Page content

Security & compliance

Security for firms that hold other people’s secrets.

A solicitor carries obligations that most buyers of new technology never meet. Your practising certificate and your professional indemnity cover depend on them. Qila means fortress. Every control on this page is one you can hold us to.

Our controls

What we commit to in writing.

ISO/IEC 27001 aligned controls

Our information security management system follows the ISO/IEC 27001 control set. Access control and supplier risk sit inside it. Incident response and business continuity sit there too. Certification is in progress and we will not call it finished.

EU data residency

Client data stays inside the EU. No model trains on your files. No transfer outside the EEA happens without an agreed lawful basis. Every sub-processor gives the same guarantee in contract.

Privilege stays with the firm

Access control runs at matter level. Permissions are set per user and every retrieval is logged. Nothing here weakens legal professional privilege.

GDPR accountability

Data protection impact assessments come as standard. Records of processing come with them. You get a signed data processing agreement before any work starts.

Penetration testing

Every environment holding your data is penetration tested before go-live. The testing repeats on a schedule. You get the remediation evidence in writing.

Your data on exit

Your data and your precedents are yours. We document the export and hand it over on request. The format is one your own systems can read.

Questions we always get

The answers your risk partner will ask for.

If your question is not here then ask it directly. We would rather have the awkward conversation early. An engagement is the wrong time to find out.

Your question for us
Who trains a model on our data?

No one. Every engagement carries a contractual ban on training with your data. The same clause covers fine-tuning and model improvement. Every sub-processor we use is held to the same ban in contract. You see those terms before you sign anything.

Where does our client data sit?

The EU only. Your documents and the indexes behind them stay inside the EU. Logs and backups sit there too. No transfer leaves the EEA without notice to you. We agree a lawful basis with you before anything moves.

How far along is your ISO/IEC 27001 certification?

We are aligned to ISO/IEC 27001. The certification work is under way and not finished. Our site will not say certified until an auditor signs it. You can ask for our control documentation at any point. The Statement of Applicability comes with it.

What protects legal professional privilege?

Access control sits at the matter and not at the firm. A fee earner sees only the files they are entitled to see. Each retrieval leaves a log entry. Your risk partner can read the log. No QILA staff member opens a client file without a written support request from you.

What comes back to us if we leave?

You get your files back in a usable format. The handover is documented. We delete our copies to an agreed schedule. Confirmation of deletion comes to you in writing. There is no lock-in clause and no charge for leaving.

What satisfies our professional indemnity insurer?

That is what the assurance stage is for. You get the penetration test report and the data flow documentation. The audit trail comes with them. Your insurer asks for exactly that pack. A client security questionnaire asks for the same.