Reference 02
Local is a data boundary, not a compliance shortcut.
The architecture is designed to keep matter processing inside the firm's environment. A secure deployment still requires identities, physical controls, backups, incident procedures, contracts, and a firm-specific risk analysis.
Authority review: August 12, 2026. State rules, local rules, contracts, and matter facts still require firm-specific review.
Important boundary
Under Seal is software, not a law firm, auditor, records custodian, or compliance certification. Local deployment reduces particular disclosure and vendor-access risks. It does not by itself satisfy professional-conduct rules, HIPAA, state privacy law, trust-account rules, discovery duties, court orders, or a firm's own policies.
Data-path controls
Matter intake
Firm-controlled storage
Checksums, page counts, immutable originals, named matter, and explicit coverage state.
Inference
Loopback interface
The product client refuses a non-loopback model host. No hosted-model fallback is part of the core path.
Index and derived data
Firm-controlled storage
Text, vectors, page locators, receipts, and review decisions remain associated with one local matter store.
Support
No matter content by default
Support artifacts must be redacted and firm-initiated. Remote access requires a separately approved procedure.
Updates
Offline signed control; production procedure pending
Pinned-key signature verification, exact payload hashes, compatibility refusal, immutable staging, verified next-launch activation, receipts, and rollback have passed a synthetic local drill. Independent key custody, production packaging, vulnerability review, customer notice, and target-hardware rollback remain release gates.
Backup and recovery
Authenticated local format; firm procedure pending
Encrypted backup, tamper and wrong-password refusal, and restore to a new workspace have passed a synthetic local drill. Destination, retention, key custody, access, destruction, and observed recovery must still be configured and tested for the firm.
HIPAA boundary
A law firm is not automatically regulated by HIPAA merely because a matter contains medical records. A lawyer providing services to a covered entity can be a business associate, and a vendor with access to that protected health information can create additional obligations. Under Seal's software-only, no-access model is intended to reduce vendor access, but the parties and contract still determine the legal analysis. Medical files also require a separate data-classification check for substance-use-disorder records governed by 42 CFR Part 2; HIPAA analysis alone is not sufficient for that material.
Claims we do not make
- Not “HIPAA certified.” HHS does not award that label to this product.
- Not compliant with every state privacy or breach law by default.
- Not a determination that HIPAA, 42 CFR Part 2, or another health-record confidentiality regime does or does not apply.
- Not secure merely because a computer sits inside an office.
- Not air-gapped unless the deployed environment is actually configured and verified that way.
Authorities and frameworks
U.S. Department of Health and Human Services
The HIPAA Security Rule
Administrative, physical, and technical safeguards for electronic protected health information when HIPAA applies.
Opens the issuing source in a new tab.U.S. Department of Health and Human Services
Business Associates
Explains when legal and data-processing services can create business-associate duties and written-assurance requirements.
Opens the issuing source in a new tab.U.S. Department of Health and Human Services
42 CFR Part 2 Final Rule Fact Sheet
Explains federal confidentiality requirements for covered substance-use-disorder patient records and the February 16, 2026 compliance date.
Opens the issuing source in a new tab.U.S. Department of Health and Human Services
Understanding Part 2
Current HHS overview of the confidentiality protections for covered substance-use-disorder patient records.
Opens the issuing source in a new tab.Electronic Code of Federal Regulations
42 CFR Part 2
Current codified text of the federal Part 2 regulations.
Opens the issuing source in a new tab.National Institute of Standards and Technology
AI Risk Management Framework
A voluntary framework for governing, mapping, measuring, and managing AI risk.
Opens the issuing source in a new tab.National Institute of Standards and Technology
Cybersecurity Framework 2.0
A voluntary security framework organized around Govern, Identify, Protect, Detect, Respond, and Recover.
Opens the issuing source in a new tab.National Institute of Standards and Technology
Secure Software Development Framework 1.1
The current final NIST SSDF baseline for integrating secure software-development practices into the lifecycle.
Opens the issuing source in a new tab.Federal Trade Commission
Start with Security: A Guide for Business
Guidance on testing security features, keeping software current, addressing vulnerabilities, and honoring security representations.
Opens the issuing source in a new tab.