{"industry":{"id":"a7b3fdc7-1217-4f39-8fc5-2e8e3f73c3d7","slug":"legal-technology","label":"Legal Technology","description":"Practice management, e-discovery, and compliance"},"topic":{"slug":"immigration-law-software","label":"Immigration Law Software","description":"Case management, USCIS form automation, client intake, billing, and security for immigration law firms and nonprofit legal aid programs.","schemaKind":null},"answer":{"id":"af1fae7b-011b-407a-8421-f921930b0660","slug":"what-security-features-should-immigration-case-management-software-have","question":"What security features should immigration case management software have?","answerMarkdown":"Immigration case management software should enforce encryption of data at rest and in transit, administrator-enforced multi-factor authentication with single sign-on, a stated tenant isolation model, role-based permissions with exportable audit logs, geo-redundant backups with a defined recovery point, independent penetration testing, and contractual rights covering data export, deletion, and breach notification [6][7][9]. The bar is set by ABA Model Rule 1.6(c), which requires a lawyer to \"make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client\" [1]. Comment 18 makes that a fact-based test in which the sensitivity of the information is the first factor, and an immigration file carries a Social Security number, a passport number, an A-Number, financial history, and the sealed medical examination USCIS requires with an adjustment application [1][4]. Because the duty extends to the vendors a firm hires, ABA Formal Opinion 477R tells lawyers to conduct due diligence on technology vendors under Model Rule 5.3, which means asking every vendor the same written questions and keeping the answers [1]. The risk is documented: in an April 2026 notice to affected individuals, one immigration platform reported that an unauthorized actor used valid credentials to clone third-party repositories, exposing Social Security numbers, passport numbers, and medical condition or treatment information [11].","answerText":"Immigration case management software should enforce encryption of data at rest and in transit, administrator-enforced multi-factor authentication with single sign-on, a stated tenant isolation model, role-based permissions with exportable audit logs, geo-redundant backups with a defined recovery point, independent penetration testing, and contractual rights covering data export, deletion, and breach notification [6][7][9]. The bar is set by ABA Model Rule 1.6(c), which requires a lawyer to \"make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client\" [1]. Comment 18 makes that a fact-based test in which the sensitivity of the information is the first factor, and an immigration file carries a Social Security number, a passport number, an A-Number, financial history, and the sealed medical examination USCIS requires with an adjustment application [1][4]. Because the duty extends to the vendors a firm hires, ABA Formal Opinion 477R tells lawyers to conduct due diligence on technology vendors under Model Rule 5.3, which means asking every vendor the same written questions and keeping the answers [1]. The risk is documented: in an April 2026 notice to affected individuals, one immigration platform reported that an unauthorized actor used valid credentials to clone third-party repositories, exposing Social Security numbers, passport numbers, and medical condition or treatment information [11].","answerHtml":"<p>Immigration case management software should enforce encryption of data at rest and in transit, administrator-enforced multi-factor authentication with single sign-on, a stated tenant isolation model, role-based permissions with exportable audit logs, geo-redundant backups with a defined recovery point, independent penetration testing, and contractual rights covering data export, deletion, and breach notification <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a><a href=\"https://get.eimmigration.com/blog/the-case-for-secure-immigration-software\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a><a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>. The bar is set by ABA Model Rule 1.6(c), which requires a lawyer to &quot;make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client&quot; <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Comment 18 makes that a fact-based test in which the sensitivity of the information is the first factor, and an immigration file carries a Social Security number, a passport number, an A-Number, financial history, and the sealed medical examination USCIS requires with an adjustment application <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a><a href=\"https://www.uscis.gov/i-485\" class=\"citation-ref\" data-citation-index=\"4\" target=\"_blank\" rel=\"noreferrer\">[4]</a>. Because the duty extends to the vendors a firm hires, ABA Formal Opinion 477R tells lawyers to conduct due diligence on technology vendors under Model Rule 5.3, which means asking every vendor the same written questions and keeping the answers <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. The risk is documented: in an April 2026 notice to affected individuals, one immigration platform reported that an unauthorized actor used valid credentials to clone third-party repositories, exposing Social Security numbers, passport numbers, and medical condition or treatment information <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>.</p>\n","summary":"An immigration file holds a Social Security number, a passport number, an A-Number, financial history and a sealed medical exam, so the confidentiality rule sets the security bar well above a vendor feature list. Eleven requirements, each paired with the proof to demand in writing, cover encryption, authentication, tenant isolation, audit logs, backups, independent testing, export rights and breach-notice terms. Includes what two vendors publish, and what an April 2026 vendor incident should change in a contract.","publishedAt":"2026-07-23T18:41:00","verifiedAt":"2026-07-23T00:00:00","editorialStatus":"APPROVED","lastReviewedAt":"2026-07-23T00:00:00","nextReviewDueAt":"2026-10-23T00:00:00","templateVersion":"v2","aliases":["What should immigration firms look for in case management software security?","Immigration case management software security checklist","What security questions should you ask an immigration software vendor?","Does immigration case management software need SOC 2?","Is immigration case management software HIPAA or GDPR compliant?","How do immigration firms meet ABA Rule 1.6(c) with cloud software?","What encryption should immigration software use?","Should immigration case management software have multi-factor authentication?","What breach notification terms should be in an immigration software contract?","Single-tenant vs multi-tenant immigration case management software","How do you vet a legal tech vendor's security claims?","Immigration legal aid case management software security requirements"],"confidenceScore":91,"confidenceLabel":"High","canonicalUrl":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"contributorOrganizationProfile":{"entityId":"ec39deab-44fe-48d8-9029-fefe993ab85a","legalName":null,"description":null,"websiteUrl":null,"imageUrl":null,"slogan":null,"subtitle":null,"facts":[],"coiNote":null,"foundingDate":null,"numberOfEmployeesText":null,"contactPoint":null,"address":null,"headquartersText":null,"organizationType":null},"contributorPerson":{"slug":"answerstack-editorial-team","displayName":"AnswerStack Editorial Team"},"sections":[{"id":"e52b4eda-1978-402d-bbe4-346c207b39d0","sectionKey":"why_the_bar_is_higher","sectionType":"markdown_section","heading":"Why does immigration case data sit at the top of the sensitivity scale?","introMarkdown":"A single adjustment of status package concentrates almost every category of regulated personal data in one record. USCIS instructs that \"When you file Form I-485, you must also submit Form I-693, Report of Immigration Medical Examination and Vaccination Record,\" and applicants filing online must open the civil surgeon's sealed envelope and upload that medical form with the package [4]. The same file carries the client's A-Number, identity documents, and financial records [4]. In immigration court, EOIR's electronic filing system has been mandatory since February 11, 2022, and registered attorneys use it to file documents and download electronic records of proceedings [5]. One login to a case management system therefore opens a client's full identity record, and often a family's.