Operational technology built for how law firms actually work
Updated
Legal Practice
Twenty-three production deployments across marketing, CRM, accounting, HR, AI, and IT operations. Custom builds where the workflow is firm-specific. Configured platforms where commercial tools fit. Deep integration with the systems firms already run on: Aderant Expert, Thomson Reuters Elite 3E, iManage, FileSurf, Intapp, CourtAlert, USPTO PAIR, PACER/ECF, and the broader legal-tech ecosystem. One deployment, a native iOS docketing application built in under six months for a top-tier IP firm, earned a Financial Times award for best use of technology in legal.
Discovery first. Proof of concept before the build.
Every engagement on this page started the same way. We did not show up with a solution. We showed up with questions, and we did not propose anything until we understood the problem well enough to defend the approach to a skeptical partner.
-
01
Discovery
We sit with the people who actually do the work. Partners, paralegals, billing coordinators, IT operations, the conflicts team, the GC. We watch the workflow, read the systems, map the failure modes. We do not propose anything in this phase. The deliverable is a written problem statement we agree on before any architecture conversation begins. If the problem is not what the firm thought it was, we say so.
-
02
Proof of Concept
Before the firm commits to a full build, we deliver a working proof of concept against the firm's real data, real systems, and real constraints. Not a slide deck. Not a wireframe. Working code, integrated with whatever the firm runs (Aderant, Elite 3E, iManage, Intapp, the docketing system), demonstrating that we understood both the problem and the technical environment. The proof of concept is the contract: if it does not convince the partners and the IT team, the engagement does not proceed.
-
03
Production Build
Once the proof of concept is validated, we execute the production build against a scope and timeline both sides have signed off on. The architecture choices, integration patterns, and edge cases are settled by the time we start writing production code. The case studies on this page are what came out of that process.
Two ways we build for law firms.
The right approach depends on whether the workflow is specific to how the firm operates, or whether a well-configured commercial platform gets you most of the way there at lower cost. Most firms end up with a mix.
When commercial tools cannot model what the firm actually does.
IP prosecution, environmental matter management, partner economics, cross-office expertise mapping. The workflows that make the firm distinctive are usually the ones no vendor has bothered to build for. We build alongside the systems the firm already runs on, not in place of them.
- Typical build4 to 11 months
- Team size6 to 14 engineers
- StackPython, Node, .NET, Postgres, Neo4j, React, native iOS/Android
- Integrates withAderant, Elite 3E, iManage, NetDocuments, Intapp, ProLaw, USPTO, ECF
- OwnershipSource code transferred to firm
When the right tool exists and the value is in setting it up correctly.
Docketing, AP automation, helpdesk, candidate screening, content automation. Strong commercial platforms exist. The work is in fitting them to law firm taxonomies, integrations, ethical walls, and approval flows so they actually get used. Configuration is the difference between a tool that ships and a tool that adopts.
- Typical setup6 to 14 weeks
- PlatformsIntapp, CourtAlert, FirmPilot, ServiceNow, Greenhouse, Bill.com, Abnormal, Litera
- ConfigurationTaxonomy, ethical walls, integrations, training, governance
- Managed serviceOptional ongoing tuning and support
- Time to valueMeasured in weeks, not quarters
Nothing on this page matters if the firm cannot answer the confidentiality question first. So here is the obligation, stated from the rules themselves rather than from us, and then what a build does about it. We are describing your duty, not claiming a credential of our own.
There is working software to look at every two weeks rather than a status report.
We do not publish a price for this work, because the range is set by the firm rather than by our rate.
Sthenos holds no independent attestation of its own, and that includes SOC 2: we are not SOC 2 attested.
The repository and the cloud accounts are in your name, with no licence back to us.
On this page
- Confidentiality, privilege and the questions a firm's general counsel will ask
- The services behind a law firm build
- When client data is also somebody else's regulated data
- E-discovery and court filing: the formats a build has to respect
- What drives the cost of legal operations software
- How the work is scheduled
- What to ask any firm building software for a law practice
- Frequently asked questions
- More about legal technology
- Talk to our engineers
Confidentiality, privilege and the questions a firm's general counsel will ask
The duty, in the rules' own words
Confidentiality. ABA Model Rule 1.6(a) provides that "a lawyer shall not reveal information relating to the representation of a client" absent informed consent or one of the listed exceptions, and Rule 1.6(c) adds the sentence that reaches software directly: "A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."
What "reasonable efforts" is measured against. Comment [18] to Rule 1.6 names the factors: "the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely affect the lawyer's ability to represent clients". It also records that a client "may require the lawyer to implement special security measures not required by this Rule". That is the clause a client security addendum runs on.
Technology competence. Comment [8] to Rule 1.1 says a lawyer "should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology".
