Black Shard

Industries · Legal

Software and security for firms that hold privilege.

We build and secure the systems law firms run on. GRM LAW, a Brisbane firm, already runs day-to-day on a portal we built.

A law firm’s systems hold the one thing it cannot lose: client confidence, backed by legal professional privilege. Matter files, trust records, and client identities now live in cloud practice systems the firm licenses rather than controls, and the obligations around them keep tightening. AML/CTF tranche 2 captures legal practitioners providing designated services from July 2026.

We know the terrain because we work in it. GRM LAW, a Brisbane firm, runs on a secure operations and compliance portal we built and still ship to weekly: intake, conflicts, matter register, AML/CTF readiness, and the audit trail underneath.

What you carry, and what we do about it.

  • Matter data lives in cloud practice systems and portals: privileged material, one credential away.

    We penetration-test practice systems, portals, and the networks around them the way an adversary would, then hand back a ranked fix list in plain English, with a re-test to confirm the holes closed.

    Penetration testing
  • AML/CTF tranche 2 captures legal practitioners providing designated services: programs, customer due diligence, records.

    We run compliance readiness programs that map the obligation to your practice, close the gaps, and build the evidence trail an assessor expects.

    Compliance readiness
  • Trust accounting records have to be complete, attributable, and producible when the examiner asks.

    The portals we build carry append-only audit ledgers, machine-enforced on every state change: the same discipline we shipped for GRM LAW.

    Secure-by-design builds
  • Client confidentiality is the product, and identity is where it leaks: the compromised inbox, the over-privileged account.

    We review and harden the Microsoft 365 tenant your firm signs in to (conditional access and MFA coverage, privileged-role and app-consent audit), the way we run our own.

    Entra ID & Microsoft 365 identity security

The obligations in play

Legal professional privilege
Confidentiality duties under the profession’s conduct rules: a systems compromise is a privilege problem, not just an IT one.
AML/CTF Act, tranche 2
Legal practitioners providing designated services are reporting entities from 1 July 2026: programs, customer due diligence, and records.
Trust account rules
State legal-profession legislation sets record-keeping and external-examination obligations over trust money.
Privacy Act 1988
The Australian Privacy Principles govern client personal information, with the Notifiable Data Breaches scheme behind them.

This list orients the engineering work. It is not legal advice; your advisers own the interpretation.

The build behind this page

GRM LAW

A Brisbane law firm runs day-to-day on the secure operations and compliance portal we built: intake, conflicts checks, matter register, and AML/CTF readiness, with role-based access, a hardened content-security policy, and an append-only audit ledger enforced on every state change.

See the work

Keep privilege where it belongs.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au