Information barrier verification
Accounts across separate matters and teams, cross-access attempted across documents, matter records and search.
Clients do not retain a firm because of its document management system. They retain it on the assumption that what they share stays privileged — and increasingly they audit that assumption before instructing.
AIPTx tests the systems holding it, and produces the evidence the audit asks for.

Law firms hold concentrated, high-value confidential information and have historically invested less in protecting it than the organisations that give it to them.
The material is exceptional in both value and sensitivity: merger and acquisition plans before announcement, litigation strategy, intellectual property, regulatory investigation material, and personal information disclosed under privilege. A firm advising on a transaction holds information that is directly monetisable in a way that most corporate data is not. Firm structure adds a distinctive problem. Partnerships are not hierarchies.
Technology decisions are made collectively, security investment competes with distributable profit, and a partner who wants to work a particular way is difficult to overrule. Information barriers between matters are a professional obligation, and enforcing them in software is an authorisation problem of real complexity.
What has changed most recently is client behaviour. Corporate clients now issue outside counsel guidelines with specific security requirements, run vendor assessments on their law firms, and in some cases require evidence of testing before instructing. Security has become a condition of being retained.
Ethical walls prevent one team from accessing another's matter. Implemented in a document management system with decades of accumulated matters, exceptions and inherited permissions, they are exactly the kind of complex authorisation model where failures hide.
Firms increasingly share material through portals and hosted data rooms. Cross-client access in one of these is a professional catastrophe, not merely a security incident.
Many firms have an IT team and no dedicated security staff. The capacity to run a security programme, triage findings and maintain evidence is genuinely limited.
An outside counsel guideline requires evidence of testing, or a client's vendor risk team sends a questionnaire during a pitch. The response affects whether the firm is instructed.
Frequently the oldest core application in the firm, holding everything, integrated with everything.
Firms advising on transactions are targeted specifically, by parties with a clear financial motive and knowledge of exactly what they are looking for.
Senior individuals with broad access, high mobility, and limited tolerance for security friction.
Configure accounts on different matters and different teams, and the agent attempts cross-access while holding both sessions. A user reaching a matter they are walled from is an authorisation failure that only surfaces when two identities are compared, and it is the single most important thing to test in a legal environment.
Multi-role authenticated testing across client, fee earner and administrative accounts, with cross-client access attempted. Where a portal serves multiple clients, isolation between them is tested the same way a SaaS product's tenant isolation would be.
Findings arrive confirmed, with the exact request, the response proving it worked, a reproducible curl command, and remediation guidance including vulnerable and secure code examples. For a firm without dedicated security staff, this is the difference between a report that gets actioned and one that gets filed.
Reports include an executive summary, technical detail, control mapping for ISO 27001, SOC 2, GDPR, NIST, CIS and PCI DSS, and trend comparison against previous assessments, exportable as PDF, HTML, JSON, CSV or SARIF. When a client's vendor risk team asks, the answer is a document rather than a project.
The Docker-deployed agent covers internal IP ranges and CIDR blocks with outbound connectivity only, providing service, version, CVE, TLS and default credential coverage across the internal estate, including the document management infrastructure.
Firms accumulate microsites for practice groups, events, publications and legacy branding. Reconnaissance enumerates what is reachable, which is usually more than the IT team expects.
Retest re-runs the specific exploit and closes the finding only when the attack fails, with retest history attached, which is precisely what an outside counsel guideline asking for evidence of remediation wants to see.
Accounts on either side of a screen are held at once and each is pointed at the other's matter. A barrier that exists in the document management policy but not in the API behind it is only visible from that comparison.
Horizontal covers one user reaching a peer's records; vertical covers a junior role reaching a function reserved for a partner. Both are attempted against the roles you configure rather than inferred from the permission model.
Whatever the client portal authenticates with, the session is held for the length of the run, so testing does not stop at the login page of the systems that actually hold the work.
A token that outlives the matter it was issued for, or one whose claims a client can edit, hands over precisely what the engagement letter promised to protect.
