Your clients' data, protected by design
A law firm handles the most sensitive things a person has: their assets, their immigration status, their family, their problems. Mandato was built treating that data as exactly what it is.
The security of legal software isn't a marketing checkbox: it's the condition for being able to use it at all. A firm that trusts its matters to a tool needs to know where that data lives, who can see it, and what happens the day something goes wrong.
This page answers that plainly, and takes care to separate what we already do from what we can't yet claim.
Twelve commitments, no small print.
Data hosted in the EU
Matters, documents and user accounts live in the European Union: the database in Ireland, and the application that serves it in Amsterdam. In the EU, not in Spain — we put it that way because that is the question a Spanish firm asks.
Encryption at rest (AES-256)
Data is encrypted at rest. The most sensitive credentials — mail tokens, integration keys — are additionally encrypted with AES-256-GCM in the application before they reach the database.
TLS in transit
Every connection between your browser and Mandato travels encrypted over TLS. Nothing sent or received moves in the clear.
Per-firm isolation
Every firm is an isolated tenant. Row-level security (RLS) stops one firm's query from ever reaching another firm's data, even when they share infrastructure.
Immutable audit trail
Sensitive actions are logged and can't be altered: who did what, on which matter and when. That includes every query to the AI.
A real password floor
Ten characters, with an upper case, a lower case and a digit, and a strength meter on the form itself. The same rule is enforced in the browser and on the server.
Two-step verification
Each user can protect their account with a TOTP second factor — the six-digit code from an authenticator app — on top of the password. Access is then tied to the verified device.
Retention on legal clocks
Data is kept as long as the law requires and no longer: ten years for the Ley 10/2010 file, six for tax records, and the rest on the window your firm sets.
GDPR by design
Mandato was designed under the GDPR, not retrofitted to it: data minimisation, data-subject rights and a data processing agreement available on every plan.
LOPDGDD
We comply with Spain's data-protection law (LOPDGDD) as well as the GDPR, with an eye on the specific duties of a firm practising in Spain.
Automatic backups
The platform runs automatic, encrypted backups of the database, so the firm's information can be restored.
ISO 27001, in preparation
We have begun preparing for ISO 27001 certification with outside support. We are not certified yet and there is no audit date: we will call it a certification the day we hold the certificate, and not before.
Where your data lives
It is worth being specific, because "in the EU" can mean a great many things. Your firm's database — the matters, the documents and the user accounts — is in Ireland, in the AWS eu-west-1 region used by our managed database provider. The application that queries it runs in Amsterdam. Both inside the European Union; neither one in Spain.
That distinction matters and we are not hiding it: if your firm needs residency on Spanish soil, Mandato does not offer it today. What it does offer is European residency, with the database and the hosting contracted from providers who guarantee it contractually.
The whole chain stays in the EU, and that is the part worth examining closely in any vendor: the database in Ireland, the application in Amsterdam, transactional email in our sending provider's European region, and the WhatsApp integration through a German provider. Messaging is where competitors' European promises usually break, which is why we name it separately.
What does leave the European Economic Area is part of the AI processing, and it is identified one by one in the data processing agreement: the medium and high complexity models process in the United States under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. There is a European AI provider the routine tier can be routed to. One further distinction almost nobody draws: hosting in the EU and contracting with a European entity are not the same thing — our email provider operates in a European region but its contracting entity is American, so the transfer remains covered by Standard Contractual Clauses. That is how it appears in the DPA. There are no hidden sub-processors: each is listed with its role and its location.
- Database and documents in Ireland; application in Amsterdam. Both in the EU.
- Transactional email in a European region; WhatsApp, through a German provider.
- European residency, not Spanish: we say so before you have to ask.
- The US transfers that do exist — medium and high complexity AI — are in the DPA, with their legal basis.
- Sub-processor list in the DPA, with role and location.
One firm never sees another
The biggest risk in a multi-firm system isn't an outside intruder: it's one firm's data appearing, by mistake, on another firm's screen. Mandato prevents that at the deepest layer, the database itself, with row-level security.
Every row of data belongs to a firm, and no query can return another firm's rows. It isn't a check the application could forget to run: it's a rule of the database itself, enforced on every read and every write.
- Row-level security (RLS) enforced in the database, not just the app.
- No mixing of data between firms, by design.
- Each user's access is limited to their firm and their role.
AI, and the «EU-only» mode
Mandato uses language models to analyse documents, draft replies, summarise meetings and classify email. It is worth knowing where each of those goes, because they do not all go to the same place.
Routine work — drafts, summaries, classification — is served by a light model. Medium and high complexity work, and document analysis, go to Anthropic's Claude models, which process in the United States under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
Any firm can turn on «EU-only» mode in its settings. With it on, the routine tier stops leaving for the United States and is served by a European provider on models hosted in the EU. We are deliberately precise about its scope: it moves the routine tier, not the whole of the processing. Medium and high complexity work stays on Claude, and telling you otherwise would be selling you a guarantee the product does not give.
Whichever model handles it, every AI query lands in the immutable audit log: which matter, which user, when.
- «EU-only» mode is switched on per firm, from Settings.
- It moves the routine tier to a European provider; medium and high complexity stays on Claude (US, under SCC).
