VaultMailVaultMail
Legal·6 min read

Privileged until it isn't: how lawyers use VaultMail to keep client email secure

Attorney-client privilege rides on confidentiality, and ordinary email is a postcard. How law firms use encryption, recall, and audit trails to keep privileged mail privileged.

Bronze Lady Justice statue holding the scales of justice

Attorney-client privilege has one load-bearing wall: confidentiality. Courts protect communications that were made and kept in confidence — and they can find privilege waived when a communication was handled carelessly. Which raises an uncomfortable question for a profession that runs on email: what does “kept in confidence” mean when the medium is a postcard?

The bar has already spoken

In Formal Opinion 477R, the American Bar Association told lawyers that routine unencrypted email is not always enough: when a matter is sensitive, lawyers “may be required to take special security precautions” — encryption among them — as part of the duty of technological competence and the duty to protect client information under Model Rule 1.6. Several state bars have followed with the same message. “Everyone uses regular email” is aging badly as a defense.

How privilege actually leaks

  • The wrong recipient. Autocomplete puts opposing counsel one keystroke from your settlement strategy. With ordinary email, sent is sent.
  • The forwarding chain. Your client forwards your advice to a spouse, a business partner, an accountant — and a court may later treat the confidence as broken.
  • The breached inbox. A compromised email account — yours or the client’s — turns years of privileged correspondence into someone else’s reading material.
Privilege is not a stamp you put on a document. It’s a chain of custody for a secret — and email is its weakest link.

What the chain looks like with VaultMail

VaultMail rebuilds that chain of custody inside the tools lawyers already use. You write the email in Gmail or Outlook exactly as you always have, then click Encrypt & Send instead of Send:

Compose inGmail / Outlook1Encrypted inyour browser2Recipient verifiestheir identity3Every openlogged4
The identity chain: encrypted before sending, decrypted only by a verified recipient, with every access logged.
  • Encrypted, never sent in the open. AES-256-GCM with a unique key per message — your email provider only ever sees a secure link, and every access is logged.
  • Only the named recipient can open it. The client verifies control of their email address before decrypting; there is no account to create and nothing to install on their side.
  • Mis-sends are recallable. Sent it to the wrong party? Revoke the link before it’s opened and the message is never readable. Set expiry so old advice doesn’t live in an inbox forever.
  • Every open is logged. An append-only audit trail shows who accessed what, when, from where — concrete evidence of the “reasonable efforts” the privilege analysis asks about.

Clients notice

There’s a quieter benefit, too. When a client receives their engagement letter or a sensitive filing through a sealed, verified channel, it says something about how the firm treats their secrets. At $5 per seat — free for a solo practice to try — it is the cheapest signal of care a firm can send.

Keep privileged mail privileged.

One click in Gmail or Outlook. Verified recipients, recallable messages, full audit trail.

Add VaultMail to Chrome — free

Written by the VaultMail team · Published January 27, 2026