Skip to content
Atlas
GET IN TOUCH

INDUSTRIESI08Legal

Privilege is not
a setting.

IT for law firms and legal practices. Confidentiality is the product, the trust account is audited, and the deadlines are set by a court rather than by you. The technology has to be arranged accordingly.

The four sentences we hear most in your sector.

  • 01
    A matter file is spread across the PMS, email, and a network drive.

    Which makes finding everything relevant to a matter a manual exercise, and makes answering a discovery or a complaint slower than it should be.

  • 02
    Our trust account controls rely on two people remembering.

    They are also the two people who are busiest. Controls that depend on memory fail on the day it matters.

  • 03
    Conveyancing settlement day is not negotiable.

    Landonline, the bank, and the other side are all on a clock. An outage that morning is a professional problem, not an IT one.

  • 04
    We are a target for payment redirection fraud.

    Law firms hold settlement funds and communicate bank details by email. Attackers know both of those things.

The systems you actually run.

Not a list of logos. These are the platforms we support, migrate, and get called about in this sector. If yours is missing, it usually means we have not worked with it, and we will say so rather than nod along.

Bring one group of systems forward
  • Practice management

    Matters, time, billing, and trust in one place. Downtime here stops the firm rather than one person.

    • Actionstep
    • LEAP
    • Infinitylaw
    • Smokeball
    • Clio
    • Time Matters
  • Document and email management

    Where privilege is actually protected, and where most firms have the least deliberate structure.

    • NetDocuments
    • iManage
    • SuiteFiles
    • SharePoint
    • Microsoft 365
    • Worldox
  • Conveyancing and registries

    External systems with their own requirements and their own very fixed deadlines.

    • LINZ Landonline
    • e-dealing
    • Court electronic filing
    • Companies Office
    • PPSR
  • Trust accounting and verification

    Audited, regulated, and the area where a control failure has consequences well beyond IT.

    • Trust accounting modules
    • Bank integrations
    • Electronic identity verification
    • AML screening
    • Secure payment confirmation

Four things we do for legal specifically.

  1. 01

    One matter, one file

    Documents and email filed against the matter rather than scattered across inboxes and drives, with access by role. It makes everyday work faster and it makes a discovery request, an audit, or a complaint answerable rather than archaeological.

  2. 02

    Payment redirection made hard

    Domain authentication and email security so nobody can send mail appearing to come from your firm, plus a verification step in your settlement process that does not bend under time pressure. Firms that hold that line rigidly almost never lose funds this way.

  3. 03

    Uptime on the days that matter

    Connectivity with failover, tested restores, and a written plan for what happens on a settlement morning when something fails. Maintenance never scheduled anywhere near a settlement or filing deadline.

  4. 04

    Confidentiality you could defend

    Access by role, logging so access can be reviewed, encryption on every device, and a leaver process that removes everything at once. If you were asked who could have seen a particular matter file, you should be able to answer.

The obligations that shape the work.

We make the systems match your obligations. We are not your lawyer or your compliance adviser, and where a question turns on interpretation we will tell you to take advice rather than guess on your behalf.

  • Lawyers and Conveyancers Act and Law Society rules

    Client confidentiality, conflict management, file retention, and trust account rules all carry direct technology consequences, particularly around access control, record keeping, and retention.

  • AML/CFT Act 2009

    Law firms have been captured since the phase two extension, which brings customer due diligence, record keeping, and suspicious activity reporting duties. The records duty is a retention and retrievability problem.

  • Privacy Act 2020

    Applies to personal information in client files alongside your confidentiality obligations, including mandatory notification of a privacy breach causing serious harm.

  • Legal professional privilege

    Not a technical control, but the reason the technical controls matter. Where privileged material sits, who can reach it, and what an attacker could have seen are all questions with professional consequences.

Per user, per month

Priced per user per month, which matches how a firm thinks about fee earner and support staff costs. Practice management migrations, document restructures, and office moves are quoted as projects. As with any firm that bills time, the comparison worth making is against the hours your people currently lose rather than against another provider’s monthly rate.

Questions from your sector

01How do law firms prevent payment redirection fraud on settlements?

With two layers. Technically, domain authentication and email security so nobody can convincingly send mail as your firm and targeted messages are caught. Procedurally, and this is the one that actually stops the loss, every set of bank details is verified by phone on a number obtained independently, never one taken from the email, and that rule holds even on a settlement morning when everyone is under pressure. The attacks work precisely because they arrive at the moment nobody wants to add a step.

02Where should matter documents and emails live?

Filed against the matter in one system, whether that is your practice management platform, a dedicated document management system such as NetDocuments or iManage, or SuiteFiles and SharePoint for a smaller firm. The critical part is that email is filed there too. An email sitting only in a fee earner’s inbox is invisible to everyone else and is the reason matter files turn out to be incomplete.

03What does AML/CFT mean for our systems?

Mostly it turns into a records problem. You must retain customer due diligence records and be able to produce them years later, which means retention applied automatically, storage that cannot be quietly altered, and a log of who accessed what. Most firms have collected the information. Fewer can retrieve it quickly and demonstrate it has not changed. Your compliance officer owns the interpretation, we make the systems match it.

04Can you support us through a settlement morning?

Yes, and it should be arranged in advance rather than hoped for. That means no maintenance anywhere near settlement dates, connectivity with automatic failover so a fibre fault does not stop you, and a written fallback for Landonline and banking access. Firms that plan this treat a failure as an inconvenience. Firms that do not treat it as a crisis.

05How do we know who has accessed a confidential matter file?

Only if access is by role and logging is switched on and retained, which are both configuration decisions made long before anyone asks. The common failure is shared logins and broad access granted because it was simpler, which means after an incident you cannot narrow the answer at all. Getting this right is cheap in advance and impossible to retrofit after the fact.

06Should a small firm use cloud practice management?

Usually yes. Cloud platforms such as Actionstep, LEAP, and Clio remove the server, handle their own updates, and work from anywhere, which suits a small firm far better than maintaining infrastructure. The trade-off is that your connection becomes critical, so failover matters more, and you still need your own backup rather than assuming the vendor is your recovery plan.

Start with the matter file.

If everything relevant to a matter cannot be found in one place in under a minute, that is where we would begin, and it is the change your fee earners will feel first.

← All industries