Document security and access
Every document where it belongs. Every access on the record.
ModulawAI holds a law firm’s documents the way the best file platforms do: a shared Firm Library, private Personal files and matter folders, with access that is granted on purpose, restricted in one click and recorded every time it changes. Then it does what a file platform cannot: it lets the AI read all of it, without ever reading past what the person asking is allowed to open.
Three places, three rules
Organised the way a firm actually works.
Some documents belong to the firm, some to a person, and some to a client’s matter. Each place has its own default, so the right people see a file without anyone having to remember to share it, and the wrong people never do.
Firm Library
Precedents, forms, publications and department folders. Open to everyone in the firm by default, like a shared drive, with any folder or file restricted to the people who should have it.
Personal files
Each person’s own working files and drafts. Private to their owner, including from administrators, until the owner shares something. When it is ready for the firm, move it to the Library.
Matter documents
Pleadings, evidence and correspondence held against the case. Access follows the matter, so ethical walls and case teams decide who can reach the files, not a folder name.
Access control
Least privilege, without the friction.
Restricted folders
Restrict a folder and everything in it goes with it.
Set an HR, partnership or conflicts folder to restricted and it disappears for everyone else in the firm: the folder, every subfolder and every file inside, in lists, in search and in the AI. Sharing a folder higher up does not reach into it. The people inside are the folder’s owner and whoever it is shared with. That includes administrators: they can see that the folder exists, but to open it they ask its owner, like anyone else.
Sharing
Give exactly the access the job needs, for as long as it needs it.
Share a file or folder with a person, a role, a department or the whole firm, as viewer, commenter, editor or manager, with an expiry date if the need is temporary. Bring in someone outside the firm as a guest on a single document, or send a link that can carry a password, turn downloading off, stop after a set number of uses and be revoked at any time. Sharing a folder shares what is in it; removing access takes it all back.
Administrators
Oversight of the firm’s files. Not a key to every room.
Workspace administrators manage the open Firm Library. Restricted folders are closed to administrator rights, and so are colleagues’ Personal files. When an administrator needs to see inside a restricted folder, they ask its owner, and an approved request ends after 24 hours unless the owner chooses otherwise. If the owner cannot be asked, an administrator can take emergency access: view only, for 24 hours, with a reason the owner is told at once. Every file opened that way is written to the audit log. The firm is never locked out of its own records, and privileged access is never silent.
AI that respects permissions
The assistant reads what you can open. Nothing more.
Search, the AI assistant and project knowledge all go through the same access check as opening a file. A restricted folder never surfaces in another person’s answer, a colleague’s Personal file never feeds your draft, and a document cannot be copied into a case or a project by someone who could not open it in the first place. Emergency access never reaches the AI either. One set of rules, enforced in one place, and refusing by default when anything is uncertain.
Accountability
When someone asks who had access, you have the answer.
An audit trail of access
Every share given or removed, every change to who can see a file or folder (with what it was before and after), every share link created or revoked, and every emergency access, with its reason and each file opened, is recorded with the person and the time.
Deletion you can undo
Deleted files and folders wait in a Recycle bin for 30 days and restore whole, folder tree included. Anything from a restricted folder stays hidden from administrators there too. Deleting forever, by a person or when the 30 days run out, is logged with what went and why.
Version history
Documents keep their earlier versions, so the version that went to the client can always be found, whatever happened to the file afterwards.
Migration
Move a whole firm’s drive, and prove nothing was left behind.
Import from Zoho WorkDrive, OneDrive and SharePoint into the Firm Library, Personal files or a case. Folder trees are recreated exactly, WorkDrive files up to 10 GB stream straight in and resume if the connection drops, and WorkDrive sharing can carry over so a file that was private stays private. Every import produces a file-by-file report to reconcile against the source, and anything that did not come across can be fetched again on its own, without rescanning the drive. See importing from Zoho WorkDrive.
Standards
Designed to the controls auditors look for.
Document access in ModulawAI is built against ISO/IEC 27001:2022 Annex A and the SOC 2 Trust Services Criteria for logical access. The table shows where each control lives in the product. We are working towards formal certification; ask us for the full control mapping.
| Control | Reference | In ModulawAI |
|---|---|---|
| Access control policy, least privilege | ISO 27001 A.5.15, SOC 2 CC6.1 | Defaults per place; restricted files and limited-access folders; one access check for every surface; refuse when uncertain |
| Information access restriction | ISO 27001 A.8.3 | Personal files private to their owner; restricted folders hidden with their contents; AI limited to what the asker can open |
| Provisioning and removing access | ISO 27001 A.5.18, SOC 2 CC6.2, CC6.3 | Shares by person, role or department with expiry dates; removing a share or a member removes their access |
| Privileged access rights | ISO 27001 A.8.2 | Administrators manage the Library outside restricted folders; restricted folders and Personal files are closed to them. Access by the owner’s approval, or time-limited emergency access with every open logged |
| Logging | ISO 27001 A.8.15, SOC 2 CC7.2 | Audit events for shares, general-access changes, share links, access requests, emergency access and each file opened with it, and permanent deletion |
| Information deletion | ISO 27001 A.8.10 | 30-day Recycle bin, logged permanent deletion and automatic expiry |
| Cryptography | ISO 27001 A.8.24 | Encryption in transit and at rest; credentials for connected drives encrypted |
Documents are held in AWS data centres, encrypted in transit and at rest, and never used to train AI models. Our subprocessor list and data processing agreement are published.
FAQ
Questions, addressed.
Can a partner or administrator read my Personal files?
No. Personal files are private to the person who owns them. Administrators manage the Firm Library, not anyone’s Personal files. You can share a Personal file with someone, or move it to the Library when it is ready for the firm.
What happens when I restrict a folder in the Firm Library?
The folder and everything inside it, at every level, is hidden from the rest of the firm, in lists, search and the AI. Only the folder’s owner and the people it is shared with can open it. Administrators see that it exists and ask its owner for access. Sharing a folder higher up does not open it.
Can the AI assistant see documents I cannot?
No. The assistant, search and project knowledge use the same access check as opening a file, so an answer can only draw on documents the person asking is allowed to open.
Is there a record of who changed access to a document?
Yes. Shares given and removed, changes to who can see a file or folder, share links created and revoked, emergency access to restricted material and permanent deletions are all written to the audit log with the person and the time.
Is ModulawAI ISO 27001 or SOC 2 certified?
Document access is designed against ISO/IEC 27001:2022 Annex A and the SOC 2 Trust Services Criteria, and we are working towards formal certification. Ask us for the control mapping.
See your own folders, protected properly.
Book a demo, import a folder you know, restrict it, and watch who can and cannot find it.