- With the mode on, the firm's sub-processor register stops including the US provider for that tier.
- Every AI query is logged, with model, user and matter.
Who gets into the account
The password on a Mandato account is not guarding a shopping list. From the first login it guards names, NIE and passport numbers, documents and matter detail covered by Ley 10/2010 and the GDPR. Which is why the floor is not the usual eight characters.
Sign-up requires at least ten characters, with an upper case, a lower case and a digit, and the form shows a strength meter and the live requirement list as you type — to push past the minimum, not to reward scraping over it. The rule lives in one place in the code and is enforced in the browser and on the server, so neither half can be relaxed without the other.
From there, each user reaches only their own firm's data and only what their role allows, and everything they do lands in the audit log.
- A ten-character minimum, with upper case, lower case and a digit.
- Strength meter and requirements visible on the sign-up form itself.
- The same rule enforced in the browser and on the server, from a single definition.
Everything is logged
When a sensitive piece of data is read, changed or shared, there's a record. The audit trail notes who took the action, on which matter and at what moment, and it can't be edited or deleted after the fact.
Artificial intelligence is no exception: every interaction with the AI is in that same log — who launched it, on which document and when — and your firm's data is not used to train models, neither ours nor the model provider's.
- Immutable trace of actions on sensitive data.
- Every AI query logged and attributed.
- Your documents don't train anyone's models.
How long data is kept
“Delete this client” is not an instruction a Spanish firm can simply carry out. Several statutes impose minimum retention periods on what that client generated, counting from the end of the relationship: ten years for the Ley 10/2010 due-diligence file (art. 25), and six for accounting and invoicing records (art. 66 LGT and art. 30 of the Commercial Code).
Mandato carries those periods as rules rather than as good intentions. Each firm sets its own general window — the professional-liability one — and the legal minimums can be raised but never taken below their floor.
When a deletion is requested for a client whose file is still inside a mandatory period, the correct answer is not to erase but to anonymise: strip the personal data, keep the record the law requires you to keep. The tool names which obligation is holding it and until when. A matter that is still open holds for as long as it stays open, for obvious reasons.
- Ten years for the Ley 10/2010 file (art. 25).
- Six years for accounting and invoicing records (art. 66 LGT, art. 30 Commercial Code).
- A general window your firm configures, never below the legal minimum.
- Anonymisation instead of deletion while an obligation to keep still runs, with the reason and the date in plain sight.
What happens when something goes wrong
No serious provider promises an incident will never happen; what marks one out as serious is having a plan for when it does. Mandato maintains an incident-response process: detection, containment, scope assessment and notification where required.
If an incident affected personal data and were notifiable, the GDPR sets the timelines and the recipients, and we act accordingly. We'd rather describe the process than promise an invulnerability no one can guarantee.
- A documented incident-response process.
- Notification within the GDPR's timelines where required.
- Backups to restore the service.
Frequently asked questions
Where is my firm's data hosted?
In the European Union: the database and documents in Ireland, and the application that serves them in Amsterdam. In the EU, but not in Spain — if your firm needs residency on Spanish soil, we don't offer it today. Some AI processing and email delivery do take place in the United States, under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework; the DPA identifies them one by one.
Is Mandato certified to ISO 27001 or SOC 2?
Not yet. We have begun preparing for ISO 27001 certification with outside support, but no audit has started and no date is committed, and we would rather say that than write “certified”. There are no plans for SOC 2 today: in the European market ISO 27001 is the one buyers ask for. If your firm needs the certificate in order to sign with us, tell us — that is exactly the signal that sets the pace, and we'll give you a real date as soon as there is one.
Can Mandato staff see my firm's data?
Access is restricted and audited. Our team only accesses a firm's data when it's necessary to provide support and with the appropriate permission, and those accesses are logged. Your firm's data is not used to train AI models.
Can I see who has opened a matter?
Yes. The audit log records accesses and actions on sensitive data — who, on which matter and when — and it cannot be edited or deleted after the fact, which is the only property that makes an access log worth having. It includes every AI query. For matters marked confidential, access is also by name: only the lawyer carrying it, management and anyone given express permission gets in.
Do you sign a data processing agreement (DPA)?
Yes. Mandato acts as a data processor and the DPA is available on every plan, with the list of sub-processors, their role and their location. There's no need to negotiate a higher tier to get it.
If a client asks me to delete their data, can I?
It depends on what the law obliges you to keep, and Mandato checks before it deletes anything. Ley 10/2010 due-diligence documentation is kept for ten years and accounting and invoicing records for six, counting from the end of the relationship; your firm also sets its own general window. While any of those clocks is still running, the right move is to anonymise — strip the personal data, keep the record you are required to keep — and the tool tells you which obligation is holding it and until when.
What happens to my data if I stop using Mandato?
You can export your firm's data, and on cancellation it is deleted as agreed in the DPA and as the GDPR requires. Your data is yours: it isn't held hostage.
Service status, in public
We publish the state of every Mandato component — application, database and documents, email, WhatsApp, public-administration notifications and AI — with its measured availability history and the incident log, updated with timestamps while things are happening. The page is checked every five minutes and served from infrastructure separate from the application, so it stays up when the application does not. It is not a service level commitment: it reports, it does not promise.
