Vendor review
Last updated October 3, 2026
Before a firm puts client information into new software, someone has to review the vendor: a partner, an IT consultant, sometimes the firm's insurer. These are the questions that review usually asks, answered plainly, including where the answer is no. Print this page or send the link.
Every answer restates what our other pages already say and links to the detail. It is a disclosure, not a contract and not a certification.
Has Fylely had an independent security audit, such as SOC 2 or ISO 27001?
No. Fylely holds no security certification and has not had an independent audit. What it does to protect your records is set out on the Security page, so you can judge it for yourself.
Where is our data kept, and who else handles it?
The database and uploaded files are held by Supabase in the United States (US East, Northern Virginia). The application is served by Vercel. Email goes out through Resend, payments through Stripe, and Microsoft is involved only if someone at your firm connects their own Outlook account. The Sub-processors page lists each one and what it receives.
Is it encrypted?
Yes. All traffic is encrypted in transit with TLS, and the database and documents are encrypted at rest by the hosting provider.
Can another firm see our records?
No. Each firm's records are separated by row-level security in the database itself, not only by the application, and uploaded files are stored under the firm that owns them with the same rule.
How do people sign in?
With a password and, if turned on, a second step: a six-digit code by email, a code from an authenticator app, or a passkey (the device's own fingerprint, face or PIN unlock). The firm owner can require the second step for everyone and set how long an idle session lasts, from 15 minutes to 4 hours. Repeated wrong passwords lock the account for a time.
Can we limit what staff see?
Yes. Each team member has a role: attorney, paralegal, billing or read-only. A paralegal does not see invoices or trust; billing staff do not open matter files; read-only can look and change nothing. The guide by role sets out what each one can do.
Is there a record of who did what?
Yes. Changes to estate and guardianship records are written to an activity log by the database. A separate security log records sign-ins, refused sign-ins, exports and changes to sign-in settings, the team and share links; the owner can read it in Settings, and entries are kept for 400 days.
Who at Fylely can see our records?
Fylely's own operator console can see across firms. It needs each operator's own account, password and authenticator code, and administrative changes are logged under that person's name.
Is our information sent to an AI service?
No. Fylely does not send your firm's information to any outside AI service. Ask, drafted replies and document descriptions are worked out inside Fylely from your own records.
Can our other software read our records?
Only if the firm owner sets it up. The owner can make an API key that reads matters, deadlines, contacts and invoices, and webhooks that send events to an address the owner chooses. A key cannot change anything, only a fingerprint of it is stored, and notes, messages, document contents and the trust ledger are not available through it. Each key or webhook made or removed is on the security log.
How is client money in trust handled?
Each client has their own trust ledger, and the database refuses any entry that would take a client below zero. A reconciliation is done entry by entry against the bank statement and prints as a report with each client's balance on the statement date. Fylely keeps one trust account per firm. Your bar or law society sets what your records must contain; check the report against its rules.
Can we get everything out?
Yes. The firm owner can download every record as one file and every uploaded document as a ZIP, from Settings, at any time and without a paid plan.
What happens to our records if we stop paying, or if Fylely shuts down?
If your plan ends, your matters stay where they are and stay readable, and the exports keep working. If we ever stop offering Fylely, the Terms commit us to emailing every account owner at least 30 days before it is switched off, with export available throughout.
How is data deleted?
Closing the account deletes the firm, its records and its uploaded files. The deletion process sets out the exceptions: backups, retained security logs, legal obligations and copies other people have already received.
Are there backups, and how fast is recovery?
We do not promise a recovery time or a loss-free recovery window, and we publish a restore check only once one has been completed and measured; the Security page shows the current state. Keep your own copies using the exports if your firm's continuity plan needs them.
Is there a data-processing agreement?
This page and the Sub-processors page are disclosures, not contracts. The Terms and Privacy Policy are the agreement. If your firm needs something further in writing, email help@fylely.com and say what you need.
Who do we tell about a security concern?
Email cole@fylely.com. No system is perfectly secure and we do not promise absolute security, but we will tell you plainly what happened.