Trust Center
Welcome to FirmInsights' Trust Center
Trust lies at the heart of our mission.
FirmInsights’ Trust Center was designed to clearly demonstrate to current and prospective clients our ongoing dedication to becoming the most reliable and secure platform for your law firm.
Within the Trust Center, you’ll see our unwavering commitment to rigorous security protocols, strict regulatory compliance, and data privacy. We adhere closely to global standards and local requirements, employing advanced cybersecurity technologies—including state-of-the-art encryption and real-time threat monitoring—to safeguard your valuable information.
Transparency is central to our approach. We openly communicate how your data is stored, managed, and protected, reinforcing accountability through frequent audits and clear reporting. At FirmInsights, your data security and privacy are our top priorities, and we continuously strive to uphold the highest professional standards.
Certification
Service Organization Control 2
SOC 2 (Service Organization Control 2) focuses on evaluating a company’s systems based on trust service criteria: security, availability, processing integrity, confidentiality, and privacy. It ensures that service providers securely manage data to protect the interests of their customers. SOC 2 compliance demonstrates a commitment to stringent operational controls and safeguards for handling sensitive information.
International standard for information security management systems
ISO 27001 is an international standard for information security management systems (ISMS). It provides a framework for implementing, managing, and continuously improving security practices. Organizations certified with ISO 27001 demonstrate their ability to protect sensitive data through risk assessments, structured policies, and robust control measures.
Data Privacy
Your data privacy is of paramount importance.
FirmInsights’ systems are designed to keep your information confidential, and accessible only to authorized parties. We never share customer data with third parties without consent, and all stored information is encrypted and securely managed.
Data Security
-
Data Backups
FirmInsights captures backups regularly to ensure internal and customer data is protected from loss according to our Business Continuity and Disaster Recovery procedures. -
Encryption-at-rest
All customer data is encrypted at-rest using AES-256. FirmInsights is committed to following encryption best practices per industry guidelines and continually reviews the rigor of current encryption standards. -
Encryption-in-transit
All communication with our services is encrypted using the TLS protocol and HTTPS secure protocol, ensuring the confidentiality, integrity, and authenticity of transmitted data. -
Physical Security
The physical security of our infrastructure is managed by AWS. Additional Information can be found in AWS’s security documentation: https://aws.amazon.com/security/ -
Web Application firewall
FirmInsights is committed to securing online applications for continued security and availability.
Infrastructure
-
AWS
FirmInsights' infrastructure is hosted by AWS. Additional information on AWS infrastructure security can be found at: https://aws.amazon.com/security/ -
BCP/DR
We have a formal Business Continuity and Disaster Recovery plan, which is exercised, reviewed, and approved annually. -
Separate environment
At FirmInsights, the production and development environments are maintained as distinct entities to safeguard operational integrity and data confidentiality.
Endpoint Security and Monitoring
-
EDR\XDR
All employee endpoints are protected with an advanced EDR solution. Endpoint security signals are monitored regularly for anomalous activity. -
SIEM
FirmInsights prioritizes the secure and centralized storage of crucial infrastructure logs. Our SIEM systems continuously monitor these logs, enabling real-time analysis to promptly detect, alert, and mitigate potential threats. -
SOC team
The SOC (Security Operations Center) team is responsible for 24/7/365 monitoring of the company's entire infrastructure
External Controls
Annual Penetration Testing (PT)
We conduct annual penetration tests performed by an external, independent cybersecurity firm. These tests identify potential vulnerabilities in our systems, ensuring our security measures remain effective and up to date. Additionally, a retest is performed to verify that all identified issues have been properly addressed and mitigated. Upon request, we provide existing customers with a detailed findings report.
Risk Assessments by External Experts
We conduct regular risk assessments to identify and evaluate potential threats to our organization. These assessments are overseen by an independent third-party company specializing in risk management, ensuring unbiased and comprehensive reviews of our processes and controls.
For any inquiries regarding information security or to report security vulnerabilities, please contact us at: security@precise-int.com
Last updated: 01.08.2025