\n\n### What the confidentiality rule requires\n\nModel Rule 1.6(c) states that \"A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client\" [1]. Comment 18 names no specific technology and instead lists non-exclusive factors: the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of those safeguards, and the extent to which they would adversely affect the lawyer's ability to represent clients [1]. Sensitivity leads that list, which puts an immigration practice at a higher setting than a general commercial firm.\n\n### The duty follows the data to the vendor\n\nBuying software is a supervision decision. Opinion 477R instructs lawyers to \"Conduct Due Diligence on Vendors Providing Communication Technology,\" because Model Rule 5.3 requires reasonable efforts to ensure a nonlawyer's conduct is compatible with the lawyer's professional obligations [1]. Colorado holds that \"A lawyer must make reasonable efforts to prevent, monitor for, halt, and investigate any security breach of data the lawyer controls\" [2], and California requires \"a reasonable inquiry to determine the extent and consequences of the breach\" plus notice to any client whose interests have a reasonable possibility of being negatively impacted [3].","introHtml":"<p>A single adjustment of status package concentrates almost every category of regulated personal data in one record. USCIS instructs that &quot;When you file Form I-485, you must also submit Form I-693, Report of Immigration Medical Examination and Vaccination Record,&quot; and applicants filing online must open the civil surgeon&#39;s sealed envelope and upload that medical form with the package <a href=\"https://www.uscis.gov/i-485\" class=\"citation-ref\" data-citation-index=\"4\" target=\"_blank\" rel=\"noreferrer\">[4]</a>. The same file carries the client&#39;s A-Number, identity documents, and financial records <a href=\"https://www.uscis.gov/i-485\" class=\"citation-ref\" data-citation-index=\"4\" target=\"_blank\" rel=\"noreferrer\">[4]</a>. In immigration court, EOIR&#39;s electronic filing system has been mandatory since February 11, 2022, and registered attorneys use it to file documents and download electronic records of proceedings <a href=\"https://www.justice.gov/eoir/ECAS\" class=\"citation-ref\" data-citation-index=\"5\" target=\"_blank\" rel=\"noreferrer\">[5]</a>. One login to a case management system therefore opens a client&#39;s full identity record, and often a family&#39;s.</p>\n<h3>What the confidentiality rule requires</h3>\n<p>Model Rule 1.6(c) states that &quot;A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client&quot; <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Comment 18 names no specific technology and instead lists non-exclusive factors: the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of those safeguards, and the extent to which they would adversely affect the lawyer&#39;s ability to represent clients <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Sensitivity leads that list, which puts an immigration practice at a higher setting than a general commercial firm.</p>\n<h3>The duty follows the data to the vendor</h3>\n<p>Buying software is a supervision decision. Opinion 477R instructs lawyers to &quot;Conduct Due Diligence on Vendors Providing Communication Technology,&quot; because Model Rule 5.3 requires reasonable efforts to ensure a nonlawyer&#39;s conduct is compatible with the lawyer&#39;s professional obligations <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Colorado holds that &quot;A lawyer must make reasonable efforts to prevent, monitor for, halt, and investigate any security breach of data the lawyer controls&quot; <a href=\"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a>, and California requires &quot;a reasonable inquiry to determine the extent and consequences of the breach&quot; plus notice to any client whose interests have a reasonable possibility of being negatively impacted <a href=\"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":10},{"id":"4c22659e-4d19-4de9-9061-1165df72ceaa","sectionKey":"requirements_table","sectionType":"table_section","heading":"Which security features belong on the requirement list?","introMarkdown":"Eleven requirements cover the ground for a US immigration practice. The third column matters more than the second, because a vendor can say yes to every feature and still leave you nothing you could show a disciplinary counsel.","introHtml":"<p>Eleven requirements cover the ground for a US immigration practice. The third column matters more than the second, because a vendor can say yes to every feature and still leave you nothing you could show a disciplinary counsel.</p>\n","outroMarkdown":"Send the identical list to every vendor and keep the replies with the engagement file. Comment 18 makes reasonableness a judgment about facts, and dated vendor answers are the record of the judgment that was made [1].","outroHtml":"<p>Send the identical list to every vendor and keep the replies with the engagement file. Comment 18 makes reasonableness a judgment about facts, and dated vendor answers are the record of the judgment that was made <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>.</p>\n","contentJson":{"rows":[{"cells":["Encryption","At rest and in transit, including attachments and backups","Named cipher, TLS version, key custody and rotation"]},{"cells":["Authentication","MFA an administrator can force on every account, plus SSO","Whether MFA and SSO are standard or an add-on [8][9]"]},{"cells":["Password and session controls","Strength rules, reset intervals, lockout, session timeout","The admin settings list and its defaults [6]"]},{"cells":["Tenant isolation","A stated model: separate database per customer, or logical separation","How cross-tenant access is tested [6][7]"]},{"cells":["Attestations","The vendor's own audit, not only its cloud host's","SOC 2 Type II or ISO 27001, with scope and period [10]"]},{"cells":["Role-based permissions","Visibility set per role down to case, document, and billing level","A paralegal-level test account in the trial [6][9]"]},{"cells":["Audit logs","Views, downloads, exports, and permission changes","Retention, export format, whether logs can be altered [7]"]},{"cells":["Client portal","Authenticated access, expiring links, no documents by plain email","Portal login and sharing settings shown live"]},{"cells":["Backups and recovery","Geo-redundant copies, a stated recovery point and recovery time","Date of the last restore test [6][9]"]},{"cells":["Independent testing","Annual application penetration test plus ongoing scanning","Test date, testing firm, remediation summary [6][9]"]},{"cells":["Exit and incident terms","Free full export, documented deletion, a breach-notice window","A sample export file and the notice clause [8][11]"]}],"columns":["Requirement","What to require","Proof to ask for in writing"]},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":20},{"id":"bf51dfd3-5887-486e-b5e6-12b5f98d0465","sectionKey":"encryption_and_authentication","sectionType":"markdown_section","heading":"How do you test encryption and authentication claims?","introMarkdown":"### Encryption\n\nAsk for the algorithm and the protocol version, because every vendor in this category says its data is encrypted. Docketwise's security page states that data is \"encrypted with 256-bit keys (AES-256)\" and that the product \"is served 100% over https\" [9]. eImmigration by Cerenade's security page describes data encrypted \"using the same security protocols employed by banks and governments,\" whether \"sitting in your database or in transit between systems,\" without naming an algorithm or a TLS version as of July 2026 [6]. The second wording is common in this market and is not disqualifying; the difference is what a buyer can check. Four follow-ups close the gap: which cipher and TLS version, who holds the keys and how often they rotate, whether documents and backups get the same treatment, and which internal roles can decrypt production data.\n\n### Multi-factor authentication and single sign-on\n\nRequire MFA that an administrator can force firm-wide, and confirm the price before signing. As of July 2026, eImmigration's pricing page lists \"2FA & SSO Advanced Authentication\" among 17 premium features, with Starter at $60 per user per month including one premium feature and Complete at $110 including all of them; extra premium features run $15 per feature, per user, per month on the lower plans [8]. Docketwise's security page says two-factor authentication is \"available on all pricing plans\" [9]. Those are two published positions, not a ranking, and the reason to check yours is the failure mode: the April 2026 incident described below began with valid credentials, not a software flaw [11].