Family-court communication records are sensitive by nature. This page states plainly what protects your client's data today, names the actual product and protocol behind each claim, and separates what's already true from what's still ahead — no badge is shown here for anything we haven't earned.
Each layer is described in full in the pillar it belongs to. This diagram shows only the order in which they apply, and where in that order the fingerprint is written.
SHA-256 turns a file into a fixed-length string. Change one byte of that file — one character, one space — and the string comes out completely different. So a matching fingerprint at delivery time is how anyone, including opposing counsel, can independently confirm an exhibit wasn't altered after Pyra produced it. No trust in Pyra required — just a hash calculator and the exhibit.
8f3a1c9d2b71a4e05c86df2419b7e3a0c1d84f6b90ae27c53d1fb84ee412a06f
The fingerprint matches the record. One byte changed. The fingerprint no longer matches.
Illustrative only. Both strings are fixed examples, swapped by the button — nothing is computed on this page.
The third column is quoted from the pillars above, word for word. Where a control rests on a setting we have not tested ourselves, the row says so in the same words the pillar does.
| Control | What backs it today | How far we have verified it |
|---|---|---|
| 01Role labels applied before chronologizing | Pillar 01 — an early step in the pipeline, then a human review pass before release. | Two limits we state rather than gloss: this is pseudonymization, not anonymization — we keep a separate sealed key that can reverse it, because a court may require that it be reversible — and while the known parties are replaced deterministically, a third person named only in passing inside a message body can be missed by an automated pass. |
| 02Per-exhibit fingerprint | Pillar 01 — a fingerprint written for each exhibit when the exhibit set is produced. | Two limits we state rather than gloss: in a de-identified deliverable that hash authenticates the original record, not the role-labelled text in your hands, and independent verification of the delivered package relies on a separate bundle-level hash we are still wiring up for self-service checking. |
| 03Two-factor sign-in on professional accounts. | Pillar 02 — a setting on the platform the Professional Portal runs on. | We have not yet completed our own end-to-end verification of that setting, so we describe it as configured rather than as proven; if your firm needs confirmation for its own due diligence, ask us and we will walk you through the current configuration. |
| 04Per-matter separation | Pillar 02 — a permission configuration plus per-matter onboarding discipline. | That separation is a permission configuration in the portal platform plus our own per-matter onboarding discipline; we have not yet completed our end-to-end isolation test, so we describe it as configured rather than proven. |
| 05Private link lifetime | Pillar 02 — the sharing configuration in the portal platform. | Link lifetime is set by the portal's sharing configuration; shortening the default expiry for records involving minors is on our security roadmap, and we will tell you the current setting if you ask. |
| 06Storage & delivery environment | Pillar 03 — an account-level mode on that same platform. | HIPAA mode is switched on in that account, but it is a setting we have configured rather than proven: the Business Associate Agreement that actually backs it has not yet been accepted, and we have not yet completed our own end-to-end verification. |
| 07Third-party certification | None today. | Pyra does not hold third-party security certifications today, and we won't display a badge implying otherwise. |
Every row points back to the pillar that describes it in full, so the short form here and the long form above cannot drift apart.
Pyra does not hold third-party security certifications today, and we won't display a badge implying otherwise. Below is what's actually in motion — styled deliberately differently from the measures above so the two are never confused.
Last reviewed: July 2026. Questions about a specific control? Ask us directly — we'll answer in writing.