Recovery standard / Security
Data starts after diligence.
Recoup is preparing for its first production recovery partnership. This page separates the current public-site boundary from the controls that must be agreed and evidenced before any law-firm billing data is accepted.
Current status
The public contact form is for business contact and high-level workflow information only. Do not send client names, matter details, claimant information, medical information, invoice data, LEDES files, carrier reports, credentials, or other confidential material through the website or ordinary email.
Recoup does not hold itself out as SOC 2 certified. A prospective firm may review the proposed architecture, vendors, contractual controls, and operating procedures before authorizing a transfer.
The pre-data gate
No production billing data should enter the workflow until the firm and Recoup have completed all of the following:
- Executed the governing engagement, confidentiality terms, and any required data-processing terms.
- Documented the exact data fields, enrolled carriers, authorized users, and business purpose.
- Approved a transfer method and verified where the data will be stored and processed.
- Agreed retention and deletion periods, backup treatment, and end-of-engagement disposition.
- Reviewed relevant subprocessors and any AI-assisted processing proposed for the engagement.
- Confirmed the firm’s filing, credential, and human-approval procedure.
Required production controls
Data minimization
The partnership should use only the records needed for enrolled recovery work. Unnecessary personal or matter information should be excluded or redacted before transfer where operationally feasible.
Access and separation
Access must be limited to named personnel with a business need. Each firm’s production data must be logically separated from other work, and access changes must be handled explicitly.
Encryption and transfer
Production data must use an approved encrypted transfer path and encryption in transit and at rest in the selected systems. Ordinary email is not an approved production transfer path.
AI-assisted processing
No client billing data should be submitted to a model provider unless the firm has approved the provider, contractual terms, retention controls, and precise use. If those conditions are not satisfied, that processing is excluded from the engagement.
Human approval and credentials
The firm remains the filing authority. A first engagement should use a documented human approval gate and should not require Recoup to hold reusable carrier-portal credentials unless the parties separately approve that access design.
Logging, incidents, and deletion
The operating plan must define material workflow events to log, an incident-contact path, required notification timing, and verifiable deletion at the end of the retention period.
Request the current readiness packet
A prospective firm can request the current architecture and control checklist during diligence. Questions can be sent to bijan@recouplegal.com. Do not attach client or billing data.
Last updated: July 18, 2026