Security

Concrete safeguards for legal work.

Atlas & Main combines verified identity, backend authorization, scoped data access, and short-lived file delivery across its legal workflows.

Verified sessions

Firebase Auth establishes identity, while the Next.js session boundary checks verification and role before protected navigation.

Role and request authorization

Backend callables and database rules validate ownership, assignment, collaborators, workflow state, and operation-specific permissions.

Protected documents

Authenticated preview routes recheck access and canonical Storage metadata. Export links are short-lived and are not persisted as durable browser credentials.

Controlled AI processing

AI requests send only the prompts and attachments selected for that feature. Operational AI views exclude prompt and document content.

Stripe payment boundary

Stripe handles card entry and payment processing. Secret keys, webhook verification, invoice mutation, and reconciliation stay on the backend.

Deletion and retention controls

Clients can export available account data and delete their account after reauthentication; shared legal and financial records follow the disclosed anonymization and retention rules.

Security is enforced beyond the interface

Buttons and navigation reflect capabilities, but protected reads and mutations are authorized again by server code, Firebase rules, or authenticated preview routes.