Security Statement
This Security Statement describes the general security approach for BRL Matters. It is informational and is not a contract or a warranty. It is not a representation that every safeguard described applies identically to every system, user, integration, or type of information.
1. Our Security Commitment
BRL Matters is designed to support the secure administration of legal matters and the protection of confidential and sensitive information.
Barshay, Rizzo & Lopez, PLLC maintains administrative, technical, and physical safeguards reasonably designed to protect information against unauthorized access, acquisition, use, alteration, disclosure, destruction, or loss. Our security practices are risk-based and may change as technology, threats, legal requirements, and the Platform evolve.
2. Administrative Safeguards
The Firm’s security program may include measures designed to address:
- designation of personnel responsible for information security;
- assessment of reasonably foreseeable internal and external risks;
- access authorization based upon job responsibilities and legitimate need;
- confidentiality and security training for personnel;
- review of security practices and controls;
- oversight of service providers that process sensitive information;
- incident identification, escalation, response, and recovery;
- retention and secure disposal of information; and
- periodic adjustment of safeguards in response to identified risks.
3. Access Controls
Access to BRL Matters is restricted to authorized users. Depending upon the user’s role and the Platform’s configuration, safeguards may include:
- individual user accounts;
- role-based permissions;
- matter-specific access restrictions;
- administrative approval of account creation;
- multifactor authentication;
- password requirements;
- automatic session expiration after a period of inactivity;
- account-lockout controls after repeated failed sign-in attempts;
- logging of authentication and account activity; and
- prompt revocation of access when authorization ends.
4. Encryption
Communications between supported browsers and BRL Matters are encrypted in transit using industry-standard transport-encryption protocols.
Information stored in the Platform’s database and backup infrastructure is encrypted at rest by the Platform’s hosting and storage providers using industry-standard encryption.
Encryption does not protect information after a user downloads it to an unsecured device, transmits it through another service, prints it, shares credentials, or otherwise removes it from the Platform’s controlled environment.
5. Password and Authentication Security
BRL Matters does not display users’ passwords to other users.
Passwords managed directly by BRL Matters are stored using salted, one-way cryptographic hashing rather than as readable text.
Users may be required to complete multifactor authentication, identity verification, password resets, or other security procedures. The Firm will not request that a user disclose a password by email or telephone.
6. Hosting and Service Providers
The Firm uses reputable third-party providers for hosting, data storage, authentication, communications, backups, and other Platform functions. The Firm evaluates service providers based upon factors that may include:
- the sensitivity of the information involved;
- the provider’s security controls;
- contractual confidentiality and security obligations;
- incident-notification commitments;
- access restrictions;
- data-location and retention practices;
- business-continuity capabilities; and
- relevant independent security assessments or certifications.
Use of a service provider does not eliminate the possibility of a security incident.
7. Monitoring and Logging
BRL Matters may record authentication activity, account access, administrative actions, document activity, configuration changes, errors, and suspected security events. Logs may be reviewed to:
- investigate suspected unauthorized access;
- troubleshoot technical problems;
- enforce access restrictions;
- preserve system integrity;
- satisfy legal or professional obligations; and
- respond to a security incident.
Monitoring is conducted for legitimate operational, security, compliance, and matter-administration purposes.
8. Vulnerability and System Management
The Firm and its service providers use risk-based processes designed to identify and address vulnerabilities. Depending upon the system involved, these processes may include:
- software and security updates;
- vulnerability scanning;
- secure configuration review;
- dependency and component review;
- malware protection;
- penetration testing;
- security-event monitoring; and
- remediation based upon severity and risk.
No testing or security process can establish that a system is invulnerable to every threat.
9. Backups and Continuity
Information maintained within BRL Matters is backed up on a recurring schedule to secure cloud storage, according to procedures designed to support restoration following certain system failures, data-loss events, or operational disruptions.
Backups do not necessarily preserve every interim change, and they are not a substitute for maintaining independent procedures for critical deadlines, court filings, and essential communications.
10. Security-Incident Response
The Firm maintains procedures for evaluating and responding to suspected security incidents. Depending upon the circumstances, the response may include:
- restricting or disabling affected accounts;
- preserving relevant records;
- investigating the nature and scope of the incident;
- engaging technical, legal, forensic, insurance, or law-enforcement resources;
- containing and remediating identified vulnerabilities;
- restoring affected services;
- assessing notification obligations; and
- providing legally required notices.
The timing and content of any notification will depend upon the circumstances and applicable legal and professional obligations.
11. User Responsibilities
Security is a shared responsibility. Authorized users should:
- protect their credentials and authentication devices;
- use unique passwords;
- enable multifactor authentication when available;
- maintain current operating-system, browser, and security updates;
- avoid accessing the Platform through public or untrusted devices;
- use reasonable caution with links, attachments, and login requests;
- verify the identity of persons requesting information;
- avoid downloading confidential information unless necessary;
- securely delete or destroy downloaded information when no longer required; and
- promptly report suspected unauthorized access, phishing, lost devices, or unusual account activity.
12. Reporting a Security Concern
Suspected vulnerabilities, unauthorized access, phishing messages, lost devices, or other security concerns should be reported promptly to:
Security Contact: security@brlfirm.com
Telephone: (631) 210-7272
Reports should include sufficient information to investigate the concern but should not include unnecessary confidential client information, passwords, Social Security numbers, or complete financial-account information.
Users should not publicly disclose a suspected vulnerability before giving the Firm a reasonable opportunity to investigate and remediate it.
13. No Absolute Guarantee
Although the Firm maintains safeguards designed to reduce security risks, no internet-based system, transmission method, authentication process, or storage environment can be guaranteed to be completely secure. This statement describes the Firm’s general security approach. It is not a warranty that every listed safeguard applies identically to every system, user, integration, or type of information.
14. Updates
The Firm may update this Security Statement as its technology, practices, service providers, and legal obligations change. The “Last updated” date identifies the current version.
← Back to sign in