\n\n### Password policy, lockout, and offboarding\n\neImmigration's security page describes controls that require strong passwords, force resets at set intervals, and lock a user out after repeated incorrect attempts [6]. Ask about session timeout, whether access can be limited by device or network, and how fast a departing paralegal's account can be disabled and their sessions ended.","introHtml":"<h3>Encryption</h3>\n<p>Ask for the algorithm and the protocol version, because every vendor in this category says its data is encrypted. Docketwise&#39;s security page states that data is &quot;encrypted with 256-bit keys (AES-256)&quot; and that the product &quot;is served 100% over https&quot; <a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>. eImmigration by Cerenade&#39;s security page describes data encrypted &quot;using the same security protocols employed by banks and governments,&quot; whether &quot;sitting in your database or in transit between systems,&quot; without naming an algorithm or a TLS version as of July 2026 <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. The second wording is common in this market and is not disqualifying; the difference is what a buyer can check. Four follow-ups close the gap: which cipher and TLS version, who holds the keys and how often they rotate, whether documents and backups get the same treatment, and which internal roles can decrypt production data.</p>\n<h3>Multi-factor authentication and single sign-on</h3>\n<p>Require MFA that an administrator can force firm-wide, and confirm the price before signing. As of July 2026, eImmigration&#39;s pricing page lists &quot;2FA &amp; SSO Advanced Authentication&quot; among 17 premium features, with Starter at $60 per user per month including one premium feature and Complete at $110 including all of them; extra premium features run $15 per feature, per user, per month on the lower plans <a href=\"https://get.eimmigration.com/pricing\" class=\"citation-ref\" data-citation-index=\"8\" target=\"_blank\" rel=\"noreferrer\">[8]</a>. Docketwise&#39;s security page says two-factor authentication is &quot;available on all pricing plans&quot; <a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>. Those are two published positions, not a ranking, and the reason to check yours is the failure mode: the April 2026 incident described below began with valid credentials, not a software flaw <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>.</p>\n<h3>Password policy, lockout, and offboarding</h3>\n<p>eImmigration&#39;s security page describes controls that require strong passwords, force resets at set intervals, and lock a user out after repeated incorrect attempts <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. Ask about session timeout, whether access can be limited by device or network, and how fast a departing paralegal&#39;s account can be disabled and their sessions ended.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":30},{"id":"d7a6049e-de40-41ce-a009-0030c56cc069","sectionKey":"isolation_and_attestations","sectionType":"markdown_section","heading":"Whose security are you actually buying?","introMarkdown":"### Tenant isolation\n\nIsolation is what stops one customer's data from surfacing in another customer's account, and vendors implement it very differently. eImmigration publishes one of the more specific architectures in this category: its security page states that \"Your data is housed in a single-tenant database, separate from any other eimmigration customer,\" and its June 2025 post adds that data is \"physically separated from all other users, not just virtually partitioned\" [6][7]. Most legal software is multi-tenant with logical separation, which is not unsafe by itself, so the useful question is how the boundary gets enforced and verified. Ask whether each customer gets a separate database, schema, or row-level filter, and how the vendor tests that a bug cannot cross the line.\n\n### A cloud host's certifications are not the vendor's\n\nDocketwise's help center article on data security says the product \"stores client data on Amazon S3 (AWS Cloud Storage)\" and lists \"SOC 1, 2 and 3 Certified\" among the attributes of that storage service [10]. eImmigration's security page states that the product is \"built on Microsoft Azure\" [6]. In both cases the named infrastructure controls belong to the hosting provider, which leaves the vendor's own application code, staff access model, and change management unaddressed. Ask whether those have ever been audited by a third party, and by whom.\n\n### Ask for the report, then read the scope\n\nRequest the vendor's own SOC 2 Type II report or ISO 27001 certificate, with the audit scope, observation period, and any exceptions the auditor noted, and expect to sign an NDA to see it. As of July 2026, neither eImmigration's security page nor its \"Built to Protect\" post uses the term SOC 2, and the security page states that the product \"is fully compliant with GDPR\" and with PCI DSS without publishing a report, an assessor name, or an attestation date [6][7]. Those frameworks cover different subject matter than US attorney confidentiality, so neither answers the Rule 1.6(c) question on its own [1]. Treat a compliance sentence as a claim to be evidenced, for every vendor, including the one already in use.","introHtml":"<h3>Tenant isolation</h3>\n<p>Isolation is what stops one customer&#39;s data from surfacing in another customer&#39;s account, and vendors implement it very differently. eImmigration publishes one of the more specific architectures in this category: its security page states that &quot;Your data is housed in a single-tenant database, separate from any other eimmigration customer,&quot; and its June 2025 post adds that data is &quot;physically separated from all other users, not just virtually partitioned&quot; <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a><a href=\"https://get.eimmigration.com/blog/the-case-for-secure-immigration-software\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a>. Most legal software is multi-tenant with logical separation, which is not unsafe by itself, so the useful question is how the boundary gets enforced and verified. Ask whether each customer gets a separate database, schema, or row-level filter, and how the vendor tests that a bug cannot cross the line.</p>\n<h3>A cloud host&#39;s certifications are not the vendor&#39;s</h3>\n<p>Docketwise&#39;s help center article on data security says the product &quot;stores client data on Amazon S3 (AWS Cloud Storage)&quot; and lists &quot;SOC 1, 2 and 3 Certified&quot; among the attributes of that storage service <a href=\"https://support.docketwise.com/en/articles/5224553-docketwise-data-security\" class=\"citation-ref\" data-citation-index=\"10\" target=\"_blank\" rel=\"noreferrer\">[10]</a>. eImmigration&#39;s security page states that the product is &quot;built on Microsoft Azure&quot; <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. In both cases the named infrastructure controls belong to the hosting provider, which leaves the vendor&#39;s own application code, staff access model, and change management unaddressed. Ask whether those have ever been audited by a third party, and by whom.</p>\n<h3>Ask for the report, then read the scope</h3>\n<p>Request the vendor&#39;s own SOC 2 Type II report or ISO 27001 certificate, with the audit scope, observation period, and any exceptions the auditor noted, and expect to sign an NDA to see it. As of July 2026, neither eImmigration&#39;s security page nor its &quot;Built to Protect&quot; post uses the term SOC 2, and the security page states that the product &quot;is fully compliant with GDPR&quot; and with PCI DSS without publishing a report, an assessor name, or an attestation date <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a><a href=\"https://get.eimmigration.com/blog/the-case-for-secure-immigration-software\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a>. Those frameworks cover different subject matter than US attorney confidentiality, so neither answers the Rule 1.6(c) question on its own <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Treat a compliance sentence as a claim to be evidenced, for every vendor, including the one already in use.