MatterLynx

Security

Last updated August 25, 2026

MatterLynx uses layered access, encryption, confirmation, logging, and monitoring controls to reduce risk. No system is completely secure, and these controls do not guarantee that an incident or error will never occur.

Identity and access boundaries

Each user signs in to MatterLynx and connects their own Clio account. MatterLynx applies firm and user boundaries, while Clio continues to enforce that user's native role and matter permissions. Connecting MatterLynx does not give a user firm-wide superuser access.

The current Clio application requests read and write scopes for Activities, Billing, Calendars, Contacts, Custom Fields, Documents, Matters, and Tasks, plus read-only access to Users. It does not request Clio scopes for accounting or bank transactions, communications, court rules, imports, payments, reporting, settings, or webhooks. MatterLynx exposes a narrower set of tools than those application scopes: it has no general-purpose Clio API tool by default, no bill-writing tool, and no bank, payment, or trust-transaction tool.

Credentials and data

OAuth access and refresh tokens are stored per connected user and encrypted with AES-256-GCM before database storage. Production secrets are held in managed environment variables. Other stored records rely on the access and encryption controls provided by MatterLynx's infrastructure providers.

Private document uploads are staged only to complete an authorized Clio operation. They normally expire after two hours and are deleted after a confirmed result. An uncertain result may require up to seven additional days of restricted retention for reconciliation. See the Privacy Policy for the complete retention summary.

Writes, audit, and monitoring

Higher-risk changes require explicit confirmation in the assistant. MatterLynx keeps append-only, best-effort audit records of relevant operations. A completed Clio action can still succeed if an audit write fails, so the audit log should not be treated as a guaranteed or complete legal record.

Audit and usage records are designed to keep structured metadata while excluding names, contact details, notes, documents, amounts, free text, and secrets. Server error reports are scrubbed of request bodies, cookies, query strings, sensitive headers, and OAuth values. Warning and critical alerts may be sent to a private operations channel and are intended to exclude case content.

Operations and assurance

Operator access is limited to operating, securing, supporting, and complying with law. The routine operator dashboard is designed to show account, connection, and operational status rather than client or matter content. Suspected token exposure, tenant isolation, billing, and write-safety issues receive high-priority triage.

MatterLynx is not currently represented as SOC 2 or ISO 27001 certified, and it has not completed an independent penetration test. Internal testing and review reduce risk but are not substitutes for independent assurance.

Report a security issue

Email Julian at julian@joulestudios.com with enough detail to reproduce the issue. Please do not include client or matter content unless it is necessary to explain the report.