Outside vendors, which is what we are. Rule 5.3 puts responsibility for nonlawyer assistance on the firm, and Comment [3] is explicit about the software case. It gives as examples "hiring a document management company to create and maintain a database for complex litigation" and "using an Internet-based service to store client information", and states that "when using such services outside the firm, a lawyer must make reasonable efforts to ensure that the services are provided in a manner that is compatible with the lawyer's professional obligations". The factors it lists are the diligence checklist: "the education, experience and reputation of the nonlawyer; the nature of the services involved; the terms of any arrangements concerning the protection of client information; and the legal and ethical environments of the jurisdictions in which the services will be performed, particularly with regard to confidentiality".
The binding rule is your jurisdiction's, not the ABA's. The Model Rules are a model. The ABA's own preface records that they were adopted by its House of Delegates in 1983 and that, at the time that edition went to press, all but eight jurisdictions had adopted professional standards based on them. In Virginia, where our office is, the Virginia Rules of Professional Conduct carry the same duty in their own wording at Rule 1.6(d), "A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information protected under this Rule", and Comment [6] to Virginia's Rule 1.1 adds that "Attention should be paid to the benefits and risks associated with relevant technology".
What that means inside the build
Figure 1. The confidentiality perimeter, from the duty to the evidence
Nothing in this diagram is counted. The seven boxes are the seven rows of the table immediately below, and the quotation is ABA Model Rule 1.6(c) as the American Bar Association publishes it.
Every row below is a build practice, not a certification. We build to these and hand over the evidence; the firm's own obligation stays the firm's.
| Obligation | What it looks like in the software | What goes wrong when it is added later |
|---|---|---|
| Access control | Permissions at matter level, enforced centrally on every route rather than screen by screen, with membership changes recorded | Retrofitting authorisation across a live API is close to a rewrite |
| Conflict and ethical walls | An access rule, not a policy note: a wall is a matter level deny that the application enforces and can prove, with a record of who was granted and removed and when | A wall that lives in a memo cannot be evidenced when somebody asks |
| Audit logging | Who opened which matter document, when, and from where, in a store nobody can quietly edit | You cannot reconstruct history you never recorded |
| Encryption | In transit and at rest, with keys managed outside the application | Key rotation designed in later means downtime |
| Data residency | A decided answer to where data sits and where engineers sit, written into the contract rather than discovered in diligence | Comment [3] to Rule 5.3 makes the jurisdiction a diligence factor, so a late answer is a late problem |
| Retention and deletion | Rules per data class, and deletion that reaches every copy including backups, search indexes and exports | Deletion is the hardest thing to bolt on to a system that assumed nothing ever leaves |
| Vendor terms | Confidentiality, subcontractor disclosure and breach notice settled in the agreement before any client data moves | An unlisted subprocessor found during diligence stalls the engagement |
Our own posture, stated plainly. Sthenos holds no independent attestation of its own, and that includes SOC 2: we are not SOC 2 attested. What we do is build to the controls the firm's obligations require, run them, and hand over the evidence trail so the firm's own answer to a client security questionnaire has something behind it. If you want the same statement in the security context, we publish it on our cybersecurity page as well: we help you prepare and evidence these frameworks rather than making claims about our own attestation status.
The services behind a law firm build
The two delivery models above describe how we engage. These are the service lines the work is staffed from, each with the page that describes it in full.
- Custom software. Custom software development and enterprise software development for the workflows that are specific to how the firm operates.
- Client and matter systems. CRM, ERP and finance, and content management work, which is where most firm operations software actually lives.
- AI and knowledge. Artificial intelligence and machine learning and agentic AI, applied where the answer can be checked, with the confidentiality question settled before any document reaches a model.
- Analytics. Data analytics for realisation, utilisation, pipeline and partner economics reporting.
- Cloud. Cloud computing and cloud migration and optimization, where residency is a design input rather than a default.
- Security and testing. Cybersecurity, penetration testing and software testing. Client security questionnaires ask about testing, so it is worth being able to answer with a report.
- Automation. Robotic process automation and automation for intake, conflicts checking support, billing preparation and the rekeying between systems that do not talk.
- Run and support. Managed services and infrastructure management, so the system has an owner after go live.
- Mobile. Mobile application development for the docket, time capture and approvals that partners will not do at a desk.
- People. Team augmentation when the firm's IT team needs capacity rather than direction.
Sthenos has delivered software development, IT and Microsoft 365, security, and website work for an intellectual property law firm in Washington, DC.
When client data is also somebody else's regulated data
A firm's confidentiality duty is not the only rule in the room. Depending on the client, the same records can carry obligations that come from health, privacy or consumer law, and those reach the vendor as well as the firm.
