Security

How we protect your firm’s data and your clients’ privilege.

Global Wakili is built for the confidentiality demands of legal practice. Security is designed into the architecture — not bolted on afterwards.

Tenant isolation

Every firm’s data is architecturally separated from every other firm. Tenant filtering is enforced at the database layer across 116 data models, making cross-tenant access impossible by design rather than by policy.

Encryption

  • Data at rest encrypted with AES-256-GCM.
  • Data in transit protected with TLS 1.3.

Tamper-evident audit trail

Critical actions generate immutable audit records secured with a SHA-256 hash chain, so the audit log cannot be silently altered.

Access control

Role-based access control (RBAC) with 400+ granular permissions governs who can see and do what. Trust accounting enforces three-way reconciliation and overdraw prevention.

AI safeguards

AI features run behind human-review gates with prompt-injection protection. Sensitive fields are redacted before any external API call, and we never use your data to train models.

Infrastructure & privilege

Data is hosted on geo-redundant Neon Postgres. Attorney-client privilege is protected at every layer, consistent with the Kenya Data Protection Act 2019 and ISO 27001-aligned practices.

Reporting a vulnerability

If you believe you’ve found a security issue, please email wakili@globalsitesltd.com. We appreciate responsible disclosure.