What it says
What this says
Current to 11 Oct 26Marlstone Legal's answers to BB-Demo's security questionnaire for the Growth tier, completed on 28 Jan 2025. It concludes the firm meets Growth requirements and that implementation can proceed on execution of the order form. It states no price, availability or response-time terms.
What it is: a customer-completed security questionnaire for Growth tier onboarding, filed in the Marlstone Legal security folder. It concludes "Marlstone Legal meets the security requirements for Growth tier access."
Commits: nothing commercial. It states no price, service level, connector date or billing term, and the order form is described as still to be executed.
Unusual: SSO is not in place and is "planned for later in 2026". Client data is described as "stored on-premises" while also saying no data leaves the firm's Snowflake account, which is not reconciled.
Not settled: who at Marlstone Legal completed it, since only "our IT team" is named as security liaison. The document does not show whether the later SSO plan went ahead, and it dates from Jan 2025, so it may be stale.
As found in this document
The document
Body
Marlstone Legal - Security Questionnaire
Overview
This document records Marlstone Legal's responses to BB-Demo's security questionnaire for Growth tier, completed on 28 January 2025.
Security Assessment
| Question | Response |
|---|---|
| Does your organisation use single sign-on (SSO) for user authentication? | We use Microsoft 365 for identity management across the firm. SSO integration is planned for later in 2026; the Growth tier does not require it at present. |
| How do you manage data access and user permissions? | Access is role-based, managed through Microsoft 365. Team leads approve access requests and we maintain an access log updated quarterly. |
| What is your data retention and deletion policy? | Client matter files are retained for seven years after case closure. Staff departures trigger immediate access removal. |
| How do you handle sensitive data such as client information? | Client data is stored on-premises and shared with BB-Demo only through authorised connectors. No data leaves our Snowflake account. |
| Do you have an incident response plan? | Yes. Security incidents are escalated to our IT team within four hours of discovery and lo |
Read the whole document (1,791 characters)
gged. | | How frequently do you back up your data? | Our systems back up nightly with secure offline storage. Recovery testing is conducted annually. | | What network and encryption standards does your organisation use? | All data in transit is encrypted using industry-standard protocols. Data at rest is encrypted by our IT systems. | | Who is the primary contact for security liaison? | Our IT team manages security liaison with BB-Demo. |
Assessment
Marlstone Legal meets the security requirements for Growth tier access. Implementation can proceed upon execution of the order form.
Unusual terms
Current to 9 Oct 26- SSO not in place, planned for later in 2026
- Data described as on-premises and within Snowflake account