Enterprise by default

There is no enterprise tier. Every firm gets the architecture the most demanding firm would insist on, because it is the only way Hourglass runs.

Compliance and assurance

  • SOC 2 Type I

    Our security, availability, and confidentiality controls have been independently examined. Our Type I report and a commitment letter outlining our path to Type II are available on request.

  • CCPA

    California's consumer-privacy law, governing the personal information of the people in your matters.

  • GDPR

    The EU's data-protection regulation, governing how personal data is collected, processed, and stored.

  • HIPAA

    The US health-privacy rule, for matters that carry protected health information.

Your firm's own deployment

Hourglass runs as a complete, separate installation for each firm: its own application, its own database, its own audit record. This is the only path a request can take through yours.

Another firm

Your firm
  1. An encrypted connection

    TLS protects every request between your browser and your firm deployment.

  2. A dedicated deployment

    Reached over TLS, running for your firm and no one else.

  3. Your own database

    Encrypted at rest with AES-256. Nothing pooled, nothing shared.

  4. The audit record

    Every access and change, written down where your firm can read it.

Another firm

Each firm runs in its own application deployment against its own database. Firm application data is not pooled into a shared customer database.

Hosted in the United States

Every firm deployment and its customer data are hosted and processed in the United States.

Encrypted throughout

Data is encrypted in transit with TLS and at rest with AES-256, everywhere it moves and everywhere it sits.

Isolated infrastructure

Each firm receives its own application deployment and database, with no shared customer application datastore.

Asked and answered

Where is our data hosted?

In the United States. Each firm’s application deployment and database are hosted there, and customer application data is not pooled into a shared firm database.

How is our firm's data kept separate from other firms'?

Every firm runs in its own application deployment with its own database. Customer application data is not pooled into a shared firm database. This is not an enterprise tier; it is the only way Hourglass runs.

How is our data encrypted?

In transit with TLS and at rest with AES-256, everywhere it moves and everywhere it sits.

How long is our data retained?

Core customer records follow your firm's configured retention and enterprise agreement. Processing data and operational logs generally follow a rolling retention period of no more than thirty days.

How do you test your defenses?

Automated vulnerability scanning runs continuously across our infrastructure and dependencies.

What happens if there is a security incident?

Affected firms are notified within 72 hours.

Security questionnaires, documentation requests, and vulnerability reports all reach a person at security@hourglass.law.