Messaging
Encrypted before it leaves the browser
A practice discusses its cases all day, and most of that conversation lives in email or in a chat tool somebody signed up for: client confidential material, outside the file, outside the firm's control. This brings it inside and encrypts it on the way, so the server holds ciphertext and nobody at Numo can read it.
- We cannot read them
- Not for support, not for an export, not under a subpoena we would rather not receive. There is no server path that decrypts a message, because the key that would do it never reaches us.
- Two conversations, one scheme
- Solicitor to client through the portal, and colleague to colleague inside the firm. The same keypair, the same encryption, so neither is the weaker one.
- Internal conversations expire
- Every internal thread is set to go when it is started: once everybody has read it, after a day, or after a week. Anything worth keeping belongs on the matter, and the product says so.
How it works
The key is made in your browser and wrapped with your password
Elliptic curve agreement on P-256, AES-GCM for the message itself, and 310,000 rounds of PBKDF2 to wrap the private key. None of those numbers is unusual; what matters is where each piece lives.
- The private key never reaches us
- It is generated in the page, encrypted under a key derived from your own password, and only the encrypted bytes are stored. We have never seen the password, the derived key or the private key.
- Wrapped, so it follows you
- Because the wrapped key is stored, signing in on a phone or a second machine works: you unlock with the password you already have, rather than moving a file between devices.
- One key per message, wrapped to each reader
- The message is encrypted once under a random key, and that key is wrapped separately to every person entitled to read it. Adding somebody to a conversation does not hand them what was said before it.
- Unlocked in memory, for the tab
- The key is held in the page while you work and nowhere else. Close the tab and what is on the server is bytes again.
With a client
On the matter, not in an inbox
Two-way, on the file, visible to whoever is working on it and to nobody else. When a client writes, the people on the matter are told, without a preview of what they said.
- It is not email
- Nothing is forwarded, nothing is in a personal mailbox, and nothing is lost when a fee earner leaves.
- The notification carries nothing
- You are told there is a message. You are not sent the message, because the notification travels by routes we can read.
- A client unlocks with their own password
- The same one they sign in with. They are asked once on a device, and told plainly that resetting it leaves anything sent before the reset sealed.
- Part of the record
- The conversation belongs to the matter and goes where the matter goes.
With colleagues
Inside the firm, and set to go
For the conversation a practice currently has over email or a phone group. You choose how long each thread lasts when you start it, and that choice does not change afterwards.
- Chosen at the start, fixed after
- Once everybody has read it, after a day, or after a week. Changing it later would change the terms everybody had already spoken under, so the product does not let you.
- Deleted, not hidden
- A sweeper removes expired messages every five minutes, and the wrapped keys go with them. There is no archive we keep for ourselves.
- Point at the file without exposing it
- Attach a matter, a document or a file and the reference travels inside the encrypted message. The server never learns which case two people were discussing.
- A sole practitioner is told so
- On a one seat account there is nobody to write to, and the page says that rather than showing an empty list with a search box over it.
What it is not
Honest about who can read what
End to end means between the ends. It is worth being exact about where those are.
- The firm can read its own messages
- A solicitor is a party to the conversation with their client, and colleagues in a thread are parties to it. That is the point of it, not a weakness in it.
- Your organisation still governs its own data
- This protects you from us and from anybody who reaches the database. It is not a way for one person at a firm to keep something from the firm.
- A forgotten password is a sealed history
- We cannot recover it, and we say so before you set the key up rather than after.
The limits
What it does not do
It does not replace the file
An internal conversation is set to expire on purpose. Anything that matters, a decision, an instruction, a piece of advice, belongs on the matter where it is kept, audited and disclosable.
It does not encrypt what you send elsewhere
Email sent through a connected Gmail or Microsoft account is ordinary email, with whatever protection that provider gives it. Only what is written here is encrypted here.
It is not anonymous
Who spoke to whom, and when, is recorded, because a firm has to be able to account for its own conduct. Only the contents are sealed.
See it on your own matters
Half an hour, your own file, and an honest answer about whether this fits how your firm already works.