Security & data protection

Grounded, and built to prove it.

Family-court communication records are sensitive by nature. This page states plainly what protects your client's data today, names the actual product and protocol behind each claim, and separates what's already true from what's still ahead — no badge is shown here for anything we haven't earned.

How the layers stack

Four layers, applied in order.

Each layer is described in full in the pillar it belongs to. This diagram shows only the order in which they apply, and where in that order the fingerprint is written.

The four layers in the order they apply 01 DE-IDENTIFY role labels, early 02 BIND a fingerprint per exhibit 03 CONTROL matter by matter 04 DELIVER the Professional Portal
Protecting your data today
PILLAR 01

De-identification & verified custody

  • Names de-identified before chronologizing — not as a final scrub, but as an early step in the pipeline.
  • Every exhibit carries the SHA-256 hash of its source record, computed when the exhibit set is produced — change one byte of that record and it no longer matches. Two limits we state rather than gloss: in a de-identified deliverable that hash authenticates the original record, not the role-labelled text in your hands, and independent verification of the delivered package relies on a separate bundle-level hash we are still wiring up for self-service checking. Ask us and we will verify a package with you in the meantime.
  • Human review is part of every delivery, not automation alone.
PILLAR 02

Access & isolation

  • Two-factor sign-in on professional accounts. The Professional Portal runs on Progress ShareFile, and two-factor authentication — a one-time code in addition to your password — is enabled on our account there. We have not yet completed our own end-to-end verification of that setting, so we describe it as configured rather than as proven; if your firm needs confirmation for its own due diligence, ask us and we will walk you through the current configuration.
  • Per-matter separation. Each matter is set up as its own space, and access is granted matter by matter rather than across the account — a professional is added to the one matter they are working on. That separation is a permission configuration in the portal platform plus our own per-matter onboarding discipline; we have not yet completed our end-to-end isolation test, so we describe it as configured rather than proven. If your firm needs confirmation for its due diligence, ask us and we will walk you through the current configuration.
  • No public or open sharing links. Reading a matter requires a professional account. The one exception is deliberate: a family member sending you source records gets a private upload link scoped to a single matter — it can upload to that matter and read nothing back, and it stops working once it expires. Link lifetime is set by the portal's sharing configuration; shortening the default expiry for records involving minors is on our security roadmap, and we will tell you the current setting if you ask.
PILLAR 03

Storage & delivery

  • Delivered through the Professional Portal, which runs on Progress ShareFile in a HIPAA-compliant-configured environment — never by email attachment. "The Professional Portal" is what we call that space; ShareFile is the platform underneath it. They are one system, not two. HIPAA mode is switched on in that account, but it is a setting we have configured rather than proven: the Business Associate Agreement that actually backs it has not yet been accepted, and we have not yet completed our own end-to-end verification. We describe it as a configuration, not a certification.
  • Secure upload links for sending source records, scoped to a single matter.
  • Descriptive-only outputs. Nothing Pyra produces contains a score, rating, or determination — see Methodology.
How verification works

A hash is a digital fingerprint.

SHA-256 turns a file into a fixed-length string. Change one byte of that file — one character, one space — and the string comes out completely different. So a matching fingerprint at delivery time is how anyone, including opposing counsel, can independently confirm an exhibit wasn't altered after Pyra produced it. No trust in Pyra required — just a hash calculator and the exhibit.

Illustrative fingerprintSHA-256  8f3a1c9d2b71…e412a06f
Source record
recordCEU-0412
fromParent A
toParent B
sent2024-03-11 18:42
textPickup moved to 5:30.
Fingerprint
SHA-256 8f3a1c9d2b71a4e05c86df2419b7e3a0c1d84f6b90ae27c53d1fb84ee412a06f

The fingerprint matches the record. One byte changed. The fingerprint no longer matches.

Illustrative only. Both strings are fixed examples, swapped by the button — nothing is computed on this page.

Control summary

What backs each control — and how far we have gone.

The third column is quoted from the pillars above, word for word. Where a control rests on a setting we have not tested ourselves, the row says so in the same words the pillar does.