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":40},{"id":"5e885824-6553-4227-a1ea-dbfd7eaaf774","sectionKey":"permissions_logs_portal","sectionType":"markdown_section","heading":"What should permissions, audit logs, and the client portal do?","introMarkdown":"### Role-based permissions\n\nPermissions should map to the roles a firm actually staffs, because immigration practices run on paralegals, accredited representatives, interpreters, and file clerks who do not need identical access. Docketwise's security page says multiple administrators and permission groups can be configured on its Advanced plan [9], and eImmigration's security page describes admin controls that set visibility on a need-to-access basis [6]. Test this in the trial: create a paralegal-level account, then try to open a sealed matter, download a passport scan, and view a trust ledger. Whatever that account can reach is the real permission model.\n\n### Audit logs\n\nLogs are what turn an incident into an answerable question, and the ethics rules assume they exist. Colorado requires a lawyer to investigate a breach and California requires a reasonable inquiry into its extent, neither of which is possible without a record of who touched what [2][3]. eImmigration's June 2025 post lists \"Activity tracking and audit logs\" among the core features to expect from any secure platform [7]. Push for the specifics a marketing page will not carry: whether the log captures views and downloads or only edits, how long it is retained, whether a firm administrator can export it, and whether anyone inside the vendor can alter it.\n\n### Client portal and document exchange\n\nThe portal is where the most sensitive documents enter the system, often from clients using a shared phone or a family email address. Confirm that portal access is individually authenticated instead of a shared link, that upload links expire, and that the platform never emails case documents as plain attachments. Ask what happens to a portal account after a matter closes, because a dormant account with a stale password is still a live entry point into the file [11].","introHtml":"<h3>Role-based permissions</h3>\n<p>Permissions should map to the roles a firm actually staffs, because immigration practices run on paralegals, accredited representatives, interpreters, and file clerks who do not need identical access. Docketwise&#39;s security page says multiple administrators and permission groups can be configured on its Advanced plan <a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>, and eImmigration&#39;s security page describes admin controls that set visibility on a need-to-access basis <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. Test this in the trial: create a paralegal-level account, then try to open a sealed matter, download a passport scan, and view a trust ledger. Whatever that account can reach is the real permission model.</p>\n<h3>Audit logs</h3>\n<p>Logs are what turn an incident into an answerable question, and the ethics rules assume they exist. Colorado requires a lawyer to investigate a breach and California requires a reasonable inquiry into its extent, neither of which is possible without a record of who touched what <a href=\"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a><a href=\"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. eImmigration&#39;s June 2025 post lists &quot;Activity tracking and audit logs&quot; among the core features to expect from any secure platform <a href=\"https://get.eimmigration.com/blog/the-case-for-secure-immigration-software\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a>. Push for the specifics a marketing page will not carry: whether the log captures views and downloads or only edits, how long it is retained, whether a firm administrator can export it, and whether anyone inside the vendor can alter it.</p>\n<h3>Client portal and document exchange</h3>\n<p>The portal is where the most sensitive documents enter the system, often from clients using a shared phone or a family email address. Confirm that portal access is individually authenticated instead of a shared link, that upload links expire, and that the platform never emails case documents as plain attachments. Ask what happens to a portal account after a matter closes, because a dormant account with a stale password is still a live entry point into the file <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":50},{"id":"02b99dbf-9663-412a-8440-7272f264403d","sectionKey":"backups_and_testing","sectionType":"markdown_section","heading":"What should you require for backups, recovery, and independent testing?","introMarkdown":"### Backups and geo-redundancy\n\nRequire two numbers in writing: the recovery point objective, meaning how much work can be lost, and the recovery time objective, meaning how long the firm is down. Vendors describe this loosely. eImmigration's security page says its \"on-the-fly data geo-replication processes mean that no matter what disasters come your way, you can never lose more than a few minutes of progress\" [6]. Docketwise's security page says data is \"continuously backed-up via AWS Elastic Beanstalk snapshots every ~5 minutes\" and that its infrastructure and data \"are spread across multiple AWS availability zones\" [9]. Both are published statements, and neither is a contract term. Ask when the last full restore was tested, who performed it, and whether the firm can pull its own independent copy on a schedule it controls.\n\n### Penetration testing and vulnerability management\n\nAn annual test by an outside firm is the baseline, and the evidence is the part to insist on. eImmigration's security page claims \"annual cybersecurity penetration testing\" and a \"24x7x365 Security Response\" team [6]; Docketwise's security page says it \"uses third party security tools to continuously scan for vulnerabilities\" and describes an incident response protocol covering escalation, mitigation, and post-mortem [9]. Neither page published a test report or a tester's name as of July 2026 [6][9], which is normal here and is why the request should be made privately. Ask for the date of the most recent application-scoped test, who ran it, findings by severity, and confirmation that high-severity findings were closed.","introHtml":"<h3>Backups and geo-redundancy</h3>\n<p>Require two numbers in writing: the recovery point objective, meaning how much work can be lost, and the recovery time objective, meaning how long the firm is down. Vendors describe this loosely. eImmigration&#39;s security page says its &quot;on-the-fly data geo-replication processes mean that no matter what disasters come your way, you can never lose more than a few minutes of progress&quot; <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. Docketwise&#39;s security page says data is &quot;continuously backed-up via AWS Elastic Beanstalk snapshots every ~5 minutes&quot; and that its infrastructure and data &quot;are spread across multiple AWS availability zones&quot; <a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>. Both are published statements, and neither is a contract term. Ask when the last full restore was tested, who performed it, and whether the firm can pull its own independent copy on a schedule it controls.</p>\n<h3>Penetration testing and vulnerability management</h3>\n<p>An annual test by an outside firm is the baseline, and the evidence is the part to insist on. eImmigration&#39;s security page claims &quot;annual cybersecurity penetration testing&quot; and a &quot;24x7x365 Security Response&quot; team <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>; Docketwise&#39;s security page says it &quot;uses third party security tools to continuously scan for vulnerabilities&quot; and describes an incident response protocol covering escalation, mitigation, and post-mortem <a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>. Neither page published a test report or a tester&#39;s name as of July 2026 <a href=\"https://get.eimmigration.com/capabilities/security\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a><a href=\"https://www.docketwise.com/security/\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>, which is normal here and is why the request should be made privately. Ask for the date of the most recent application-scoped test, who ran it, findings by severity, and confirmation that high-severity findings were closed.