HIPAA, when the matter involves protected health information
The Department of Health and Human Services lists, among its own examples of a business associate, an "attorney whose legal services to a health plan involve access to PHI", and separately an "IT contractor or vendor" whose support services require it "to create, receive, maintain, or transmit ePHI". HHS also states that "a business associate must establish a BAA with its subcontractor before disclosing PHI to the subcontractor for work to be done for a covered entity", and that all such downstream subcontractors are themselves business associates. So where a firm is a business associate and the software touches PHI, the paper has to exist before the data moves, not after.
What we do. The question of whether PHI will reach a build or test environment belongs in discovery, and the answer changes the environment design.
GDPR, when the firm processes personal data of people in the EU
Article 28 of the General Data Protection Regulation says a controller "shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures", that "the processor shall not engage another processor without prior specific or general written authorisation of the controller", and that the processing has to be governed by a contract setting out its subject matter and duration, its nature and purpose, the type of personal data and the categories of data subjects. The contract must state that the processor processes personal data "only on documented instructions from the controller" and ensures that authorised persons "have committed themselves to confidentiality".
What we do. We settle subprocessor disclosure in the agreement before any client data moves, and we design so that "documented instructions" is enforceable in the system, not just in the contract.
CCPA, when the firm holds personal information about California residents
The California Attorney General describes the California Consumer Privacy Act as giving consumers the right to know what personal information a business collects and how it is used and shared, the right to delete personal information collected from them with some exceptions, the right to opt out of the sale or sharing of their personal information, and the right to non-discrimination for exercising those rights. It records that Proposition 24, the CPRA, added rights to correct inaccurate personal information and to limit the use and disclosure of sensitive personal information from 1 January 2023, and that businesses subject to the law have responsibilities including responding to consumer requests and giving certain notices.
What we do. We build the deletion and correction paths as first class operations that reach every copy, because a rights request that a system cannot execute becomes a manual process somebody has to run forever.
E-discovery and court filing: the formats a build has to respect
EDRM, the Electronic Discovery Reference Model
Who issues it, and whom it binds. EDRM. It is a reference model rather than a rule, and it binds nobody, which is precisely why it is useful as shared vocabulary between counsel, the client and the engineers. EDRM 2.0, released on 1 September 2026, is described by EDRM as the first substantive update to the model since it incorporated the full Information Governance Reference Model, developed by approximately 150 multidisciplinary practitioners across the EDRM community.
- Identification"determining the scope of the matter and relevant ESI and document sources"
- Preservation"safeguarding relevant ESI and documents against alteration or destruction"
- Reviewevaluating documents "for relevance, responsiveness, privilege, confidentiality, privacy, and/or issue significance"
- Disposition"a systematic, defensible process to retain, delete, transfer or return data after use"
Those four phase definitions are EDRM's own words.
What a software build has to do under it. Two of those phases are architecture. Preservation means a legal hold that survives a user pressing delete and a retention job running overnight. Review means privilege is a field on the record with its own history, not a note in a comment box.
What we do. We design hold and privilege as system states with their own audit trail, and we make disposition an explicit action rather than a side effect of a cleanup script.
CM/ECF, filing into the federal courts
Who issues it, and whom it binds. The federal Judiciary. The U.S. Courts describe Case Management/Electronic Case Files as "the federal Judiciary's system that allows case documents, such as pleadings, motions, and petitions, to be filed with the court online", note that filing "requires a PACER account and special access issued by an individual court", and record that "attorneys and other filers are required to acknowledge their responsibility to redact 'personal identifier' information each time they log in to CM/ECF".
What a software build has to do under it. Redaction is a workflow step with a record attached, not a rendering option, and the docket number is the join key between the firm's systems and anything the court holds. Access is granted per court, so a single credential model will not survive contact with a multi jurisdiction practice.
What we do. We model the court and the docket as first class entities, and we keep the redaction decision, its author and its timestamp with the document rather than in a separate log.
What drives the cost of legal operations software
We do not publish a price for this work, because the range is set by the firm rather than by our rate. These are the factors that actually move the number.
- Whether the workflow is firm specific or industry standard. Configuring a strong commercial platform and building a system nobody sells are different orders of effort, which is the distinction the two models above are drawing.
- How many systems of record the data has to cross. Practice management, document management, docketing, finance, HR and the intranet each have an owner, a release schedule and an opinion.
- Whether the integration targets have documented APIs. A supported API is an integration. An export file and a scheduled job is a small product with its own failure modes.
- The confidentiality perimeter. Matter level permissions, ethical walls and per client security addenda change the data model, not just the settings screen.
- Whether other people's regulated data is in scope. PHI, EU personal data or California consumer data each add contractual and design work, as above.
