Trust

How access works

If it holds client files, you should be able to read how access works on this page, not in a buried PDF.

Sign in with the firm’s identity

Microsoft 365 or Google. No extra password to invent for SPBX. The app lives at login.spbx.pro; after sign-in it knows which firm you belong to.

Authenticator MFA, required

Every role enrolls an authenticator app. Sign-in is not complete without it — the app, APIs, and database rules reject a session that skipped the second factor. Permanent document deletes also require a fresh confirmation.

Your firm, only your firm

Every record is tagged to a firm. The system rejects reads and writes that cross that line. Hiding a menu item is not the control.

Scoped people stay scoped

Staff see assigned cases. Contract attorneys see approved cases only. Asking for another case by URL returns a permission error, not an empty screen.

Documents are never public

Files sit in private storage. The app mints a short-lived signed URL when someone with access needs to open one.

An audit trail

Creates, updates, uploads, deletes, logins, and permission denials are written down. That’s the record you can look at later.