Legal
IT for Michigan law firms, where confidentiality is an ethical duty
Security controls that hold up against ABA Model Rules 1.1 and 1.6, secure client file exchange, and infrastructure designed so a technology failure never becomes a missed deadline.
Technology competence is not optional for you the way it is for other businesses
ABA Model Rule 1.1 Comment 8 established that competent representation includes understanding the benefits and risks of relevant technology. Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information. Together those create a professional obligation that sits on the attorney, not on the IT vendor.
Which means when we configure your environment we are not just protecting a business. We are supporting a duty you personally carry, and if something goes wrong the question asked will be whether reasonable efforts were made. Documentation of what you did and why becomes the answer to that question.
The practical side has two pressure points. First, client file exchange, because emailing documents to clients and opposing counsel is still routine in most firms and is the least defensible habit in the profession. Second, deadlines. Courts are unsympathetic to server problems, and a filing system that goes down the afternoon before a deadline is a malpractice conversation rather than an IT ticket.
We also handle the conflict-adjacent technical work most providers never consider: ethical walls enforced at the permission level so a screened attorney genuinely cannot access a matter, rather than being asked politely not to.
What goes wrong without the right setup
- Client confidential documents sitting in email inboxes and sent folders indefinitely, discoverable and unencrypted
- An ethical wall that exists as a policy memo while the file permissions allow full access
- A document management outage the afternoon before a filing deadline with no tested recovery path
- Business email compromise where an attacker in a firm mailbox redirects a settlement wire
- An unencrypted laptop with client files lost at a courthouse or airport
- A departed associate retaining access to the document system for months
Built for firm operations
Compliance
Ethical and practical obligations we build around
Reasonable efforts under Rule 1.6(c)
Documented security controls proportionate to the sensitivity of client information, so reasonable efforts is a demonstrable position rather than an assertion.
Ethical walls at the permission layer
Matter-level access restrictions technically enforced, so a screened attorney cannot reach conflicted files even accidentally. Policy alone is not a control.
Secure client file exchange
An encrypted portal replacing email attachments, with access logging that shows who downloaded what and when if it is ever questioned.
Deadline-protective architecture
Redundancy and recovery objectives set on the assumption that a filing deadline could be tomorrow, because it often is.
Litigation hold and retention
Retention configured per matter type, with legal hold capability that preserves data properly when preservation obligations attach.
Departing attorney procedures
Documented access removal and file transition, which matters both ethically and practically when a partner leaves and takes a book of business.
Andrew is wonderful. He is knowledgeable, professional, and caring. I would recommend him for any IT needs.
Questions
Legal IT questions
Does a cyber incident create an ethics problem, not just a business one?
It can. Rule 1.6 covers confidentiality, and the question after an incident is whether reasonable efforts had been made to prevent unauthorized disclosure. There may also be a duty to notify affected clients depending on circumstances, separate from Michigan breach notification law. This is genuinely why documentation matters more in your profession than most: it converts reasonable efforts from a claim into a record.
Is email actually inadequate for client documents?
Email is not inherently prohibited, and the ABA has addressed this in Formal Opinion 477R, which concluded that reasonable efforts may require more than unencrypted email depending on the sensitivity of the information. For routine scheduling, email is fine. For medical records in a personal injury matter, financial disclosures in a divorce, or anything a client would be harmed by seeing exposed, a portal is the defensible choice and it is not a difficult change to make.
How do you handle conflicts and ethical walls technically?
Matter-level permissions in your document management system and file shares, enforced so a screened attorney's account has no read access to conflicted material. We also log access attempts. The important distinction is that this is a technical control rather than a request, which means it holds up if it is ever examined.
What if our document management system goes down before a filing?
That scenario drives the design rather than being handled after the fact. Document management and time and billing get the highest recovery tier, with tested restores and a documented path to get a specific matter's files back fast rather than waiting on a full system recovery. We also keep a written emergency procedure, because the answer to a deadline cannot be that recovery is in progress.
Can you support Clio, MyCase, or our practice management platform?
Yes, including the cloud platforms. With cloud practice management the work shifts to identity, endpoint, and email security, because that is where the actual exposure lives once the data is in the vendor's infrastructure. For on-premise systems like ProLaw we handle the database backup properly, which requires application-aware jobs rather than file copies.
We are a four-attorney firm with two staff. Do we qualify?
Six people total, so yes. Our minimum is five employees regardless of how they split between attorneys and staff. Firms in the five to thirty range are a good fit for us, and honestly are the ones most often underserved, because they carry full ethical obligations without the budget for an internal IT director.
Want a second opinion on where you stand?
The assessment scores your environment against the requirements that apply to you specifically, and the written report is yours to keep either way.
No pressure, no obligation. If we are not the right fit we will tell you and point you somewhere better.