IT for law firms that takes attorney-client privilege as seriously as you do.

Rhode Island adds a second duty that gets far less attention. Under R.I. Gen. Laws § 11-49.3-2, anyone holding personal information about a Rhode Island resident must maintain a risk-based information security program, and must require by written contract that any outside party they hand that information to does the same. Your IT provider is that outside party. Ask the one you have now for that contract and see what comes back.
What we would build for you
Email on Proton Mail, end-to-end encrypted and based in Switzerland, with a provider that does not mine your messages for advertising and that will sign a HIPAA Business Associate Agreement where you need one. Files, calendars and contacts on Nextcloud, with document editing through Collabora. Shared passwords in Vaultwarden. Encrypted off-site backups that we restore in front of you before we leave.
It is fully managed, so your staff keep working the way they already do, with the same kind of apps on the same devices. The difference is underneath, where your clients' information finally sits somewhere you can actually answer for.
What we will not claim
We will not tell you this makes you subpoena-proof. Nothing does, and a vendor who implies otherwise is selling you something that will fall apart at the worst possible moment. What owning your infrastructure changes is who gets served, whether you find out, and how much is sitting there to be taken. That is the honest version, and we have written it out in full.
We start every engagement by mapping what you use now, so if something in your practice would be genuinely hard to move, we tell you plainly rather than forcing it.
Book a discovery conversation about your firm's data and where it lives.

