SafeVault

Document Security

Secure File Sharing for Law Firms: What "Reasonable Efforts" Looks Like in Practice

Secure File Sharing for Law Firms: What "Reasonable Efforts" Looks Like in Practice

Short answer: Secure file sharing for law firms means sending and receiving client documents in a way that limits who can see them, protects them in transit and at rest, and leaves a record of what happened. The ABA Model Rules ask lawyers to make "reasonable efforts" to prevent unauthorized access to client information. In practice, that usually means moving sensitive documents off plain email and open links and into a permissioned client portal, with stronger measures for more sensitive matters.

This article is general information, not legal advice. Your state's rules of professional conduct and ethics opinions govern your obligations.

A paralegal emails a settlement draft to the wrong "Michael" in the address bar. A client forwards a shared folder link to a family member, who forwards it again. A former associate still has access to a drive full of closed matters.

None of these involve a hacker. They are ordinary mistakes, made possible by tools that were never designed for confidential client material. That is why file sharing is not only an IT question for a law firm. It is part of the duty of confidentiality.

Why file sharing is an ethics question, not only an IT one

Three parts of the ABA Model Rules of Professional Conduct are relevant. Most states have adopted versions of them, though the exact wording varies by jurisdiction.

Model Rule 1.6(c) says a lawyer "shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." The comments to the rule list factors for judging what is reasonable, including how sensitive the information is, how likely disclosure is without more safeguards, the cost and difficulty of extra safeguards, and whether they would make the lawyer's work harder.

Comment 8 to Model Rule 1.1 ties competence to technology. Lawyers are expected to keep up with the benefits and risks of the technology they use.

ABA Formal Opinion 477R (2017) applies these rules to electronic communication. It does not ban email. It takes a risk-based view: lawyers may use the internet to communicate with clients if they have made reasonable efforts to prevent unauthorized access, and some highly sensitive matters may call for stronger measures than ordinary email.

The practical takeaway is simple. There is no single required tool. There is a required judgment, and the firm should be able to explain it.

Where common file-sharing methods fall short

MethodWhat worksWhere it breaks
Email attachmentsEveryone has it; no training neededEasy to misaddress; copies persist in sent folders and backups; no record of what happened after sending
Consumer file-sharing linksHandles large files; quickAnyone with the link can often open it; forwarding is invisible; access is rarely withdrawn after the matter closes
Encrypted email add-onsProtects the message in transitClients find them awkward; still no shared view of what was requested and received
Client portalAccess tied to named people; requests and history in one placeNeeds a little setup and a short explanation to clients

What secure file sharing for a law firm should include

When you evaluate a tool, these are the questions that map back to "reasonable efforts."

Access limited to named people

Every document should be visible only to people you chose. Sharing by open link should not be possible for confidential material. When a matter closes or a client relationship ends, you should be able to withdraw access without deleting the firm's own records.

Encryption in transit and at rest

Documents should be protected while they travel (TLS) and while they are stored. Ask the vendor which parts of the system are encrypted at rest: the database, the stored documents and the backups.

A record of document activity

If a client says a document was never received, or a question arises about who changed a file, you want an answer from the system rather than from memory. Ask what the activity log records and how long it is kept.

Independent evidence, not adjectives

"Bank-grade security" tells you nothing. An independent examination, such as a SOC 2 Type 2 report, tells you whether a vendor's controls were designed well and operated effectively over a period of time. Ask to read the report, usually under an NDA.

A clear answer on what the provider can see

Some services are zero-knowledge, meaning the provider cannot read your files. Others can, often because they classify or search documents. Neither is automatically wrong, but under Rule 1.6 you should know which one you are using and decide whether it suits the matter.

Matching protection to sensitivity

Opinion 477R's risk-based approach suggests a tiered habit rather than one rule for everything.

  • Routine correspondence such as scheduling or general updates can usually go by ordinary email.
  • Confidential client documents such as financial records, identity documents, contracts and draft agreements belong in a permissioned portal.
  • Highly sensitive matters may call for extra steps agreed with the client, for example limiting who at the firm can access the file, or confirming the client's own device and email are secure before sharing.