ControlWhat backs it todayHow far we have verified it
01Role labels applied before chronologizing Pillar 01 — an early step in the pipeline, then a human review pass before release. Two limits we state rather than gloss: this is pseudonymization, not anonymization — we keep a separate sealed key that can reverse it, because a court may require that it be reversible — and while the known parties are replaced deterministically, a third person named only in passing inside a message body can be missed by an automated pass.
02Per-exhibit fingerprint Pillar 01 — a fingerprint written for each exhibit when the exhibit set is produced. Two limits we state rather than gloss: in a de-identified deliverable that hash authenticates the original record, not the role-labelled text in your hands, and independent verification of the delivered package relies on a separate bundle-level hash we are still wiring up for self-service checking.
03Two-factor sign-in on professional accounts. Pillar 02 — a setting on the platform the Professional Portal runs on. We have not yet completed our own end-to-end verification of that setting, so we describe it as configured rather than as proven; if your firm needs confirmation for its own due diligence, ask us and we will walk you through the current configuration.
04Per-matter separation Pillar 02 — a permission configuration plus per-matter onboarding discipline. That separation is a permission configuration in the portal platform plus our own per-matter onboarding discipline; we have not yet completed our end-to-end isolation test, so we describe it as configured rather than proven.
05Private link lifetime Pillar 02 — the sharing configuration in the portal platform. Link lifetime is set by the portal's sharing configuration; shortening the default expiry for records involving minors is on our security roadmap, and we will tell you the current setting if you ask.
06Storage & delivery environment Pillar 03 — an account-level mode on that same platform. HIPAA mode is switched on in that account, but it is a setting we have configured rather than proven: the Business Associate Agreement that actually backs it has not yet been accepted, and we have not yet completed our own end-to-end verification.
07Third-party certification None today. Pyra does not hold third-party security certifications today, and we won't display a badge implying otherwise.

Every row points back to the pillar that describes it in full, so the short form here and the long form above cannot drift apart.

Where we're headed

The honest roadmap.

Pyra does not hold third-party security certifications today, and we won't display a badge implying otherwise. Below is what's actually in motion — styled deliberately differently from the measures above so the two are never confused.

SOC 2 Type II readiness assessmentPlanned
Formal incident-response & breach-notification runbookPlanned
Independent penetration testPlanned
Security & data-handling questions
Who can see my client's identity before it's de-identified?
De-identification happens early in the pipeline, before the record is chronologized. Access to any pre-de-identification material is limited and logged. In the finished deliverable the parties and the children are replaced with role labels — Parent A, Parent B, Child 1 — first automatically, then checked by a human review pass before anything is released to you. Two limits we state rather than gloss: this is pseudonymization, not anonymization — we keep a separate sealed key that can reverse it, because a court may require that it be reversible — and while the known parties are replaced deterministically, a third person named only in passing inside a message body can be missed by an automated pass. That is precisely what the human review step exists to catch, and it is why we call the result de-identified rather than anonymous.
What happens if a hash doesn't match on export?
It shouldn't — a mismatch means the file changed after production. If you ever see one, contact us immediately; it's the tripwire the hash exists to catch.
Is data shared across matters or professionals?
No. Each matter is set up as its own space in the Professional Portal, and access is granted to the one professional assigned to it. That separation is a permission configuration plus our per-matter onboarding discipline; our own end-to-end isolation test is still outstanding, so we describe it as configured rather than proven. See the Professional Portal.
Does Pyra hold a HIPAA Business Associate Agreement?
Not yet — our storage platform offers a Business Associate Agreement and we have not executed it; we would rather say so than leave the question hanging. In most matters it does not bite: coparenting communication records are typically not HIPAA-covered data, and law firms are generally not HIPAA-covered entities — this depends on your specific matter. Our storage account is configured in the platform's HIPAA mode; the Business Associate Agreement that backs that mode is not yet executed, and we will tell you when it is signed. Ask us directly if your matter has HIPAA-specific requirements.
Read the full FAQ →

Last reviewed: July 2026. Questions about a specific control? Ask us directly — we'll answer in writing.