Skip to main content
R Recoup Discuss recovery

Recovery standard / Security

Data starts after diligence.

Recoup is preparing for its first production recovery partnership. This page separates the current public-site boundary from the controls that must be agreed and evidenced before any law-firm billing data is accepted.

Current status

The public contact form is for business contact and high-level workflow information only. Do not send client names, matter details, claimant information, medical information, invoice data, LEDES files, carrier reports, credentials, or other confidential material through the website or ordinary email.

Recoup does not hold itself out as SOC 2 certified. A prospective firm may review the proposed architecture, vendors, contractual controls, and operating procedures before authorizing a transfer.

The pre-data gate

No production billing data should enter the workflow until the firm and Recoup have completed all of the following:

  1. Executed the governing engagement, confidentiality terms, and any required data-processing terms.
  2. Documented the exact data fields, enrolled carriers, authorized users, and business purpose.
  3. Approved a transfer method and verified where the data will be stored and processed.
  4. Agreed retention and deletion periods, backup treatment, and end-of-engagement disposition.
  5. Reviewed relevant subprocessors and any AI-assisted processing proposed for the engagement.
  6. Confirmed the firm’s filing, credential, and human-approval procedure.

Required production controls

Data minimization

The partnership should use only the records needed for enrolled recovery work. Unnecessary personal or matter information should be excluded or redacted before transfer where operationally feasible.

Access and separation

Access must be limited to named personnel with a business need. Each firm’s production data must be logically separated from other work, and access changes must be handled explicitly.

Encryption and transfer

Production data must use an approved encrypted transfer path and encryption in transit and at rest in the selected systems. Ordinary email is not an approved production transfer path.

AI-assisted processing

No client billing data should be submitted to a model provider unless the firm has approved the provider, contractual terms, retention controls, and precise use. If those conditions are not satisfied, that processing is excluded from the engagement.

Human approval and credentials

The firm remains the filing authority. A first engagement should use a documented human approval gate and should not require Recoup to hold reusable carrier-portal credentials unless the parties separately approve that access design.

Logging, incidents, and deletion

The operating plan must define material workflow events to log, an incident-contact path, required notification timing, and verifiable deletion at the end of the retention period.

Request the current readiness packet

A prospective firm can request the current architecture and control checklist during diligence. Questions can be sent to bijan@recouplegal.com. Do not attach client or billing data.

Last updated: July 18, 2026

R Recoup

Carrier reduction recovery for insurance-defense firms.

Security Privacy Contact

© 2026 Recoup. Recoup is a billing-recovery service, not a law firm, and does not provide legal advice.