Security built for confidentiality obligations.
Handled. was built by a practicing litigator who carries the same confidentiality obligations you do. It was not built to monetize case data, run analytics on your matters, or build a database of client information across firms. That is why the product is local-first: your case information should be something you control, not something a vendor collects.
This page explains, in plain English, how Handled. protects your case information and your account. It is written to be useful both to you and to an IT or compliance reviewer, and every claim on it is consistent with, and does not go beyond, the commitments in the Privacy Policy, the Terms of Service, and the Data Processing Addendum.
Your case data
Free and Solo. Your case information stays in an encrypted local database on your own computer. The encryption key is held through your operating system's credential store, not sent to Handled. Free and Solo do not copy your case content to Handled.'s servers, or between computers through Handled., at all.
Pro. Pro keeps the same local database, and additionally creates a protected copy so you and one authorized assistant or paralegal can work from the same current information. That copy is encrypted on your device before it is uploaded, and Handled. does not hold the key needed to read it. Your recovery phrase, the human-readable key used to authorize additional devices, is generated on your own computer, and current setup does not transmit it to us. We cannot recreate it if you lose it.
What we can see. We can see and process operational metadata: which account or device made a change, when, and to which record, because that information is what lets us synchronize and run the service. We cannot see the actual content of your matters, notes, or client information in the protected Pro copy.
A caveat worth repeating. A .lhbackup file and a CSV matter report are both plain, unencrypted files. They do not inherit the local database's encryption or Pro's online protection. Exporting a backup or report takes information out of Handled.'s protected storage, and from that point forward, storing, transferring, and deleting it securely is on you.
Your account and the website
Signing in works the way most modern software handles it: credentials and session management through our authentication provider. Devices you authorize are tracked, and a Pro account owner can remove an assistant's or paralegal's access and registered devices from their account at any time.
Checkout and billing are handled entirely by Lemon Squeezy, acting as merchant of record. Your card details go directly to Lemon Squeezy, not to us. Handled. does not process or store your payment card information.
Information sent between your computer and Handled.'s servers travels over encrypted connections. Each plan enforces a device and seat limit, and every request to synchronize or access Pro data requires a currently valid license and an authorized device.
How we operate
Before a new feature ships, we review how it handles case information and account access, not only whether it works. Access to the infrastructure that runs Handled. is limited to what a person actually needs to operate and support the service, not open by default.
We would rather be direct about where we are today than imply otherwise: Handled. does not currently hold a SOC 2 certification, has not completed a formal third-party security audit, and does not run a bug bounty program. Those are not in place yet. If your firm needs documentation of our practices for its own review, email us and we will work with you directly.
If something goes wrong
We maintain an incident-response process. If a security incident affects information for which notice is legally required, we will notify affected individuals, and any required regulators, without unreasonable delay and within the timeframe the law requires. Where we are processing information on your behalf as a service provider, which covers most Pro case content, we will notify you without undue delay so that you can meet your own notification obligations to your clients.
Technical FAQ
.lhbackup file and a CSV matter report are both plain, unencrypted files once you create them. They do not inherit the local database's encryption or Pro's online protection. Once you export one, protecting, storing, and deleting it securely is your responsibility.The binding legal language behind everything on this page lives in the Privacy Policy, the Terms of Service, and the Data Processing Addendum. Questions, or found a security issue? Email [email protected].