Built like it holds client money.
suss. sits next to the most protected account a firm has. That's a responsibility we designed for from the first line of code, not a page we wrote afterward.
Encryption everywhere
Data is encrypted in transit and at rest. Firm data is isolated per customer; no firm can ever see another firm's matters, payees, or balances.
No training on client data
We do not train AI models on your client or matter data, and personally identifiable information is stripped before data is processed in our systems. This commitment is written into our customer agreements.
Least privilege, always
Access to production systems is restricted, logged, and reviewed. Firm accounts support strong authentication, and every action inside suss. is attributed to a named person or to suss. itself.
Your firm holds the pen
suss. verifies, matches, reconciles, and holds. It does not move money on its own. Every disbursement requires your firm's approval, and the trust journal records who approved what, when.
The record is the proof
Every check, hold, clearance, and approval is written to a signed, timestamped audit trail your firm can export at any time, for your bar examiner, your auditor, and your carrier.
Independent review
Independent security review and SOC 2 examination are part of our full rollout. Founding firms get visibility into our posture and progress as part of onboarding.
Report a concern
Found something that worries you? Tell us directly: info@gotsuss.com. Security reports go to the founders, and we respond to every one.
