Your clients' data, protected by design
A law firm handles the most sensitive things a person has: their assets, their immigration status, their family, their problems. Mandato was built treating that data as exactly what it is.
The security of legal software isn't a marketing checkbox: it's the condition for being able to use it at all. A firm that trusts its matters to a tool needs to know where that data lives, who can see it, and what happens the day something goes wrong.
This page answers that plainly, and takes care to separate what we already do from what we can't yet claim.
Nine commitments, no small print.
Data hosted in the EU
All of your firm's information is stored and processed in the European Union, in the Frankfurt region. It doesn't leave the European data space.
Encryption at rest (AES-256)
Data is encrypted at rest. The most sensitive credentials — mail tokens, integration keys — are additionally encrypted with AES-256-GCM in the application before they reach the database.
TLS in transit
Every connection between your browser and Mandato travels encrypted over TLS. Nothing sent or received moves in the clear.
Per-firm isolation
Every firm is an isolated tenant. Row-level security (RLS) stops one firm's query from ever reaching another firm's data, even when they share infrastructure.
Immutable audit trail
Sensitive actions are logged and can't be altered: who did what, on which matter and when. That includes every query to the AI.
GDPR by design
Mandato was designed under the GDPR, not retrofitted to it: data minimisation, data-subject rights and a data processing agreement available on every plan.
LOPDGDD
We comply with Spain's data-protection law (LOPDGDD) as well as the GDPR, with an eye on the specific duties of a firm practising in Spain.
Automatic backups
The platform runs automatic, encrypted backups of the database, so the firm's information can be restored.
SOC 2 / ISO 27001, in progress
We work to the SOC 2 and ISO 27001 controls as a framework. We are not certified yet, and we don't pretend to be: we say it as a goal, not a seal.
Where your data lives
Your firm's data is stored and processed on servers in the European Union, in the Frankfurt region. It is not transferred to the United States or outside the European Economic Area for ordinary operation.
The providers involved in delivering the service — the hosting, the AI model provider, the WhatsApp Business API provider — are named in the data processing agreement, with their role and their location. There are no hidden sub-processors.
- Storage and processing in the EU (Frankfurt).
- No transfer of data to the US in ordinary operation.
- Sub-processor list in the DPA, with role and location.
One firm never sees another
The biggest risk in a multi-firm system isn't an outside intruder: it's one firm's data appearing, by mistake, on another firm's screen. Mandato prevents that at the deepest layer, the database itself, with row-level security.
Every row of data belongs to a firm, and no query can return another firm's rows. It isn't a check the application could forget to run: it's a rule of the database itself, enforced on every read and every write.
- Row-level security (RLS) enforced in the database, not just the app.
- No mixing of data between firms, by design.
- Each user's access is limited to their firm and their role.
Everything is logged
When a sensitive piece of data is read, changed or shared, there's a record. The audit trail notes who took the action, on which matter and at what moment, and it can't be edited or deleted after the fact.
Artificial intelligence is no exception: every interaction with the AI is in that same log — who launched it, on which document and when — and your firm's data is not used to train models, neither ours nor the model provider's.
- Immutable trace of actions on sensitive data.
- Every AI query logged and attributed.
- Your documents don't train anyone's models.
What happens when something goes wrong
No serious provider promises an incident will never happen; what marks one out as serious is having a plan for when it does. Mandato maintains an incident-response process: detection, containment, scope assessment and notification where required.
If an incident affected personal data and were notifiable, the GDPR sets the timelines and the recipients, and we act accordingly. We'd rather describe the process than promise an invulnerability no one can guarantee.
- A documented incident-response process.
- Notification within the GDPR's timelines where required.
- Backups to restore the service.
Mandato is not certified today in ISO 27001 or SOC 2; we use those frameworks as a reference and work towards them, but we don't hang up a seal we don't have. We don't offer on-premise deployment: Mandato is a cloud service hosted in the EU. And the database's encryption at rest is provided by the hosting platform; the AES-256-GCM encryption we apply ourselves specifically protects the most sensitive credentials and integrations. We say it here so nobody has to guess.
Frequently asked questions
Where is my firm's data hosted?
On servers in the European Union, in the Frankfurt region. Your firm's information is not transferred to the United States or outside the European Economic Area for ordinary operation.
Is Mandato certified to ISO 27001 or SOC 2?
Not yet. We work to the ISO 27001 and SOC 2 controls as a reference framework and are working towards certification, but we don't claim to be certified while we aren't. When we are, we'll say so with the document that proves it.
Can Mandato staff see my firm's data?
Access is restricted and audited. Our team only accesses a firm's data when it's necessary to provide support and with the appropriate permission, and those accesses are logged. Your firm's data is not used to train AI models.
Do you sign a data processing agreement (DPA)?
Yes. Mandato acts as a data processor and the DPA is available on every plan, with the list of sub-processors, their role and their location. There's no need to negotiate a higher tier to get it.
What happens to my data if I stop using Mandato?
You can export your firm's data, and on cancellation it is deleted as agreed in the DPA and as the GDPR requires. Your data is yours: it isn't held hostage.