Write the tiers down. A one-page policy that staff actually follow is worth more than a long one that nobody reads.

Working with clients who are not technical

The best security tool fails if the client goes back to email. A few habits help.

  • Send a short, plain invitation that explains why you use a portal: "We use this so your documents are not sitting in email inboxes."
  • Use document requests rather than open-ended asks. A client who sees "Upload: signed lease, 2025 bank statements" knows exactly what to do.
  • Choose a tool that works in a browser with nothing to install.
  • Tell clients what happens when the matter ends, including that their access will be withdrawn.

A simple file-sharing policy for a small firm

  1. Decide which document types must go through the portal.
  2. Name who at the firm can share documents with clients.
  3. Require that confidential documents are never sent by open link.
  4. Withdraw client and staff access when a matter closes or a person leaves.
  5. Review the activity log when a dispute or question arises.
  6. Keep the vendor's security report on file and review it each year.
  7. Revisit the policy when your tools or your state's guidance change.

Where SafeVault fits

SafeVault's client portal is built for professional firms, including attorneys, that exchange sensitive documents as routine work.

  • Documents are shared with named people, never by open link, and access can be withdrawn when the matter is finished.
  • Document requests carry a status, so you and your client can see what is outstanding.
  • Documents are encrypted in transit using TLS and at rest using AES-256.
  • Uploads, shares, renames, deletions and other document actions are recorded in an activity log inside the product.
  • Clients upload through a browser invitation, with nothing to install.

AmitaSoft, LLC, which builds SafeVault, completed a SOC 2 Type 2 examination covering Security, Availability, Processing Integrity and Confidentiality. The report is available under an NDA. See our security page for detail.

There are limits worth stating plainly, because Rule 1.6 asks you to understand your tools:

  • SafeVault is not zero-knowledge. Its DocIQ feature reads documents in order to classify them and extract key fields.
  • It is not a case management, e-discovery or legal hold system.
  • It is not HIPAA compliant and does not offer a Business Associate Agreement. If your firm handles protected health information as a business associate, use a tool that does.

You can try the portal with sample data in SafeVault Playground before you upload any client material. For a broader comparison of tools, see our guide to the best client portal software.

Key takeaways

  • Under ABA Model Rule 1.6(c), lawyers must make reasonable efforts to prevent unauthorized access to client information.
  • Formal Opinion 477R takes a risk-based approach: ordinary email is not banned, but sensitive matters may need more.
  • Plain email and open links are the most common sources of accidental disclosure.
  • A permissioned portal with encryption, named access and an activity log is a practical way to show reasonable efforts.
  • Know what your provider can see, and write a short policy your staff will follow.

Frequently asked questions

Is email secure enough for law firms to send client documents?

For routine matters it may be. ABA Formal Opinion 477R does not ban email, but it says lawyers must make reasonable efforts to protect client information, and highly sensitive matters may require stronger measures than ordinary email.

What does "reasonable efforts" mean under ABA Model Rule 1.6(c)?

It is a judgment based on factors such as the sensitivity of the information, the likelihood of disclosure without more safeguards, and the cost and difficulty of adding them. There is no single required tool.

What is the safest way for a law firm to share documents with clients?

For confidential documents, a client portal that limits access to named people, encrypts files in transit and at rest, and records document activity is safer than email attachments or open file-sharing links.

Should a law firm use a zero-knowledge file sharing service?

It depends on the matter. Zero-knowledge services prevent the provider from reading files, while others read documents to offer features like classification. Under Rule 1.6, the firm should understand which kind it uses and decide whether it fits the sensitivity of the work.

Does a client portal replace a firm's confidentiality policy?

No. A portal is one control. The firm still needs a written policy on what is shared, by whom, and how access is withdrawn when a matter ends.

This article is general information, not legal advice.

Explore SafeVault