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":60},{"id":"6cbfbf0a-e878-437d-8aca-86c2b0b1f70b","sectionKey":"exit_and_breach_terms","sectionType":"markdown_section","heading":"What do the exit terms and the breach-notification terms need to say?","introMarkdown":"### Data export, portability, and deletion\n\nSettle export and deletion before signing, because a firm has no bargaining power the day it decides to leave. As of July 2026, eImmigration's pricing FAQ states that on cancellation \"You may export one copy of all your data for no charge. Additional copies will incur a cost, depending on the size of your database\" [8]. Whatever a vendor answers, pin down what \"all your data\" covers, because matter records, documents, notes, billing history, and audit logs are separate exports, and a CSV of case rows without the document store is not a migration. Ask in the same breath how deletion is certified and how long deleted records survive inside backup snapshots.\n\n### Breach notification, in the contract\n\nThe ethical duty to notify clients belongs to the lawyer, so the contract has to deliver the facts in time to act on them. ABA Formal Opinion 483, quoted by the California committee, holds that \"lawyers must employ reasonable efforts to monitor the technology and office resources connected to the internet, external data sources, and external vendors providing services relating to data and the use of data\" [3]. Colorado adopts the same opinion's definition of a breach and requires timely notice to current clients [2]. Neither standard survives a vendor's discretionary disclosure schedule.\n\n### One documented sequence to read before you negotiate\n\nIn April 2026, DocketWise notified individuals whose data was held by a portion of its immigration law firm customers. In the company's own notice, DocketWise says its forensic investigation confirmed that \"an unauthorized actor(s) used valid credentials to clone certain third-party partner repositories, some of which were used as part of a data migration pipeline for the DocketWise application\" [11]. Impacted information varied by individual and could include Social Security number, passport number, financial account number, tax identification number, and medical condition or treatment information; letters were mailed beginning April 3, 2026 [11]. The notice also reports no evidence of ongoing unauthorized activity, no evidence that personal information was published, and that DocketWise notified the FBI [11]. ComplexDiscovery's account of the incident puts the total at 116,666 individuals, with the compromise dated on or around September 1, 2025 and the scope confirmed on February 19, 2026 [12]. That sequence is a diligence fact rather than a verdict on any product, since any cloud vendor can end up on the receiving end of one. What it argues for is contract language: notice within a defined number of hours or days of discovery, an obligation to identify which of the firm's own records were affected, access to the forensic findings, and cooperation with client notifications.","introHtml":"<h3>Data export, portability, and deletion</h3>\n<p>Settle export and deletion before signing, because a firm has no bargaining power the day it decides to leave. As of July 2026, eImmigration&#39;s pricing FAQ states that on cancellation &quot;You may export one copy of all your data for no charge. Additional copies will incur a cost, depending on the size of your database&quot; <a href=\"https://get.eimmigration.com/pricing\" class=\"citation-ref\" data-citation-index=\"8\" target=\"_blank\" rel=\"noreferrer\">[8]</a>. Whatever a vendor answers, pin down what &quot;all your data&quot; covers, because matter records, documents, notes, billing history, and audit logs are separate exports, and a CSV of case rows without the document store is not a migration. Ask in the same breath how deletion is certified and how long deleted records survive inside backup snapshots.</p>\n<h3>Breach notification, in the contract</h3>\n<p>The ethical duty to notify clients belongs to the lawyer, so the contract has to deliver the facts in time to act on them. ABA Formal Opinion 483, quoted by the California committee, holds that &quot;lawyers must employ reasonable efforts to monitor the technology and office resources connected to the internet, external data sources, and external vendors providing services relating to data and the use of data&quot; <a href=\"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. Colorado adopts the same opinion&#39;s definition of a breach and requires timely notice to current clients <a href=\"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a>. Neither standard survives a vendor&#39;s discretionary disclosure schedule.</p>\n<h3>One documented sequence to read before you negotiate</h3>\n<p>In April 2026, DocketWise notified individuals whose data was held by a portion of its immigration law firm customers. In the company&#39;s own notice, DocketWise says its forensic investigation confirmed that &quot;an unauthorized actor(s) used valid credentials to clone certain third-party partner repositories, some of which were used as part of a data migration pipeline for the DocketWise application&quot; <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>. Impacted information varied by individual and could include Social Security number, passport number, financial account number, tax identification number, and medical condition or treatment information; letters were mailed beginning April 3, 2026 <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>. The notice also reports no evidence of ongoing unauthorized activity, no evidence that personal information was published, and that DocketWise notified the FBI <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>. ComplexDiscovery&#39;s account of the incident puts the total at 116,666 individuals, with the compromise dated on or around September 1, 2025 and the scope confirmed on February 19, 2026 <a href=\"https://complexdiscovery.com/when-your-legal-tech-vendor-gets-breached-docketwise-incident-exposes-116666-immigration-records-and-a-professions-blind-spot/\" class=\"citation-ref\" data-citation-index=\"12\" target=\"_blank\" rel=\"noreferrer\">[12]</a>. That sequence is a diligence fact rather than a verdict on any product, since any cloud vendor can end up on the receiving end of one. What it argues for is contract language: notice within a defined number of hours or days of discovery, an obligation to identify which of the firm&#39;s own records were affected, access to the forensic findings, and cooperation with client notifications.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":70},{"id":"f7e8eb23-4f26-4a9f-9ad7-507cbfd2245d","sectionKey":"contributor_perspective","sectionType":"markdown_section","heading":"How this answer was researched","introMarkdown":"Primary authority and vendor documentation were read directly for this answer instead of summarized from other buyer guides. The rule text and the reasonableness factors come from ABA Formal Opinion 477R, which reproduces Model Rule 1.6(c) and Comment 18 in full [1]. The breach-response duties come from two state bar opinions that adopt and quote ABA Formal Opinion 483, which keeps the citation on authority a firm can hand to its own risk counsel [2][3]. Product statements were taken from vendor security, pricing, and support pages as published, with each quotation checked against the live page on July 23, 2026 and date-stamped in the text. Where a page asserts a compliance position without publishing a report or an assessor, this answer records the gap instead of upgrading the claim. Immigration attorneys, DOJ accredited representatives, legal-aid technology leads, and security professionals who have run these vendor reviews are invited to submit corrections.","introHtml":"<p>Primary authority and vendor documentation were read directly for this answer instead of summarized from other buyer guides. The rule text and the reasonableness factors come from ABA Formal Opinion 477R, which reproduces Model Rule 1.6(c) and Comment 18 in full <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. The breach-response duties come from two state bar opinions that adopt and quote ABA Formal Opinion 483, which keeps the citation on authority a firm can hand to its own risk counsel <a href=\"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a><a href=\"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. Product statements were taken from vendor security, pricing, and support pages as published, with each quotation checked against the live page on July 23, 2026 and date-stamped in the text. Where a page asserts a compliance position without publishing a report or an assessor, this answer records the gap instead of upgrading the claim. Immigration attorneys, DOJ accredited representatives, legal-aid technology leads, and security professionals who have run these vendor reviews are invited to submit corrections.