Security & privacy

How we protect your data, plainly stated.

Evidence in a family matter is some of the most sensitive personal data there is. This page lists only what is actually in place today, verified against our own systems. Where something is on the roadmap rather than live, it says planned: we would rather tell you that than dress it up.

What is in place today

1. Encrypted in transit (HTTPS/TLS)

Every connection to legallyheard.co.uk uses HTTPS with TLS 1.2 or 1.3 (certificates from Let's Encrypt). Plain HTTP requests are redirected to HTTPS. Session cookies are marked Secure and HttpOnly, and every form is protected against cross-site request forgery.

2. A private server in the EU

Your data lives on our own dedicated server, hosted by Hetzner in Falkenstein, Germany (EU), not on a shared multi-tenant analytics platform. We operate under UK GDPR (our users are UK-based) and EU GDPR (where the data is hosted).

3. SHA-256 evidence integrity

Every file added to a case's evidence vault gets a SHA-256 cryptographic hash computed at upload and recorded in the report's exhibit index. Any party, yours, theirs, or the court, can independently verify that a supplied copy is bit-for-bit identical to the file we recorded. Metadata such as captions can be edited; the file and its hash never change.

4. Owner-scoped access control

Cases, uploads, evidence and reports are tied to your account. Requests for another user's case return "not found", the platform does not even confirm the case exists. Login attempts are rate-limited, and passwords are stored only as salted one-way hashes (scrypt), never in a readable form.

5. Locked-down storage

Uploads and reports are stored outside the web root with owner-only file permissions, in per-user, per-case directories, and are reachable only through authenticated, owner-checked routes. The database file itself is readable only by the application's account.

6. Deletion you control

You can delete individual uploads, evidence files, key moments and reports at any time. You can also delete your entire account, every file and every database record, self-serve from Account settings, in line with your UK GDPR right to erasure. Deletion takes effect immediately on our server.

What we don't do

  • We don't sell your data. Not to advertisers, not to data brokers, not "anonymised", not at all.
  • We don't run trackers. No advertising pixels, no third-party analytics; the site sets a single first-party cookie.
  • We don't use your content to train AI models. The local rule-based overview stays on our server. Chat reaches an external AI provider only for an explicitly opted-in Deep Fact-Finding Review after provider, data-flow and estimated-cost disclosure.
  • We don't take sides. The platform presents the communication record factually and impartially; the same analysis is applied to every participant in a conversation.

Third parties we rely on

Hetzner (Germany, EU) provides the physical server. Let's Encrypt issues our TLS certificates. Stripe processes card payments when live payments are enabled, card numbers never touch our server. The local chat overview is rule-based and runs on our server. The optional Deep Fact-Finding Review and optional draft transcription may use an external AI provider; before either, we disclose the provider, content sent, purpose, safeguards and estimated provider cost and require explicit opt-in. No chat is sent to an AI provider without that consent.

Honest answers to hard questions

"What if a court orders you to hand over case data?"

We comply with lawful UK court orders, and where we are permitted to do so we will tell you about the request. We will always seek the narrowest disclosure the order allows.

"Can LegallyHeard staff read my case?"

Honestly: administrators have technical access to the server. The white-glove Court Bundle and Deep Fact-Finding Review may also require authorised staff to handle scoped material for delivery and quality checks. Access is limited to operating the service and completing the agreed work; we explain the scope before engagement and do not use case content for unrelated purposes.

"What protects me during an AI-assisted deep review?"

The service is not self-serve or fully automated. We agree scope, disclose the proposed provider and estimated provider cost, and obtain explicit opt-in before sending chat. AI returns structured findings across overlapping context windows; deterministic code deduplicates and synthesises them, direction/directedness is classified, and quotations are checked exactly against the supplied source. Reporting applies the same rules to both sides.

"What if my ex-partner is also a customer?"

Accounts are fully separated. Neither account can see the other's cases or files, requests for someone else's case return "not found", and the platform never discloses whether any particular person holds an account.

"Is my data encrypted at rest?"

In transit, yes: everything is TLS-encrypted. At rest, files are protected by strict server access controls and owner-only file permissions, but the disks themselves are not currently encrypted. Full disk-level encryption at rest is planned; we say so here rather than claim it early.

"Are you ISO 27001 / SOC 2 certified?"

No, and we won't pretend to be. We are a young product run on infrastructure we control. Independent security review and formal certifications are on the roadmap as the product grows; anything on this page describes what is genuinely in place today.

Planned: clearly separated from what’s live

The items below are roadmap commitments, not current facts. They will move to the list above only when they are actually in place.

  • Planned: full disk-level encryption at rest on the evidence server.
  • Planned: two-factor authentication for accounts.
  • Planned: an independent security review / penetration test, with a summary made available to firms.
  • Planned: a standard Data Processing Agreement (DPA) and published sub-processor list for professional users, with advance notice of changes.
  • Planned: per-case access logs that users can download to support chain-of-custody statements.

Questions about any of this?

Ask us directly, we'll answer plainly, including about the things we haven't built yet.