Legal Center
Agreements & Policies
The agreements, policies, and notices that govern the use and administration of the Laweyriez Platform, operated by Salienz LLC, and—where applicable—regulate or direct tenants’ activities therein. Each document is versioned and dated. The English-language version of each document governs.
For Subscribing Firms
The binding contract between Salienz LLC and the subscribing law firm governing access to and use of the platform.
Governs Salienz LLC’s processing of personal data on behalf of the firm, including CCPA/CPRA, multi-state privacy, and GDPR Article 28 terms.
The third-party sub-processors Salienz LLC uses to provide the platform, referenced by the Data Processing Addendum.
Uptime commitments, exclusions, and service credits available to eligible subscription tiers.
HIPAA Business Associate Agreement offered to firms that use the platform to create, receive, maintain, or transmit protected health information.
An adoptable FTC Safeguards Rule (16 C.F.R. Part 314) information-security program template for subscribing firms — qualified individual, risk assessment, safeguards, service-provider oversight, incident response, training, and governance reporting. A template for the firm to adopt, not Salienz’s program.
An adoptable risk-based AML/Customer Due Diligence program template for subscribing firms — CIP, CDD/beneficial ownership, sanctions/PEP screening, funds handling and cash reporting, monitoring, escalation, recordkeeping, and training. A template for the firm to adopt with counsel, not Salienz’s program.
For Authorized Users
The license that governs each individual authorized user’s access to and use of the platform software.
The conduct rules that apply to everyone who uses the platform, incorporated by reference into the other agreements.
How attorneys and staff must use AI-assisted features on the platform, including ABA competence and confidentiality obligations, verification requirements, HIPAA restrictions, and known AI risks.
Informational reference summarizing AI ethics guidance from all 50 states, DC, and the ABA — jurisdiction-by-jurisdiction obligations, opinion citations, and ethics hotline contacts.
For Firm Clients
Governs a firm client’s use of the client portal. Salienz LLC provides software only and forms no attorney-client relationship with portal users.
For External Recipients & Courts
Terms for people who receive a document, signing request, or notice through the platform but are not account holders.
Limited, view-only access terms for court personnel and others granted access to shared exhibits or trial presentations.
Platform-Wide
PCI DSS Self-Assessment Questionnaire A readiness package documenting why the platform is SAQ A eligible (card data handled entirely by Stripe; no PAN on Salienz systems), with pre-filled control responses and an Attestation of Compliance template. A self-assessment, not a certification.
Management-authored SOC 2 system description of the Salienz platform — infrastructure, software, people, data, and procedures, with service commitments, boundaries, and complementary user/sub-service controls. Pre-audit readiness, not a SOC 2 report.
Mapping of implemented platform controls to all five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy), with a gap list. A control mapping for audit readiness, not an auditor’s report.
Salienz LLC’s internal information security policy: governance, risk assessment, access control, data classification, change management, logging/monitoring, secure development, incident response, and security awareness.
How the platform encrypts data in transit and at rest, manages keys (including the master key and end-to-end-encrypted matter files), rotates and destroys keys, and the algorithms and standards used.
How Salienz detects, triages, contains, eradicates, recovers from, and notifies about security incidents, including severity levels and breach-notification obligations to firms, individuals, and regulators.
How the platform maintains and restores availability after disruption — architecture resilience, backups, recovery objectives (RTO/RPO), continuity procedures, and recovery testing.
How Salienz assesses and monitors sub-processors and key vendors — onboarding due diligence, contractual safeguards, annual review of SOC 2/ISO/PCI assurance, change notification, and offboarding.
How long the platform retains each category of data and how it is securely disposed of, including legal holds, crypto-shredding, and deletion requests. Firm (controller) instructions govern tenant data.
How Salienz LLC collects, uses, discloses, and protects personal information, including U.S. state privacy rights.
The cookies and similar technologies the platform uses, and your choices.
Consent to transact electronically and to use electronic records and signatures under ESIGN and UETA.
How to report copyright infringement and Salienz LLC’s notice-and-takedown procedure under the DMCA.