Skip to content

Legal · Trust center

Security, answered before you ask.

What suss. reads, what it never touches, and how we protect it. Written for the person who fills out the security questionnaire.

Request the SOC 2 report

Architecture

suss. reads from your bank (read-only), your practice management system and your ledgers, and writes only to its own record. It never initiates a payment or transfer.

Data handling

suss. does not train models on client data. Personally identifiable information is stripped before any model sees a document. Firm data is isolated per firm. See How we handle your data for the full policy.

Encryption

Data is encrypted in transit and at rest. Firm data is isolated per customer; no firm can ever see another firm’s matters, payees, or balances.

Access and approvals

Role-based access for attorneys, office managers and signatories. Approving money requires a step-up (passkey or device code) for the signatory at the moment of approval.

SOC 2

SOC 2 Type 1 is in progress. The report will be available under NDA on request when issued.

Request the SOC 2 report

Security contact

Found something that worries you? Tell us directly: info@gotsuss.com. Security reports go to the founders, and we respond to every one. See also Security.