Legal Center

Agreements & Policies

The agreements, policies, and notices that govern the use and administration of the Laweyriez Platform, operated by Salienz LLC, and—where applicable—regulate or direct tenants’ activities therein. Each document is versioned and dated. The English-language version of each document governs.

For Subscribing Firms

Master Subscription Agreementv1

The binding contract between Salienz LLC and the subscribing law firm governing access to and use of the platform.

Data Processing Addendumv1

Governs Salienz LLC’s processing of personal data on behalf of the firm, including CCPA/CPRA, multi-state privacy, and GDPR Article 28 terms.

Sub-processor Listv1

The third-party sub-processors Salienz LLC uses to provide the platform, referenced by the Data Processing Addendum.

Service Level Agreementv1

Uptime commitments, exclusions, and service credits available to eligible subscription tiers.

Business Associate Agreementv1

HIPAA Business Associate Agreement offered to firms that use the platform to create, receive, maintain, or transmit protected health information.

GLBA Safeguards Program (Firm Template)Firm templatev1

An adoptable FTC Safeguards Rule (16 C.F.R. Part 314) information-security program template for subscribing firms — qualified individual, risk assessment, safeguards, service-provider oversight, incident response, training, and governance reporting. A template for the firm to adopt, not Salienz’s program.

AML / Customer Due Diligence Program (Firm Template)Firm templatev1

An adoptable risk-based AML/Customer Due Diligence program template for subscribing firms — CIP, CDD/beneficial ownership, sanctions/PEP screening, funds handling and cash reporting, monitoring, escalation, recordkeeping, and training. A template for the firm to adopt with counsel, not Salienz’s program.

For Authorized Users

End User License Agreementv3

The license that governs each individual authorized user’s access to and use of the platform software.

Acceptable Use Policyv2

The conduct rules that apply to everyone who uses the platform, incorporated by reference into the other agreements.

Artificial Intelligence Usage Policyv1

How attorneys and staff must use AI-assisted features on the platform, including ABA competence and confidentiality obligations, verification requirements, HIPAA restrictions, and known AI risks.

State Bar AI Ethics Guidance Referencev1

Informational reference summarizing AI ethics guidance from all 50 states, DC, and the ABA — jurisdiction-by-jurisdiction obligations, opinion citations, and ethics hotline contacts.

For Firm Clients

Client Portal Terms of Usev2

Governs a firm client’s use of the client portal. Salienz LLC provides software only and forms no attorney-client relationship with portal users.

For External Recipients & Courts

Third-Party Recipient Notice & Termsv1

Terms for people who receive a document, signing request, or notice through the platform but are not account holders.

Court Personnel & Limited Viewer Access Termsv1

Limited, view-only access terms for court personnel and others granted access to shared exhibits or trial presentations.

Platform-Wide

PCI DSS SAQ A Readiness PackagePlatform-widev1

PCI DSS Self-Assessment Questionnaire A readiness package documenting why the platform is SAQ A eligible (card data handled entirely by Stripe; no PAN on Salienz systems), with pre-filled control responses and an Attestation of Compliance template. A self-assessment, not a certification.

SOC 2 System Description (Readiness)Platform-widev1

Management-authored SOC 2 system description of the Salienz platform — infrastructure, software, people, data, and procedures, with service commitments, boundaries, and complementary user/sub-service controls. Pre-audit readiness, not a SOC 2 report.

SOC 2 Control Matrix (Readiness)Platform-widev1

Mapping of implemented platform controls to all five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy), with a gap list. A control mapping for audit readiness, not an auditor’s report.

Information Security PolicyPlatform-widev1

Salienz LLC’s internal information security policy: governance, risk assessment, access control, data classification, change management, logging/monitoring, secure development, incident response, and security awareness.

Encryption & Key Management PolicyPlatform-widev1

How the platform encrypts data in transit and at rest, manages keys (including the master key and end-to-end-encrypted matter files), rotates and destroys keys, and the algorithms and standards used.

Incident Response PlanPlatform-widev1

How Salienz detects, triages, contains, eradicates, recovers from, and notifies about security incidents, including severity levels and breach-notification obligations to firms, individuals, and regulators.

Business Continuity & Disaster Recovery PolicyPlatform-widev1

How the platform maintains and restores availability after disruption — architecture resilience, backups, recovery objectives (RTO/RPO), continuity procedures, and recovery testing.

Vendor & Sub-processor Management PolicyPlatform-widev1

How Salienz assesses and monitors sub-processors and key vendors — onboarding due diligence, contractual safeguards, annual review of SOC 2/ISO/PCI assurance, change notification, and offboarding.

Data Retention & Disposal PolicyPlatform-widev1

How long the platform retains each category of data and how it is securely disposed of, including legal holds, crypto-shredding, and deletion requests. Firm (controller) instructions govern tenant data.

Privacy PolicyPlatform-widev2

How Salienz LLC collects, uses, discloses, and protects personal information, including U.S. state privacy rights.

Cookie PolicyPlatform-widev1

The cookies and similar technologies the platform uses, and your choices.

Electronic Records & Signatures ConsentPlatform-widev1

Consent to transact electronically and to use electronic records and signatures under ESIGN and UETA.

Copyright & DMCA PolicyPlatform-widev1

How to report copyright infringement and Salienz LLC’s notice-and-takedown procedure under the DMCA.