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":"This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.","noteHtml":"<p>This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.</p>\n","sortOrder":80},{"id":"38b00444-0028-4993-8b5a-742f754768df","sectionKey":"trade_offs","sectionType":"markdown_section","heading":"Trade-offs and limits worth knowing","introMarkdown":"### A single-tenant database costs something\n\nDedicated databases usually carry a higher price and can mean slower feature releases, because the vendor maintains more instances. A well-run multi-tenant platform with tested logical isolation and a current SOC 2 Type II report can be the safer purchase than a single-tenant claim with no external audit behind it, so the comparison worth making is between the evidence each vendor can produce.\n\n### An attestation is scoped, and the scope is the point\n\nA SOC 2 Type II report describes whether specified controls operated over a stated period. It can exclude the module a firm cares about and it can carry exceptions, so the scope section is the part of the report that produces information. Retention settings deserve the same scrutiny, because audit logs held for years also become discoverable material about how a firm handled a matter.\n\n### Controls create friction for the people doing the work\n\nComment 18 counts difficulty of implementation and the effect on a lawyer's ability to represent clients among the reasonableness factors, an acknowledgment that controls have costs [1]. Enforced MFA is harder in a legal-aid clinic where volunteers rotate weekly and share a workstation, so the answer is usually a different MFA method rather than an exemption.\n\n### The most-audited vendor is not automatically the right one\n\nRule 1.6(c) asks for reasonable efforts, not maximum security [1]. A general practice platform with a thicker compliance binder may lack the USCIS form library an immigration practice runs on, while a specialized vendor with thinner paperwork may fit the work better. Documenting the comparison on both axes is what makes the decision defensible.","introHtml":"<h3>A single-tenant database costs something</h3>\n<p>Dedicated databases usually carry a higher price and can mean slower feature releases, because the vendor maintains more instances. A well-run multi-tenant platform with tested logical isolation and a current SOC 2 Type II report can be the safer purchase than a single-tenant claim with no external audit behind it, so the comparison worth making is between the evidence each vendor can produce.</p>\n<h3>An attestation is scoped, and the scope is the point</h3>\n<p>A SOC 2 Type II report describes whether specified controls operated over a stated period. It can exclude the module a firm cares about and it can carry exceptions, so the scope section is the part of the report that produces information. Retention settings deserve the same scrutiny, because audit logs held for years also become discoverable material about how a firm handled a matter.</p>\n<h3>Controls create friction for the people doing the work</h3>\n<p>Comment 18 counts difficulty of implementation and the effect on a lawyer&#39;s ability to represent clients among the reasonableness factors, an acknowledgment that controls have costs <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Enforced MFA is harder in a legal-aid clinic where volunteers rotate weekly and share a workstation, so the answer is usually a different MFA method rather than an exemption.</p>\n<h3>The most-audited vendor is not automatically the right one</h3>\n<p>Rule 1.6(c) asks for reasonable efforts, not maximum security <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. A general practice platform with a thicker compliance binder may lack the USCIS form library an immigration practice runs on, while a specialized vendor with thinner paperwork may fit the work better. Documenting the comparison on both axes is what makes the decision defensible.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":90},{"id":"30084ef9-371f-45ed-be48-0ad6e2b2d01a","sectionKey":"what_software_security_is_not","sectionType":"markdown_section","heading":"What software security does not cover","introMarkdown":"### It is not a substitute for firm-side practice\n\nOpinion 477R's obligations run past software selection: understand how client information is transmitted and where it is stored, label privileged communications, and train lawyers and nonlawyer assistants in information security [1]. A platform with strong controls still fails if a caseworker emails an unencrypted I-589 draft from a personal account.\n\n### It is not statutory breach compliance\n\nEthical notification duties and state breach-notification statutes are separate obligations, and Colorado's opinion says so directly while pointing lawyers to their own state's statutory requirements [2]. A vendor saying it handled notification does not discharge the firm's duty to its clients under the ethics rules [3].\n\n### It is not immunity from a vendor-side incident\n\nThe DocketWise notice describes credentials at a third-party partner repository as the entry point rather than a flaw in the application a firm logged into [11]. Diligence lowers the probability and, more reliably, shortens the gap between a vendor's discovery and a firm's ability to tell clients something accurate [2][3]. Comment 18 frames reasonableness against evolving threats, so re-running these questions at renewal keeps the file current [1].","introHtml":"<h3>It is not a substitute for firm-side practice</h3>\n<p>Opinion 477R&#39;s obligations run past software selection: understand how client information is transmitted and where it is stored, label privileged communications, and train lawyers and nonlawyer assistants in information security <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. A platform with strong controls still fails if a caseworker emails an unencrypted I-589 draft from a personal account.</p>\n<h3>It is not statutory breach compliance</h3>\n<p>Ethical notification duties and state breach-notification statutes are separate obligations, and Colorado&#39;s opinion says so directly while pointing lawyers to their own state&#39;s statutory requirements <a href=\"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a>. A vendor saying it handled notification does not discharge the firm&#39;s duty to its clients under the ethics rules <a href=\"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</p>\n<h3>It is not immunity from a vendor-side incident</h3>\n<p>The DocketWise notice describes credentials at a third-party partner repository as the entry point rather than a flaw in the application a firm logged into <a href=\"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>. Diligence lowers the probability and, more reliably, shortens the gap between a vendor&#39;s discovery and a firm&#39;s ability to tell clients something accurate <a href=\"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a><a href=\"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. Comment 18 frames reasonableness against evolving threats, so re-running these questions at renewal keeps the file current <a href=\"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":100}],"citations":[{"title":"Formal Opinion 477R: Securing Communication of Protected Client Information","url":"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf","excerpt":"A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-07-23T00:00:00","supportsText":"Text of Model Rule 1.6(c); the five non-exclusive Comment 18 reasonableness factors; the statement that strong measures like encryption are warranted in some circumstances; the instruction to conduct due diligence on technology vendors under Model Rule 5.3; obligations to understand where informatio","domain":"docs.tbpr.org","publisherName":"ABA Standing Committee on Ethics and Professional Responsibility (copy hosted by the Tennessee Board of Professional Responsibility)"},{"title":"Formal Opinion 141: Ethical Duties Arising from Data Breach","url":"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770","excerpt":"A lawyer must make reasonable efforts to prevent, monitor for, halt, and investigate any security breach of data the lawyer controls.