Legal

Clients now ask who touched the matter.

Schedule a meeting

Law firms under ABA Model Rules, client guidelines and GDPR

Security built for law firms and their clients

Hand clients and courts a record of document and email activity they can check themselves.

Obligations

ObligationARRTECH recordStays with the firm
ABA Rule 1.6(c), Op. 483: monitorDirectory, VPN, Microsoft 365 and file server logs, with a silent-source alert. →Document management logs need a parser.
Op. 483 and client guidelines: notifyA case timeline showing what was touched. →The notice itself.
Op. 512: generative AIPrompts and uploads inspected, blocked and logged. →The client consent process.
FRE 902(14)Hash, signature, chain and a standalone verifier. →The admissibility ruling.
FRCP 37(e): preservationSigned records kept per source. →A legal hold workflow.
SRA Code for Firms 2.2Signed records and a console audit log. →Your compliance records.
Ethical wallsNo record claimed. →Enforcement inside the document system.

Client audits

Show clients who touched their matter

Client security questionnaires often ask who accessed their files. ARRTECH keeps a signed record of document, email and remote access activity, so you can show who touched a matter.

ABA Rule 1.6(c)

Stop client files leaving by email or USB

ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information. ARRTECH DLP checks email before it is sent and controls uploads, USB drives and printing.

Control what goes into AI tools

Prompts and uploads to AI tools are checked and logged.

FBI IC3 alert

Spot the Silent Ransom Group

In 2025, the FBI warned that the Silent Ransom Group targets law firms, using remote access tools and file transfers to steal data. ARRTECH DLP can block those tools, and Cyberdroid AI Detection flags unusual programs and network activity.

By rule

ABA Rule 1.6(c), Op. 483: monitor

ARRTECH: Directory, VPN, Microsoft 365 and file server logs, with a silent-source alert.

Op. 483 and client guidelines: notify

ARRTECH: A case timeline showing what was touched.

Op. 512: generative AI

ARRTECH: Prompts and uploads inspected, blocked and logged.

FRE 902(14)

ARRTECH: Hash, signature, chain and a standalone verifier.

FRCP 37(e): preservation

ARRTECH: Signed records kept per source.

SRA Code for Firms 2.2

ARRTECH: Signed records and a console audit log.

Ethical walls

Keep matter teams apart. Not covered: ARRTECH does not enforce or record ethical walls inside your document system.

Questions

Would we spot the Silent Ransom Group?

The FBI says to watch for newly installed remote access tools and file transfers to outside addresses. ARRTECH DLP can block those tools. Cyberdroid AI Detection flags programs and network activity that are unusual for your firm and shows the evidence.

Can client documents leave by email or USB?

ARRTECH DLP checks email before it is sent, inspects web uploads, controls USB drives and printing, and recognizes excerpts of protected documents. Rules cover departing lawyers and personal email addresses.

What about AI tools?

ABA Formal Opinion 512 says lawyers need informed client consent before putting client information into AI tools that learn from it. ARRTECH DLP checks prompts and uploads and can block and log them.

Who approves an action?

A person. ARRTECH SOAR emails the approver up to five options and waits. The history shows who chose what and when.

What stays with the firm?

Ethical walls inside your document system, legal holds, and whether a court accepts the record. Cyberdroid AI Detection reports about once an hour and never blocks.

Sources

Guide

What does ABA Formal Opinion 483 require?

Lawyers must monitor for breaches, stop them promptly, and notify clients when client data is affected.

Can law firms use AI tools with client data?

ABA Formal Opinion 512 says informed client consent is needed before putting client information into self-learning AI tools.

What is FRE 902(14)?

A federal evidence rule that lets data self-authenticate through digital identification, usually a hash value.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.