LockeResearch Companion

Security and data controls

The application uses authenticated, tenant-scoped case-file access and separates public research pages from private workspace routes.

Access controls

Private research routes require authentication. Case files, documents, research runs, exports, timelines, issues, and facts are checked against the authenticated user and firm before access.

Uploads

Uploads are type- and size-checked, stored under an application-controlled path, and processed for extraction before they are attached to a case file. The application does not treat a filename as a storage path.

Operational disclosure

Encryption at rest, backup retention, production personnel access, provider subprocessors, and incident-notification commitments are deployment and legal-policy facts. They should be documented from the actual production configuration rather than inferred from application code.