- Taxonomy. Practice areas, matter types, client hierarchies and rate structures are the firm's own language, and mapping it is discovery work that cannot be skipped.
- Data migration. Years of matter history in a shape nobody documented is usually the largest single unknown in a replacement project.
- How many people have to change what they do. Adoption work is real work, and a system partners will not use has a cost of its own.
- Reporting depth. A dashboard is cheap. A number a managing partner will defend in a partners' meeting is not.
How the work is scheduled
We work in two week sprint cycles, so there is working software to look at every two weeks rather than a status report. Discovery comes first, and as the methodology above says, it produces a written problem statement both sides agree on before any architecture conversation begins.
We do not publish a duration for a project we have not scoped. On a first call we will tell you which parts of the work are known and which are discovery, and say plainly which is which. The standard we hold our own delivery to is published in full as the production readiness checklist.
What to ask any firm building software for a law practice
These questions work on us as well as on anybody else the firm is talking to. If a vendor cannot answer them, that is the answer.
- Where will our data be stored, and where will the engineers who can read it be sitting? Comment [3] to Rule 5.3 makes the jurisdiction of performance a diligence factor, so this is an ethics question wearing an IT costume.
- Will you sign a confidentiality agreement before the first call, and what does it say about subcontractors? Ask for the subprocessor list, not a reassurance.
- How is an ethical wall enforced in your system, and can you show me the record of who was inside it? A wall that cannot be evidenced is a policy, not a control.
- Which of your security claims are audited and which are self declared? Then ask for the report and its date. Anybody can print a badge.
- If a client demands deletion, what does your system delete and what does it miss? Listen for whether backups and search indexes come up unprompted.
- How does a legal hold survive a user deleting a document? If the answer is a policy rather than a state in the system, it is not a hold.
- Who owns the code, the repository and the cloud accounts when we are done? Get it in writing before the first invoice.
- What happens to the work if you disappear? Ask about handover, documentation and whether anything depends on the vendor continuing to exist.
Frequently asked questions
Does using an outside developer waive privilege?
That is a question for the firm's own counsel and its jurisdiction's rules, not for a vendor. What the ABA Model Rules do address is the duty: Rule 5.3 makes the lawyer responsible for making reasonable efforts to ensure an outside nonlawyer's services are compatible with the lawyer's professional obligations.
What should a firm require in a vendor confidentiality agreement?
Comment [3] to ABA Model Rule 5.3 points at the terms of any arrangements concerning the protection of client information, and at the legal and ethical environments of the jurisdictions where the work is performed. In practice that means confidentiality, named subprocessors, data location and breach notice.
Does Sthenos hold a SOC 2 report?
No. Sthenos holds no independent attestation of its own, and that includes SOC 2: we are not SOC 2 attested. We build to the controls, run them, and hand over the evidence trail, and we tell you that in the first conversation rather than at procurement.
What is an ethical wall in software terms?
An access rule the application enforces rather than a memo people are asked to respect. In a build it is a matter level deny, applied centrally, with a record of who was placed inside or outside the wall and when, so the firm can evidence it later.
What does GDPR require of a firm's software vendor?
Article 28 requires the controller to use only processors giving sufficient guarantees, bars a processor from engaging another processor without the controller's written authorisation, and requires a contract fixing the subject matter, duration, nature and purpose of processing and the categories of data involved.
Does a law firm ever need a business associate agreement?
HHS lists an attorney whose legal services to a health plan involve access to protected health information as an example of a business associate. Where that applies and a vendor will touch that data, HHS states the agreement has to be in place before the information is disclosed.
Why does a matter management build cost more than a CRM?
Because the confidentiality perimeter is part of the data model. Matter level permissions, ethical walls, privilege as a tracked field and deletion that reaches every copy are structural decisions, where a CRM can usually treat access as a role on a record.
Who owns the code and the cloud accounts?
You do, entirely, from the first commit. The repository and the cloud accounts are in your name, with no licence back to us and no dependency on us continuing to exist.
More about legal technology
- Services. Custom software development, CRM, AI and machine learning, data analytics, cybersecurity, penetration testing, managed services, team augmentation.
- Rules and standards, at the source. ABA Model Rule 1.6, Rule 1.1 comment, Rule 5.3 comment, Virginia Rules of Professional Conduct, HHS on business associates, GDPR, California Attorney General on the CCPA, the EDRM model, CM/ECF.
- Insights and related work. What SOC 2 compliance means, what FedRAMP is, the production readiness checklist, and talk to our engineers.
If something on this page sounds like a problem you actually have, we should talk.
We do not run discovery calls to qualify you. Send a short note describing the workflow that is not working, and we will tell you whether we have built it before, what it would take, and whether you should buy a platform instead.