Legal
Privacy Policy
Securing Your Law Firm — a service of Cyber Bulwark, LLC
Effective date: July 31, 2026 · Last updated: July 31, 2026
1. Who we are and what this policy covers
Cyber Bulwark, LLC ("Cyber Bulwark," "we," "us," or "our") provides cybersecurity assessments, email security hardening, and Microsoft 365 migration and hardening services to small and mid-sized law firms.
This Privacy Policy explains what information we collect, why we collect it, how we protect it, and the choices you have. It applies to:
- The website at securingyourlawfirm.com and any subdomains;
- The Proprietary Exposure Review;
- Email, phone, and other communications with us; and
- Information we handle in the course of delivering paid engagements.
This policy does not override any executed engagement letter, master services agreement, non-disclosure agreement, or outside counsel guidelines you have with us. Where those documents impose stricter confidentiality or data-handling obligations than this policy, those documents control.
2. Our core commitments, in plain English
Because our clients are law firms holding privileged and confidential client information, we hold ourselves to a stricter standard than a typical marketing site. Specifically:
- We do not sell your personal information. Ever. We have never sold personal information and we do not share it for cross-context behavioral advertising.
- We do not disclose the findings about your domain to anyone outside our firm. Your exposure review results, assessment findings, configuration details, and remediation evidence are not published, syndicated, resold, listed in a directory, shared with vendors, shared with insurers, or provided to any third party without your written instruction — except in the narrow legally compelled circumstances described in Section 10.
- We do not use your findings to market to you as a "problem firm," and we do not use them as case studies, testimonials, screenshots, or examples without your specific written permission.
- We keep the work in-house. Assessment analysis, report generation, and engagement work are performed by our own personnel. We do not outsource, offshore, or subcontract the analysis of your environment or your findings.
- We collect the minimum we need. The free exposure review requires only a domain and a work email.
- We never access anything private to run a free review. The free exposure review uses only publicly available DNS and web records — no credentials, no logins, no scanning of private systems, no intrusive testing.
- We take no referral fees and resell no software, so we have no commercial incentive to pass your information to anyone.
3. Information we collect
3.1 Information you provide to us
| What | When | Why |
|---|---|---|
| Firm domain name | Exposure review, contact forms | To run the review against the correct organization |
| Work email address | Exposure review (required), contact | To verify the request is from the firm itself and to deliver results |
| Name, title, phone number | Contact, scoping calls, engagements | To communicate and scope work |
| Firm name, size, practice areas | Scoping and proposals | To scope an engagement accurately |
| Message content | Contact form, email, calls | To respond to your inquiry |
| Billing and payment details | Paid engagements | To invoice and collect payment |
We do not ask for, and ask that you not send us, sensitive personal information (such as government identifiers, financial account numbers, health information, or biometric data) through our web forms.
3.2 Publicly available technical information
To produce the Proprietary Exposure Review, we query information that is already publicly published and available to anyone on the internet, including:
- DNS records (MX, SPF, DKIM, DMARC, and related records);
- WHOIS/RDAP registration data as publicly published;
- Publicly resolvable subdomains and hostnames;
- TLS/HTTPS certificate transparency data and public certificate metadata;
- HTTP response headers and other publicly served web configuration;
- Publicly registered domains that closely resemble your firm's domain ("lookalike" domains); and
- Publicly indexed exposure signals of a similar nature.
We do not authenticate to, log into, scan, probe, or attempt to access any private system, mailbox, tenant, or network to produce a free review. These are passive, read-only queries against public records.
3.3 Engagement data (paid clients only)
If you engage us for the Security Baseline, Email Hardening, or Cloud Migration services, we will necessarily handle more sensitive material, which may include:
- Microsoft 365 / Entra ID tenant configuration, policy, and audit settings;
- Email authentication and routing configuration;
- User account inventories, group memberships, role assignments, and sign-in policy data;
- Sharing, retention, and administrative control settings;
- Delegated or time-bound administrative access credentials you provision to us;
- Before-and-after evidence artifacts (screenshots, exports, configuration snapshots); and
- Assessment findings, risk ratings, and remediation recommendations.
Scope of access is agreed in writing before work begins. We request the least privilege necessary, for the shortest duration necessary, and we do not request access to matter files, document management systems, or client work product unless it is expressly and specifically necessary to a defined task you have authorized in writing.
3.4 Information collected automatically
When you visit our website we may collect standard technical information such as IP address, browser type and version, device type, operating system, referring page, pages viewed, and timestamps. This is used for site operation, security, abuse prevention, and aggregate traffic measurement.
We do not use third-party analytics, advertising cookies, or tracking pixels. We do collect standard server logs (IP address, browser type, pages viewed) for security and abuse prevention, as described above.
