Retour aux articles

Security and BeSavvy: A practical guide to what you need to check

29 avril 2026

Not every legal tech platform carries the same security risk. It matters to know the difference.

Security reviews are a fact of life in law firm procurement. They exist for good reason: legal tech tools that handle client data, financial information, or confidential matter details carry real risk and deserve careful scrutiny.

The problem is that security processes are often applied uniformly — the same lengthy review for a platform that stores client files and a platform that does not.

Understanding what a tool actually does with data is the first step to calibrating the review appropriately.

This article explains BeSavvy's security posture honestly, so your security and IT teams can make that assessment quickly.

Our certifications and trust centre

BeSavvy currently holds Cyber Essentials certification and is in the process of acquiring ISO 27001 certification. We take the view that certifications are a floor, not a ceiling — compliance matters, but demonstrable action matters more.

For that reason, we maintain a dedicated trust centre where you can review our security practices, policies, and current certification status in detail. We built it specifically because we wanted to give firms something more useful than a checkbox: a transparent, up-to-date record of what we actually do to protect data.

You can review our trust centre at: besavvy.app/security

Two levels of integration — and two very different risk profiles

The most useful way to think about BeSavvy security is to identify which level of integration your firm is considering. The two levels carry materially different risk profiles and warrant different levels of review.

Level 1: Standard platform use

At this level, BeSavvy receives no client data, no financial data, and no confidential matter information. The only data that enters the platform is:

  • User identity information passed through single sign-on from your identity provider — most commonly Microsoft Entra
  • Performance data generated by users working through simulations on the platform

All simulation content at this level is either built from generic legal scenarios or developed by BeSavvy using fully anonymised source material. Before any content reaches the platform, we run local anonymisation and risk checks to identify and remove anything that could be considered private or confidential.

All data is stored on Tier 1 EU or US servers, compliant with local data protection law including GDPR.

At Level 1, BeSavvy does not hold client data, matter data, or financial data of any kind.

The platform poses no material data security risk of the type that legal tech tools handling live client information would carry.

In many firms, this means that a standard Level 1 deployment can proceed with a significantly lighter security review than would apply to, for example, a document management or matter management system.

Level 2: Deeper integration

At this level, the firm is actively bringing more of its own data into the platform. Examples include:

  • Uploading contracts or internal documents to build simulations tailored to specific practice areas or clients
  • Creating simulations that reference client-specific information or scenarios
  • Opening simulations to external participants, including clients

This level of integration does increase the security surface and warrants a fuller review. We welcome that process. We are prepared to go through your firm's standard security assessment, respond to security questionnaires, and comply with specific requirements your IT and risk teams identify.

We already have the foundational certifications in place, and we are actively building toward additional accreditations. If your firm requires specific certifications or contractual commitments as a condition of Level 2 integration, we ask that you raise these early so we can confirm our current status and timeline.

A practical note on security reviews

Before beginning any engagement, we ask firms to make an honest assessment of which level of integration they are starting with.

This is not a legal tactic or an attempt to avoid scrutiny — it is a practical observation that security teams are best served by accurate information about what a tool actually does.

In our experience, when security teams understand that a Level 1 deployment involves no client data, no matter data, and authentication handled entirely by the firm's own identity provider, the review process becomes significantly more straightforward. In some cases, a clear explanation of the data architecture is sufficient to resolve concerns that a standard questionnaire process would have taken weeks to work through.

If you are unsure which level applies to your planned use of BeSavvy, we are happy to work through that assessment with you before any formal procurement process begins.