Data security
How we protect the information you share with us.
Effective Sep 23, 2026
Protections in place
- All connections use HTTPS (TLS), with HTTP Strict Transport Security.
- Requests are stored in a managed Postgres database that is encrypted at rest.
- Only authorized staff can view requests, through single sign-on with individual accounts; access is logged.
- Every change to a request (status, export, delivery) is recorded in an audit log.
- Unsubmitted answers are kept only in your own browser for 30 minutes; contact details are never stored in your browser.
- Health information is never sent to advertising platforms or analytics tools.
- We collect only what a law firm needs for a first review — no Social Security numbers, record numbers, or uploads.
- Bot protection and duplicate detection reduce fraud and misuse.
Law firms and partners
Participating firms must protect the information they receive, use it only to evaluate and respond to your request, honor opt-outs and deletion requests, and notify us of any security incident. See our Data Usage & Buyer Responsibility Policy.
If something goes wrong
We maintain an incident response process. If a security incident affects your personal information, we will notify you and regulators as required by law.
Report a security issue
Email info@tortmatics.com with the subject “Security.” Please give us a reasonable time to fix issues before disclosing them, and don't access data that isn't yours.