Security & trust

Built for confidential matter work.

Last updated June 2026

Mandate holds privileged, client-sensitive material. The platform is designed so that a firm's matters are isolated, every action is permanently recorded, and disclosure to a client is always the firm's deliberate choice.

Tenant isolation

Each firm is a separate tenant. Matter data is partitioned and access is enforced at the database row level, so one firm can never read another firm's matters.

Operator access is scoped to the authenticated firm. Application queries run within the firm's tenant context.

Immutable record

Every action on a matter is appended to a time-stamped ledger. Entries are never edited or deleted in place, which preserves a defensible record of what was done and when.

State changes follow a fixed lifecycle and are logged as part of the same record.

Controlled disclosure

The client progress view is read-only and shows only the entries a firm explicitly marks visible. Internal notes and operator detail are never exposed through it.

Client access is granted through a non-guessable, single-purpose link that the firm can revoke at any time.

Transport and credentials

All traffic is served over TLS. Sessions are signed and time-bounded, and passwords are stored only as salted, hashed values.

Service-to-service calls within the platform are authenticated with signed, timestamped requests to prevent replay.

Access and onboarding

Registration is by invitation. New firms are provisioned individually rather than through open sign-up.

Reporting a security concern: contact your Kinetic point of contact directly and it will be routed for review.