Introduction
Practice League has invested a lot of time and money to ensure that your information is secure and
private. Our Security platform and process leverages on multiple levels of security – consisting of
Security Systems and Equipment combined with Security Procedures and Practices and Auditing
Processes, to ensure unparalleled security for all the services we provide. The platform tackles security
at various levels
Data Security & Privacy highlights
1) All data is stored in a highly secure and certified data center on fast, fully-redundant servers.
2) All systems are monitored 24x7x365 to ensure optimum performance and maximum security.
Physical Layer – Facility
Customer data is stored in SOC 2 / SSAE 16 certified Microsoft Azure datacenters that are
geographically distributed while taking regional data location considerations into account. Our
datacenters are built from the ground up to protect services and data from harm by natural disaster
or unauthorized access. Datacenter access is restricted 24 hours a day by job function—with only
customer application and services access given to essential personnel. Physical access control uses
multiple authentication and security processes, including badges and smart cards, biometric scanners,
on-premises security officers, continuous video surveillance, and two-factor authentication. The
datacenters are monitored using motion sensors, video surveillance, and security breach alarms. In
case of a natural disaster, security also includes automated fire prevention and extinguishing systems
and seismically braced racks where necessary.
Physical Layer – Network
Logical Layer
Automated Operations
Admin Access to Data
Data Security & Privacy highlights
1) Personnel level to ensure that there are appropriate background checks and strict account
management so that only those essential to the task may perform the task
2) Multiple resources with maker-checker process
3) Role based access control
4) Access for a limited amount of time
5) Just-in-time accounts with high entropy passwords
6) Access to take specific actions based on the role
7) Auditing and review of all access
Application Security
Authentication Options
Secure Credential Storage
API Security & Authentication
Access Privileges & Roles
Access to data within PracticeLeague is governed by access rights, and can be configured to define
granular access privileges. PracticeLeague provides a completely customizable user access control
which enables you create roles and privileges as per the needs of your firm/Legal Department.
Data Security & Privacy highlights
IP Restrictions
Access to data within PracticeLeague is governed by access rights, and can be configured to define
granular access privileges. PracticeLeague provides a completely customizable user access control
which enables you create roles and privileges as per the needs of your firm/Legal Department.
Data Encryption
Encryption in Transit
Encryption at Rest
Encryption of documents
Field Level Encryption
Secure Credential Storage
API Security & Authentication
Secure Development Practices
.Net Framework Security Controls
Security Training
Quality Assurance
Separate Environments
Privacy Policy
System Hardening, Application of Updates, Bug Fixes and Security Patches
Pre-Upgrade Testing Processes
Audit/Logs for security events
Login History
Record Creation and Modification Fields
Setup Audit Trail
5) IP address
Data Deletion/Purging
Data Backup, Protection
Business Continuity and Disaster Recovery Program/RPO/RTO
For the clients on Microsoft Azure cloud platform, additional level redundancy and recoverability is
offered through Recovery feature.
At the Azure data center, our servers assigned to a secondary location which contains a real-time
replication of their data and dedicated redundant capacity. The primary and secondary sites are
located in two separate geographically separate data centers. In the event of a disaster, this allows
Practiceleague restore the services to original state.