Security & Compliance

Your clients' data
is safe. Full stop.

PI attorneys have ethical obligations around client data. PIM was built with security at the foundation — not bolted on after the fact.

HIPAA Ready
AES-256 Encrypted
BAA Available
Role-Based Access
HIPAA Ready
Encrypted
Role-Based
BAA Available
HIPAA Ready
Data Encrypted
Role-Based Access
Zero Data Selling
Secure Auth
Audit Logging
HIPAA

Built to meet your ethical obligations

PI attorneys handle protected health information every day. HIPAA compliance isn't optional for your firm, and it isn't optional for us.

We can execute a Business Associate Agreement (BAA) with your firm upon request.

Business Associate Agreement

Available upon request at no additional cost

Contact us at support@picasemachine.com to request a BAA before or after onboarding.

PHI handled in compliance with HIPAA requirements

Business Associate Agreements available upon request

Access controls limit who can view sensitive medical records

Audit logging tracks all access to protected client records

Data minimization — we only collect what is necessary

Data Security

Multiple layers of protection

🔐

AES-256 Encryption

All data encrypted at rest using AES-256. All data in transit protected by TLS 1.2+. Your case files and client records are never exposed in plain text.

Data in transit

Your Browser

PIM Server

TLS 1.2+ · AES-256
🏢

Firm-Level Isolation

Your firm's data is completely isolated from every other firm on the platform. Row-level security means one firm can never access another firm's cases or clients.

Firm isolation

Your Firm

Cases
Leads
Clients

Other Firm

Cases
Leads
Clients

Row-level security — zero cross-firm access

📋

Audit Logging

Every action in PIM is logged — who accessed what, when, and from where. Full audit trails available for compliance review and incident investigation.

Audit trail

C. WebbViewed case #28472s ago
M. TorresUploaded police report1m ago
C. WebbSent demand letter4m ago
J. ParkAdded case note12m ago
🔑

Secure Authentication

Industry-standard auth with session management, token expiration, and brute force protection. MFA available for all accounts.

Encryption layers

Client Data
TLS 1.2+
AES-256
Secure Storage
🛡️

Role-Based Access

Attorneys, paralegals, and case managers each operate within their own permission level. No one sees more than they need to.

Role-based permissions

Admin
All CasesAll LeadsBillingSettingsUsers
Attorney
My CasesMy LeadsNotesDocuments
Paralegal
Assigned CasesDocumentsNotes
Case Manager
Assigned CasesTasksTimeline
☁️

Secure Cloud Infrastructure

Enterprise-grade cloud infrastructure with 99.9% uptime SLA, automated backups, and redundant systems.

Uptime SLA99.9%
30 daysToday
Data Privacy

Your data is yours.
We never sell it.

PIM does not sell, share, or monetize your firm's data. We do not use your case data to train AI models. We do not share your information with advertisers.

When you leave PIM, your data leaves with you. Full export available on request.

🚫

Never sold

Your data is never sold to any third party, ever.

📵

No ads

Never used for advertising targeting or profiling.

🤖

No AI training

We do not train AI models on your case data.

📦

Full export

Request all your firm data at any time.

Attorney Ethics

Designed with bar obligations in mind

State bar rules require attorneys to take reasonable measures to protect client confidentiality. PIM was designed to meet that standard.

ABA Model Rule 1.6

Confidentiality of Information

PIM uses encryption, access controls, and secure infrastructure to protect client confidences as required.

ABA Model Rule 1.1

Competence

Using secure, purpose-built technology is part of competent representation. PIM keeps your practice current.

HIPAA

Protected Health Information

Medical records and PHI handled in compliance with HIPAA. BAA available upon request at no additional cost.

Questions about security?

We're happy to walk through our security practices, provide documentation, or execute a BAA. Reach out any time.