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-07-23T00:00:00","supportsText":"Duty to prevent, monitor for, halt, and investigate a breach and to timely notify current clients; ABA Formal Opinion 483's definition of a data breach; Rule 5.3 supervision of third-party vendors; statutory notification duties are separate from ethical ones.","domain":"cobar.org","publisherName":"Colorado Bar Association Ethics Committee"},{"title":"Formal Opinion No. 2020-203: Data Breaches","url":"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf","excerpt":"lawyers must employ reasonable efforts to monitor the technology and office resources connected to the internet, external data sources, and external vendors providing services relating to data and the use of data.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-07-23T00:00:00","supportsText":"Duty to assess risk and take reasonable steps to secure electronic systems; duty to conduct a reasonable inquiry into a breach and notify affected clients; the quoted ABA Formal Opinion 483 duty to monitor external vendors providing data services.","domain":"calbar.ca.gov","publisherName":"State Bar of California Standing Committee on Professional Responsibility and Conduct"},{"title":"I-485, Application to Register Permanent Residence or Adjust Status","url":"https://www.uscis.gov/i-485","excerpt":"When you file Form I-485, you must also submit Form I-693, Report of Immigration Medical Examination and Vaccination Record.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-07-23T00:00:00","supportsText":"An adjustment package includes the sealed medical examination (Form I-693) uploaded with an online filing; A-Number issuance; representatives file through a USCIS online account.","domain":"uscis.gov","publisherName":"U.S. Citizenship and Immigration Services"},{"title":"EOIR Courts & Appeals System (ECAS) - Online Filing","url":"https://www.justice.gov/eoir/ECAS","excerpt":"ECAS is available at all immigration courts and the Board of Immigration Appeals. Use of the system is mandatory as of February 11, 2022.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-07-23T00:00:00","supportsText":"Electronic filing is mandatory at all immigration courts and the BIA since February 11, 2022; registered attorneys and accredited representatives file documents and download electronic records of proceedings.","domain":"justice.gov","publisherName":"U.S. Department of Justice, Executive Office for Immigration Review"},{"title":"eimmigration Security Features","url":"https://get.eimmigration.com/capabilities/security","excerpt":"Your data is housed in a single-tenant database, separate from any other eimmigration customer.","quoteText":null,"sourceRole":"SUPPORTING","verifiedAt":"2026-07-23T00:00:00","supportsText":"eImmigration's published security architecture as of July 2026: single-tenant database, encryption described by comparison rather than by algorithm, multi-factor authentication, role-based permissions, Google and Microsoft Azure AD SSO, password policies and lockouts, Microsoft Azure hosting, geo-re","domain":"get.eimmigration.com","publisherName":"Cerenade (eImmigration)"},{"title":"Built to Protect: The Case for Secure Immigration Software","url":"https://get.eimmigration.com/blog/the-case-for-secure-immigration-software","excerpt":"Your data is physically separated from all other users, not just virtually partitioned.","quoteText":null,"sourceRole":"SUPPORTING","verifiedAt":"2026-07-23T00:00:00","supportsText":"Vendor-published checklist of core security features to expect, including activity tracking and audit logs; the claim that customer data is physically separated rather than virtually partitioned; real-time replication across geographically diverse data centers; Microsoft Azure hosting. Post dated Ju","domain":"get.eimmigration.com","publisherName":"Cerenade (eImmigration)"},{"title":"Pricing | eimmigration Law Software","url":"https://get.eimmigration.com/pricing","excerpt":"You may export one copy of all your data for no charge. Additional copies will incur a cost, depending on the size of your database.","quoteText":null,"sourceRole":"SUPPORTING","verifiedAt":"2026-07-23T00:00:00","supportsText":"As of July 2026: 2FA and SSO advanced authentication is listed among 17 premium features; Starter $60 per user per month includes one premium feature, Essentials $90 includes four, Complete $110 includes all; additional premium features cost $15 per feature per user per month; on cancellation one fr","domain":"get.eimmigration.com","publisherName":"Cerenade"},{"title":"Docketwise Security","url":"https://www.docketwise.com/security/","excerpt":"encrypted with 256-bit keys (AES-256), the strongest industry-adopted and government-approved algorithm","quoteText":null,"sourceRole":"INDEPENDENT","verifiedAt":"2026-07-23T00:00:00","supportsText":"A second vendor's published security page for factual comparison: AES-256 encryption, 100% HTTPS, AWS hosting, Elastic Beanstalk snapshots roughly every five minutes, multiple availability zones, continuous third-party vulnerability scanning, employee SSO or 2FA, documented incident response, two-fa","domain":"docketwise.com","publisherName":"Docketwise (8am, LLC)"},{"title":"Docketwise Data Security","url":"https://support.docketwise.com/en/articles/5224553-docketwise-data-security","excerpt":"Docketwise stores client data on Amazon S3 (AWS Cloud Storage) and irreversibly hashes all sensitive information.","quoteText":null,"sourceRole":"INDEPENDENT","verifiedAt":"2026-07-23T00:00:00","supportsText":"Illustrates that published SOC certifications can attach to the storage service rather than the application vendor: the article describes storing client data on Amazon S3 and lists SOC 1, 2 and 3 certification among that service's attributes.","domain":"support.docketwise.com","publisherName":"Docketwise Help Center"},{"title":"DocketWise Data Incident (notice to potentially affected individuals)","url":"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf","excerpt":"an unauthorized actor(s) used valid credentials to clone certain third-party partner repositories, some of which were used as part of a data migration pipeline for the DocketWise application","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-07-23T00:00:00","supportsText":"The company's own notice: October 2025 discovery that third-party partner repository credentials may have been accessed; valid credentials used to clone repositories in a data migration pipeline containing law firm records; the list of impacted data types including Social Security number, passport n","domain":"classaction.org","publisherName":"DocketWise / 8am, LLC"},{"title":"When Your Legal Tech Vendor Gets Breached: DocketWise Incident Exposes 116,666 Immigration Records","url":"https://complexdiscovery.com/when-your-legal-tech-vendor-gets-breached-docketwise-incident-exposes-116666-immigration-records-and-a-professions-blind-spot/","excerpt":"116,666 individuals","quoteText":null,"sourceRole":"INDEPENDENT","verifiedAt":"2026-07-23T00:00:00","supportsText":"Independent reporting on the incident total of 116,666 affected individuals, the Maine Attorney General filing dated April 3, 2026, the compromise date on or around September 1, 2025, and scope confirmation on February 19, 2026.","domain":"complexdiscovery.com","publisherName":"ComplexDiscovery"}],"revisions":[],"relatedAnswers":[{"id":"44658f2b-07eb-4ae5-88ad-725a0eaa8ff1","slug":"how-should-firms-evaluate-uscis-form-automation","question":"How should firms evaluate USCIS form automation?","publishedAt":"2026-08-17T18:22:28.236","confidenceScore":92,"confidenceLabel":"High","industry":{"id":"a7b3fdc7-1217-4f39-8fc5-2e8e3f73c3d7","slug":"legal-technology","label":"Legal Technology","description":"Practice management, e-discovery, and compliance"},"topic":{"slug":"immigration-law-software","label":"Immigration Law Software","description":"Case management, USCIS form automation, client intake, billing, and security for immigration law firms and nonprofit legal aid programs.