4. How we use information
We use the information described above only for the following purposes:
- To run and deliver the free exposure review you requested;
- To verify that a review request comes from the firm that owns the domain;
- To respond to inquiries and provide requested information;
- To scope, quote, deliver, document, and support paid engagements;
- To produce deliverables for you — partner reports, evidence packages, client-facing one-pagers, and remediation roadmaps;
- To invoice and collect payment;
- To maintain the security, integrity, and availability of our own systems, and to prevent abuse of our free tools;
- To improve the quality and accuracy of our own methodology using our internal records only, and never by exposing an identifiable firm's findings; and
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use your information for automated decision-making that produces legal or similarly significant effects about an individual, and we do not profile individuals for advertising.
5. Confidentiality of assessment findings
This section is the heart of this policy and we treat it as a binding commitment.
Your findings are yours. Any exposure review result, assessment finding, configuration detail, evidence artifact, gap, weakness, or remediation record associated with your firm or your domain is treated as confidential information of your firm.
We commit that we will not:
- Publish, post, or display your findings, in whole or in part, in any public or semi-public forum;
- Provide your findings to any other law firm, competitor, vendor, marketing partner, data broker, threat intelligence feed, insurer, or ranking or scoring service;
- Include your firm's name, domain, logo, findings, or screenshots in marketing materials, case studies, testimonials, sales decks, conference talks, or social media without your specific, written, opt-in permission;
- Contribute your findings to any shared, industry, benchmarking, or aggregate dataset that is disclosed outside our firm; or
- Use your findings for any purpose other than delivering and supporting the services you asked for.
6. Professional confidentiality, privilege, and work product
We understand that our clients operate under professional responsibility obligations, including duties of confidentiality (e.g., ABA Model Rule 1.6 and state analogues), the duty of technology competence (ABA Formal Opinion 477R), and breach-notification obligations to clients (ABA Formal Opinion 483).
Accordingly:
- We treat all firm information as confidential by default, without regard to whether it is marked confidential.
- We recognize that we may incidentally encounter information subject to the attorney-client privilege or the work-product doctrine. We do not seek out such information, we do not review it beyond what is strictly necessary, and encountering it does not diminish its protected status. We will notify you promptly if we believe we have been given access beyond agreed scope.
- Where you engage us in anticipation of litigation or at the direction of counsel, we will cooperate reasonably with arrangements intended to preserve privilege, including Kovel-style or counsel-directed engagement structures.
- We are prepared to execute a firm-specific NDA, sign your outside counsel guidelines, and complete client security questionnaires on request.
- If you are subject to sector-specific obligations flowing down from your own clients (for example, HIPAA business associate terms or CJIS requirements), tell us during scoping so we can paper it correctly.
7. We do not sell or share personal information
We do not, and will not, sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) and comparable state laws. We have not done so in the preceding twelve (12) months.
We do not permit third parties to place advertising or tracking technologies on our site for their own purposes.
8. Service providers
We keep analysis and engagement work in-house. However, like any business, we rely on a small number of infrastructure and business-operations providers to run the website and communicate with you. These providers include Vercel for front-end web hosting, Railway for backend hosting services, and QuickBooks for invoicing.
Where we use such providers:
- They are bound by written agreements that limit them to processing information only on our instructions and only to provide the service to us;
- They are prohibited from selling or independently using the information;
- We select providers that offer encryption in transit and at rest and that maintain recognized security certifications; and
- We do not send assessment findings, engagement evidence, or client environment data to any provider except as strictly necessary for storage or transmission, in encrypted form, under contract.
We do not transfer your information to third parties for their own marketing purposes under any circumstances.
9. Requests concerning domains you do not control
The Proprietary Exposure Review requires a work email matching the domain requested.
You may only submit a domain that your organization owns or that you are authorized to request a review for. Submitting another organization's domain without authorization may violate our terms and applicable law.
We log the domain, the submitting email address, IP address, and timestamp for each request, for abuse prevention and to be able to respond to any complaint that a review was requested improperly.
If you believe a review of your firm's domain was requested by someone without authority, contact us at info@securingyourlawfirm.com and we will investigate, tell you what was requested and when, and suppress the domain from future requests on request.
10. Legally compelled disclosure
We will not disclose your information to law enforcement, regulators, or private litigants except where we are legally compelled by a valid subpoena, court order, warrant, or other binding legal process, or where disclosure is necessary to protect against imminent harm.
If we receive such a demand relating to a client's information, and unless we are legally prohibited from doing so, we will:
- Notify you promptly and before producing anything, so that you have a meaningful opportunity to object, move to quash, or seek a protective order;
- Object to overbroad demands and seek to narrow the scope to the minimum required;
- Assert any applicable protections, including confidentiality, privilege, and work-product objections available to you, and defer to your counsel's direction where you elect to intervene; and
- Produce only what is legally required, and, where possible, under seal or subject to a protective order.
Where a legal prohibition on notice expires, we will notify you at the earliest permissible time.
