VaultMailVaultMail
Legal·5 min read

What law firms taught us about encrypted email

We built VaultMail with clinics in mind — then law firms became some of its most demanding users. Five workflows they run through it every day, from verified engagement letters to the one-minute clawback.

Signing legal documents at a desk with a pen

We built VaultMail with clinics in mind: HIPAA, BAAs, disclosure ledgers. Then law firms started showing up — first a solo immigration attorney, then family-law practices, then litigation boutiques — and they turned out to be some of the most demanding users the product has. Confidentiality, it turns out, doesn’t care which profession’s ethics rules demand it.

What follows isn’t a feature tour. It’s the five workflows we watch firms run through VaultMail every day — several of which we didn’t design for, and now treat as first-class.

1. The engagement letter, with proof of who opened it

An engagement letter sets the terms of the privilege itself, so firms want more than delivery — they want identity. A VaultMail recipient verifies control of their email address before the message decrypts, and the audit log records the open. The firm knows the client — and only the client — read the letter, and can show it.

2. The one-minute clawback

Every litigator knows the discovery clawback. Email never had one — until the sent message became a revocable link. Autocomplete puts opposing counsel one keystroke from your settlement strategy, and with ordinary email, sent is sent. With VaultMail, the mis-send has an undo:

2:14 PMSent to thewrong counsel2:15 PMLink revoked fromthe sent threadResultNever opened —the audit log proves itEvery VaultMail message link can be revoked until the moment it is opened
A real recall: the link dies before it's opened, and the append-only log is your evidence that the contents were never read.

3. Settlement drafts that expire

Negotiation positions are radioactive with a half-life. Firms send draft agreements with per-message expiry — 24 hours to 30 days — so a superseded number doesn’t live in an inbox forever, waiting to be forwarded out of context or swept up in someone else’s breach.

4. Passing the client’s security questionnaire

The pressure on firms increasingly comes from their own clients: outside counsel guidelines now ask pointed questions about how privileged material moves. “AES-256-GCM per message, access-controlled per recipient, every open logged” turns a paragraph of hedging into a row of checked boxes — at $5 a seat, not an enterprise suite’s procurement cycle.

5. Exhibits that don’t fit

Deposition video stills, medical records in a personal-injury matter, financial disclosures in a divorce: 30 MB per secure message, sent from the compose window — instead of a consumer file-share link that lives outside the matter’s paper trail and outside anyone’s retention policy.

Privilege rarely fails in a dramatic hack. It fails one autocompleted recipient, one forwarded thread, one stale draft at a time.

What we changed because of them

Lawyers pushed us on things clinics never asked about: expiry defaults per matter, cleaner audit exports for privilege logs, recall that’s obvious enough to use mid-panic. The product is better for every user because the bar showed up. If your firm runs on Gmail or Outlook, the pieces are already in your compose window.

Built for HIPAA. Adopted by the bar.

Verified recipients, expiring drafts, and a clawback for email — $5 per seat, free for solo practices to try.

Add VaultMail to Chrome — free

Written by the VaultMail team · Published July 28, 2026