Security
How we protect your firm’s data and your clients’ privilege.
Global Wakili is built for the confidentiality demands of legal practice. Security is designed into the architecture — not bolted on afterwards.
Tenant isolation
Every firm’s data is architecturally separated from every other firm. Tenant filtering is enforced at the database layer across 116 data models, making cross-tenant access impossible by design rather than by policy.
Encryption
- Data at rest encrypted with AES-256-GCM.
- Data in transit protected with TLS 1.3.
Tamper-evident audit trail
Critical actions generate immutable audit records secured with a SHA-256 hash chain, so the audit log cannot be silently altered.
Access control
Role-based access control (RBAC) with 400+ granular permissions governs who can see and do what. Trust accounting enforces three-way reconciliation and overdraw prevention.
AI safeguards
AI features run behind human-review gates with prompt-injection protection. Sensitive fields are redacted before any external API call, and we never use your data to train models.
Infrastructure & privilege
Data is hosted on geo-redundant Neon Postgres. Attorney-client privilege is protected at every layer, consistent with the Kenya Data Protection Act 2019 and ISO 27001-aligned practices.
Reporting a vulnerability
If you believe you’ve found a security issue, please email wakili@globalsitesltd.com. We appreciate responsible disclosure.