Privileged material escapes by the incidental route far more often than the obvious one: a stack trace naming a client, an error message quoting the document it could not open.
The agent sits inside the network and reaches out, so nothing is opened inbound for it. Port, service and version detection, CVE matching, TLS posture and default credentials across the ranges you declare.
Firms accumulate sites the way they accumulate matters: a merged practice, a conference, a rebrand two names ago. The forgotten ones stay routable long after anyone is responsible for them.
Imported from a spec where one exists, discovered from live traffic and client bundles where it does not, which is how the endpoints the portal itself never calls get tested.
API SecurityPDF for the client security questionnaire, SARIF and JSON for the people fixing what it found, and the same underlying findings behind both answers.
Accounts across separate matters and teams, cross-access attempted across documents, matter records and search.
Multi-client testing with cross-client access attempted across shared portal infrastructure.
A client requires evidence of testing. Run a Standard assessment, export the report with control mapping.
Producing current testing evidence as part of a competitive submission.
Internal assessment of the infrastructure and application layer of the firm's core system.
Assessing a hosted data room configuration before confidential material is placed in it.
Assessing an acquired firm's systems before connecting them to the main estate.
Yes. By configuring accounts on separate matters and attempting cross-access between them. Information barrier failures are authorisation failures, and they only surface when a tool holds two identities at once and compares what each can reach. It is the most valuable test available to a law firm.
Yes, and the output is designed with that in mind. Findings arrive confirmed with the request, response and a reproducible curl command, plus remediation guidance including vulnerable and secure code examples. Your IT team receives specific changes rather than a report requiring interpretation.
It produces the technical testing evidence those guidelines typically ask for: testing methodology, findings with severity and control mapping, remediation guidance and retest history. Guidelines vary by client and some include requirements beyond technical testing, so the honest position is that this supports the response rather than completing it.
The infrastructure and any HTTP-exposed application layer, yes. Internal network assessment covers the hosts and services, and application testing covers what the system exposes over HTTP. Coverage of a specific vendor platform's internals depends on its architecture and is worth scoping directly.
Destructive actions are off by default, the request rate is configurable, and out-of-scope paths are respected. Firms typically test outside working hours for the core systems and any time for external surfaces.
Only with that client's authorisation. Scope is verified before anything runs.
Test information barriers, client portals and the systems holding privileged material, and get evidence your clients' risk teams will accept.
Scope verified before any test runs · Destructive actions off by default
Same engine, different threat model, different auditor. Each page covers the systems, regulations and attack paths that sector actually lives with.
Payment flows, lending decisions, account servicing, open banking APIs — the logic that handles money is the logic attackers study hardest. It is also the logic no signature database describes.
ExplorePatient portals, scheduling systems, clinical APIs, payer integrations: all of it holds data that carries a lifetime of consequence if it leaks, and much of it runs on systems that cannot be taken offline for a test.
ExploreBenefits portals, licensing systems, tax filing, records access — services that must be open to everyone by design, running on estates that were often built decades apart and connected later.
ExploreAlmost nobody breaks into a plant by attacking a controller. They arrive through a corporate account, a supplier portal, an ERP integration or an exposed remote access service, and then walk into a network that was designed for reliability, not for containment.
ExploreThe vulnerabilities that cost retailers money are rarely exotic. A discount that stacks when it should not. A price accepted from the client. A gift card balance that survives a concurrent request. A loyalty account reachable from another customer's session.
ExploreEvery enterprise deal arrives with a questionnaire, a SOC 2 request and someone technical asking when you last tested. Meanwhile you ship on Tuesday and again on Thursday, and the last pentest describes a product that has since changed twice.
ExploreA single authorisation flaw in a subscriber portal is not one exposed account. At operator scale it is a data set — and the same flaw in a provisioning API is an operational one.
ExploreA department stood up a project site in 2019. A research group runs its own server. A faculty subdomain points at infrastructure that was decommissioned two years ago. None of it went through central IT, and all of it is reachable.
Explore