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"A rejected USCIS filing loses its filing date and cannot be appealed, which makes form automation the highest-stakes feature in an immigration platform. Nine tests, run live on your own data in a vendor demo, cover edition dates, agency coverage past USCIS, in-product instructions, auto-population, related-case packets, e-filing, update speed, blank forms, and the audit trail.","url":"/q/how-should-firms-evaluate-uscis-form-automation"},{"id":"92d1784a-ba89-4d6a-965b-55ed8ea1848b","slug":"how-much-does-immigration-case-management-software-cost","question":"How much does immigration case management software cost?","publishedAt":"2026-08-17T18:22:25.237","confidenceScore":88,"confidenceLabel":"High","industry":{"id":"a7b3fdc7-1217-4f39-8fc5-2e8e3f73c3d7","slug":"legal-technology","label":"Legal Technology","description":"Practice management, e-discovery, and compliance"},"topic":{"slug":"immigration-law-software","label":"Immigration Law Software","description":"Case management, USCIS form automation, client intake, billing, and security for immigration law firms and nonprofit legal aid programs.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"Published per-seat prices for immigration-specific case management ran between $55 and $129 per user per month in August 2026, and two of the largest enterprise platforms publish no price at all. This answer maps the public numbers, converts them into an annual bill at three, eight, and twenty seats, and shows what sits outside the advertised per-user rate.","url":"/q/how-much-does-immigration-case-management-software-cost"},{"id":"050276c1-49f1-420f-8e6b-3e0cb82cad9c","slug":"do-nonprofit-immigration-legal-aid-programs-get-discounts-on-case-management-software","question":"Do nonprofit immigration legal aid programs get discounts on case management software?","publishedAt":"2026-08-13T16:53:00","confidenceScore":85,"confidenceLabel":"High","industry":{"id":"a7b3fdc7-1217-4f39-8fc5-2e8e3f73c3d7","slug":"legal-technology","label":"Legal Technology","description":"Practice management, e-discovery, and compliance"},"topic":{"slug":"immigration-law-software","label":"Immigration Law Software","description":"Case management, USCIS form automation, client intake, billing, and security for immigration law firms and nonprofit legal aid programs.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"Most legal tech vendors will discount for a nonprofit legal services program, but very few print the terms. A check of immigration and legal aid platforms in August 2026 found one immigration-specific vendor publishing a nonprofit percentage, several publishing no price at all, and legal aid specialists pricing by organization rather than by seat. The work that decides your budget is getting the percentage, the eligibility proof, the commitment length, the stacking rules, and the renewal rate into a written quote.","url":"/q/do-nonprofit-immigration-legal-aid-programs-get-discounts-on-case-management-software"},{"id":"a43e4c0c-0972-42fc-98a8-87c1507962ea","slug":"can-a-small-immigration-firm-use-clio-instead-of-specialized-immigration-software","question":"Can a small immigration firm use Clio instead of specialized immigration software?","publishedAt":"2026-08-05T14:27:00","confidenceScore":90,"confidenceLabel":"High","industry":{"id":"a7b3fdc7-1217-4f39-8fc5-2e8e3f73c3d7","slug":"legal-technology","label":"Legal Technology","description":"Practice management, e-discovery, and compliance"},"topic":{"slug":"immigration-law-software","label":"Immigration Law Software","description":"Case management, USCIS form automation, client intake, billing, and security for immigration law firms and nonprofit legal aid programs.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"Clio Manage is a general practice platform, and Clio itself routes immigration form work to Clio Draft or to integrations with Docketwise and Prima.Law. That makes the real decision a stack question rather than a brand question: who owns USCIS form editions, related-case packets, priority-date chart selection, and filings that run through USCIS, DOL FLAG, and EOIR ECAS. This answer maps what each layer publishes, what the hybrid setup actually syncs, and how caseload mix changes the call.","url":"/q/can-a-small-immigration-firm-use-clio-instead-of-specialized-immigration-software"}],"contributorStats":{"verifiedAnswers":269,"openDisputes":0},"schemaJson":{"@context":"https://schema.org","@type":"Question","name":"What security features should immigration case management software have?","text":"What security features should immigration case management software have?","url":"https://www.answerstack.io/q/what-security-features-should-immigration-case-management-software-have","answerCount":1,"datePublished":"2026-07-23T18:41:00","author":{"@type":"Person","name":"AnswerStack Editorial Team","worksFor":{"@type":"Organization","name":"AnswerStack"},"url":"https://www.answerstack.io/contributors/answer-stack"},"about":[{"@type":"Thing","name":"Immigration Law Software"},{"@type":"Thing","name":"Legal Technology"}],"acceptedAnswer":{"@type":"Answer","text":"Immigration case management software should enforce encryption of data at rest and in transit, administrator-enforced multi-factor authentication with single sign-on, a stated tenant isolation model, role-based permissions with exportable audit logs, geo-redundant backups with a defined recovery point, independent penetration testing, and contractual rights covering data export, deletion, and breach notification [6][7][9]. The bar is set by ABA Model Rule 1.6(c), which requires a lawyer to \"make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client\" [1]. Comment 18 makes that a fact-based test in which the sensitivity of the information is the first factor, and an immigration file carries a Social Security number, a passport number, an A-Number, financial history, and the sealed medical examination USCIS requires with an adjustment application [1][4]. Because the duty extends to the vendors a firm hires, ABA Formal Opinion 477R tells lawyers to conduct due diligence on technology vendors under Model Rule 5.3, which means asking every vendor the same written questions and keeping the answers [1]. The risk is documented: in an April 2026 notice to affected individuals, one immigration platform reported that an unauthorized actor used valid credentials to clone third-party repositories, exposing Social Security numbers, passport numbers, and medical condition or treatment information [11].","url":"https://www.answerstack.io/q/what-security-features-should-immigration-case-management-software-have","upvoteCount":0,"datePublished":"2026-07-23T18:41:00","dateModified":"2026-07-23T00:00:00","author":{"@type":"Person","name":"AnswerStack Editorial Team","worksFor":{"@type":"Organization","name":"AnswerStack"},"url":"https://www.answerstack.io/contributors/answer-stack"},"citation":[{"@type":"CreativeWork","name":"Formal Opinion 477R: Securing Communication of Protected Client Information","url":"https://docs.tbpr.org/pub/aba%20formal%20opinion%20477.authcheckdam.pdf"},{"@type":"CreativeWork","name":"Formal Opinion 141: Ethical Duties Arising from Data Breach","url":"https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf?ver=2020-07-20-100834-770"},{"@type":"CreativeWork","name":"Formal Opinion No. 2020-203: Data Breaches","url":"https://www.calbar.ca.gov/sites/default/files/portals/0/documents/ethics/Opinions/Formal-Opinion-No-2020-203-Data-Breaches.pdf"},{"@type":"CreativeWork","name":"I-485, Application to Register Permanent Residence or Adjust Status","url":"https://www.uscis.gov/i-485"},{"@type":"CreativeWork","name":"EOIR Courts & Appeals System (ECAS) - Online Filing","url":"https://www.justice.gov/eoir/ECAS"},{"@type":"CreativeWork","name":"eimmigration Security Features","url":"https://get.eimmigration.com/capabilities/security"},{"@type":"CreativeWork","name":"Built to Protect: The Case for Secure Immigration Software","url":"https://get.eimmigration.com/blog/the-case-for-secure-immigration-software"},{"@type":"CreativeWork","name":"Pricing | eimmigration Law Software","url":"https://get.eimmigration.com/pricing"},{"@type":"CreativeWork","name":"Docketwise Security","url":"https://www.docketwise.com/security/"},{"@type":"CreativeWork","name":"Docketwise Data Security","url":"https://support.docketwise.com/en/articles/5224553-docketwise-data-security"},{"@type":"CreativeWork","name":"DocketWise Data Incident (notice to potentially affected individuals)","url":"https://www.classaction.org/media/docketwise-data-breach-online-notice-2026.pdf"},{"@type":"CreativeWork","name":"When Your Legal Tech Vendor Gets Breached: DocketWise Incident Exposes 116,666 Immigration Records","url":"https://complexdiscovery.com/when-your-legal-tech-vendor-gets-breached-docketwise-incident-exposes-116666-immigration-records-and-a-professions-blind-spot/"}]}}}