Security & how we handle your data

Plain-language answers, because you're trusting us with confidential case data and that deserves a straight answer, not marketing language.

Your firm's data is isolated

Every case, deadline, task, document, and activity record is tagged to your firm and every database query is scoped to that tag. Other firms using DocketPilot cannot see, query, or export your data, and there is no cross-firm reporting or aggregation of any kind.

Documents are private by default

Uploaded documents are stored in a private object store, not a public file host. There is no public URL for any document — every download is re-checked against your login session and your firm ID before the file is served, every time.

Encrypted in transit

The entire app is served over HTTPS. Login sessions are signed tokens stored in an httpOnly cookie, which means the token itself is never exposed to page scripts.

We don't sell or share your data

DocketPilot does not sell, rent, or share client or case data with third parties, and we don't run ads. The only outbound data flow is transactional email (deadline reminder notifications), sent through our email provider on your behalf.

Where we are today

DocketPilot is an early-stage product. We are not yet SOC 2 certified or through a formal third-party security audit — we want to say that plainly rather than let it go unmentioned. What's described above reflects the actual current architecture, not a compliance claim. If formal certification matters for your firm's requirements, tell us — it's on our roadmap and we'd rather know it's a blocker for you now than lose your trust later.

Questions or concerns

Reach out any time at security@docketpilot.app — a real person reads it, not a ticket queue.