Trust & Security
RetainProof handles your marketing, vendor and retained-matter data with controls designed for professional-services confidentiality — and documented to support a future SOC 2 review.
All traffic runs over TLS/HTTPS with Secure, HttpOnly, SameSite cookies and HSTS enforced.
Bcrypt-hashed passwords, optional TOTP two-factor authentication with backup codes, and brute-force lockout.
Granular permissions per role — owner, manager, analyst, viewer — enforced on every endpoint.
Every record is scoped to your firm. No firm can ever read or write another firm's data.
Security-relevant actions — logins, MFA changes, admin actions, data changes — are logged with IP and timestamp.
Platform administration is restricted and gated; firm users can never reach super-admin functions.
We don't store SSNs, medical records, full card numbers or case documents. Free-text is scrubbed of sensitive patterns.
Export your complete data set anytime, and request full deletion of your firm's data on demand.
RetainProof minimizes sensitive data by design. We do not store Social Security numbers, medical records or PHI, full payment-card numbers (payments run through Stripe), or substantive case documents. Sensitive patterns entered in free-text fields are automatically redacted.
Our controls are mapped to the SOC 2 Trust Services Criteria across Security, Availability, Confidentiality and Privacy. Encryption at rest, automated backups and continuous monitoring are provided through our managed production infrastructure.
RetainProof™ · Provided by CMD Marketing Enterprises LLC through CMD+DesignLab.
This overview describes current controls and is provided for informational purposes.