Plans & Pricing
About Gavel
Careers
Product Wishlist
The software solution you can trust. Gavel protects your data and your clients' information with top security features and protocols.
Law firms, government organizations, and courts across the world trust Gavel with their sensitive data. As a result, we take several measures to ensure the collection, storage, and transfer of this data is secure. Each Gavel customer is set up on their own subdomain and isolated database.
We continuously monitor for potential vulnerabilities and review and update our code and systems configuration to ensure your data is always protected. Gavel also maintains high standards for code quality, mandatory code reviews, and constant internal security consultations.
Each year, Gavel works with a leading cybersecurity firm that tests the software using the most advanced techniques to ensure that Gavel's platform is secure. This includes implementing a Secure Software Development Life Cycle (SSDLC) to integrate security measures–such as:
Upon onboarding and at least annually afterwards, all employees receive security and compliance training from Gavel’s compliance team. In these trainings, employees are taught how to avoid, mitigate, spot and manage security risks.
All of the data you and your users collect and transmit is encrypted in transit and at-rest using industry best practices, including Transport Layer Security (TLS). Gavel requires all third party integrations (configurable by you) that receive data from Gavel to provide secure, encrypted endpoints that will receive the data.
Gavel is also the “data processor” and our customers are the “data controllers” as further described in our Terms of Service. This relationship means Gavel merely provides the infrastructure for customers who then are solely responsible for the set up, configuration, solicitation, collection and storage of data.
Your data is encrypted at rest with AES-256 encryption in AWS data centers. AWS data centers are managed in accordance with SOC 1-3, PCI DSS Level 1 and ISO 9001/ISO 270001. For users who use Gavel for payment processing, our payment processing vendors are also PCI compliant.
You have full control over whether the data collected by your workflows is stored in your account. If you do choose to store data, you also have full control over immediately deleting any and all data in your account.
By default, Gavel will store your data in the United States via Amazon Web Services (AWS) data centers. AWS data centers are equipped to protect mission critical computer systems with full redundancy and compartmentalized security zones. Gavel also offers hosting options in the European Union, Canada, Australia, or any other AWS region (see here).
The data centers comply with the strictest physical security measures which are detailed here. Measures include, but are not limited to:
Data centers in all AWS regions securely decommission their storage devices using techniques detailed in NIST 800-88.
Internal communication involving or transmitting customer data is encrypted. Cryptographic controls are also used to protect customer data as outlined in the Data Protection in AWS Key Management Service.
To further protect customer data, policies and procedures should be implemented to protect wireless network environments, including but not limited to:
Gavel only uses and integrates with payment vendors who are operating in accordance with PCI legislation. Gavel does not store any payment information.
Gavel enforces physical, technical, and administrative protocols, including but not limited to:
Gavel is subject to periodic vulnerability assessments by third-party expert cybersecurity firms. Regularly and at least annually, the vulnerability of Gavel’s standard and advanced web application is assessed to identify security vulnerabilities including but not limited to:
Gavel customers may set up two-factor authentication and/or single sign-on (SSO) with your preferred provider in order to further limit access through your organization. We also enforce strong passwords, regular password resets, and will also automatically lock your account for a period of time after too many failed login attempts.