Security Practices
Version 1.2.0 · Effective July 17, 2026
TRIBUNALMETRIX SECURITY PRACTICES Version: 1.2.0 TribunalMetrix is designed as a data-minimized legal-support service. It does not offer saved client or matter workspaces. Matter information is processed only for the active request and is not intentionally retained after the result is returned. Core safeguards include invitation-only access; mandatory authenticator-app multi-factor authentication; account roles; database-enforced ownership of firm-profile information; twelve-hour maximum sessions; thirty-minute inactivity expiry by default; secure, HttpOnly, SameSite cookies; per-session CSRF tokens; origin validation; encrypted HTTPS transport; restricted use of server administrative credentials; private storage of optional firm logos; metadata-stripped logo normalization; no matter details in security logs; no server storage of generated PDFs; no content-based research history; and security-session revocation. Production processing locations are described as follows: development infrastructure. Cloudflare should initially be configured as DNS-only unless its proxying, logging and data-processing implications have been separately assessed and documented. Authentication email must not contain client or matter information. TribunalMetrix is not certified or approved by the Law Society of Ontario and cannot guarantee a user’s compliance. Each licensee remains responsible for assessing the service, configuring it appropriately and complying with professional, privacy and records-management duties. Security concerns should be reported promptly to thomas-turner@hotmail.com.