11. How we protect information
We apply the same controls to our own environment that we recommend to clients, including:
- Multi-factor authentication on all administrative and email accounts;
- Encryption in transit (TLS) and encryption at rest for stored findings and engagement data;
- Least-privilege access, with engagement data accessible only to personnel working that engagement;
- Time-bound, just-in-time administrative access to client tenants, revoked at engagement close;
- Endpoint protection and patch management on all systems used to deliver services;
- Logging and monitoring of access to client data;
- Secure deletion procedures at the end of the applicable retention period; and
- Written incident response procedures.
Breach notification.
If we experience a security incident affecting your information, we will notify you without undue delay and in any event within seventy-two (72) hours of confirming the incident, and we will provide the information you need to satisfy your own notification obligations to your clients, your insurer, and any applicable regulator.
No system is perfectly secure, and we do not claim otherwise. We do commit to being transparent with you if something goes wrong.
12. How long we keep information
| Category | Retention |
|---|---|
| Free exposure review requests and results | 12 months, then securely deleted |
| Prospect and inquiry contact information | 24 months from last contact, or until you ask us to delete |
| Engagement working data (configuration exports, evidence artifacts) | Duration of engagement plus 12 months, then securely deleted |
| Final deliverables (reports, roadmaps, evidence packages) | 3 years, to support your audit, insurance, and client-questionnaire needs |
| Contracts, invoices, and financial records | As required by law and applicable statutes of limitation, typically 7 years |
| Website and security logs | Up to 12 months |
Early deletion on request.
At any time after an engagement ends, you may request accelerated deletion of your engagement data and findings via written request. We will comply within thirty (30) days and provide written confirmation of deletion, retaining only what we are legally required to keep (typically contracts and invoices).
13. Your choices and rights
Regardless of where you live, you may:
- Ask what we hold about you or your firm;
- Correct inaccurate information;
- Request deletion of your information, subject to legal retention requirements;
- Request a copy of your information in a portable format;
- Opt-out of all marketing communications, at any time, by replying to any email or contacting us. We will still send transactional and engagement-related messages;
- Withdraw consent where processing is based on consent; and
- Request suppression of your domain from future free-review requests.
To exercise any of these, email info@securingyourlawfirm.com with the subject line "Privacy Request." We will acknowledge within ten (10) business days and respond substantively within forty-five (45) days, extendable once where permitted by law. We will verify your identity and authority to make the request before acting, using the email address on file or another reasonable method.
14. State privacy rights
Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — among other states with comprehensive privacy laws — may have specific statutory rights including access, correction, deletion, portability, opt-out of sale/share/targeted advertising, and opt-out of certain profiling.
We extend the rights described in Section 13 to all users regardless of residency, so you do not need to establish residency to exercise them.
Specific California disclosures.
In the preceding 12 months we have collected the categories of personal information described in Section 3, from the sources described in Section 3, for the business purposes described in Section 4, and we have disclosed personal information only to the service providers described in Section 8. We have not sold or shared personal information. We do not knowingly collect or process sensitive personal information for the purpose of inferring characteristics.
Authorized agents.
You may use an authorized agent to submit a request; we will require written proof of authorization.
Appeals.
If we decline a request, you may appeal by replying to our decision. If your appeal is denied, you may contact your state attorney general.
Global Privacy Control.
We honor the GPC browser signal as an opt-out of sale/sharing where applicable.
15. Users outside the United States
We are a United States business and process information in the United States. If you contact us from outside the U.S., your information will be transferred to and processed in the U.S., which may have different data protection laws than your country.
We provide strictly U.S.-only services.
16. Cookies and tracking
We do not use advertising cookies, retargeting pixels, or third-party trackers that build profiles of you across other websites.
Most browsers let you block or delete cookies. Blocking strictly necessary cookies may prevent parts of the site from working.
17. Third-party links
Our website may link to third-party sites and resources. We do not control those sites and are not responsible for their privacy practices. Review their policies before providing information to them.
18. Children
Our services are for businesses. We do not direct our services to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.
19. Not legal or compliance advice
Our assessments, reports, and findings are informational and technical in nature. They do not constitute legal advice, a legal opinion, a compliance certification, a formal audit, or a penetration test, and no attorney-client relationship is created by our provision of services. This Privacy Policy is a description of our practices and is not legal advice to you.
20. Changes to this policy
We may update this policy. When we do, we will revise the "Last updated" date above. If we make a material change — particularly any change to our commitments in Sections 2, 5, 7, or 8 — we will notify affected clients directly by email before the change takes effect, and we will not apply a materially less protective policy retroactively to information already collected without your consent.
We will maintain prior versions of this policy available on request.
21. Contact us
Email: info@securingyourlawfirm.com
Privacy requests: info@securingyourlawfirm.com (subject: "Privacy Request")
