Public information
Sub-processors
The third parties that receive data when a firm uses BRON, what each one does, and what actually reaches it. Most are off until a firm supplies a key. The ones that are on by default are marked as such.
Last updated August 21, 2026.
How to read this page
Under the privacy policy, the firm is the controller of its client data and BRON is a processor acting on the firm's instructions. The providers below are sub-processors: they process data on BRON's behalf so a feature can work.
The right-hand column is the one that matters most. Always on means the provider receives data on any working install. On by default means it is used unless an operator changes a setting. Firm-enabled means nothing reaches that provider until the firm supplies a credential or connects an account, and most firms will never enable most of them.
This list is derived from the code that makes each call. It is maintained as features change, and it does not describe a specific firm's configuration. To find out which of these are active for your firm, ask your firm administrator, who controls the integration settings.
Core infrastructure
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| Supabase | The database, the sign-in system, and the document store. One private storage bucket. | Everything the firm puts in the service: account records, matter data, document files, privileged and work-product material, billing and trust ledgers, and the audit record. | Always on |
Documents are held in a private bucket and served through signed links that expire. The key that can read the database is held on the server only and is never sent to a browser.
[OWNER: name the hosting region for the Supabase project and the host the application server runs on, and state whether backups stay in that region. The repository does not record either, so residency cannot be stated here without you.]
AI model providers
These receive the content a feature needs to do its work. For drafting, analysis, and the assistant, that includes document text and matter facts, which for a law firm means privileged material and client confidential information. Read the AI section of the privacy policy before enabling anything here.
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| Anthropic | The primary model provider: drafting, analysis, the attorney assistant, and the client portal assistant. Also runs the provider's own web search when the product researches a court rule. | Document text, matter facts, and attorney work product. Search queries composed by the model may carry matter context. | On by default |
| OpenAI | Three separate jobs. It computes the embeddings that make documents searchable. It transcribes live deposition audio and dictation. It also serves chat models a firm may select. | Every ingested document chunk and every search query. Raw audio of depositions and dictation. Chat content when an OpenAI model is chosen. | On by default for search and transcription |
| Gemini models, when a firm or user selects one. | The same content class as Anthropic, when selected. | Firm-enabled | |
| Voyage AI | An alternative embedding provider for legal text. | Document chunk text, if selected instead of OpenAI. | Firm-enabled, off by default |
Two things a general counsel should know before signing. First, search and transcription mean OpenAI is not optional in a default install: text you upload is sent there to be indexed, even if every model you talk to is Anthropic. Second, if the primary provider fails or hits a quota, a request can be retried automatically on a different provider from this table. A firm that needs work confined to one vendor should raise that before deployment.
Transcription is the sharpest edge here, and the code says so in its own comments: deposition audio and dictation are privileged speech, and they go to OpenAI today. A self-hosted transcriber is named in the source as the intended replacement and is not built.
Email, messaging, and notifications
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| Resend | Sends outbound email from the platform. | Recipient addresses, message subject and body, and any attachment, including executed documents. | Firm-enabled |
| Mailgun, Amazon SES, or Resend | Receives inbound email addressed to a matter. The firm chooses which one. | Inbound messages and their attachments. | Firm-enabled |
| Google (Gmail API) | Sends mail from an attorney's own mailbox, after that attorney connects it. | The outbound message and its recipients. | Firm-enabled, then per-attorney consent |
| Microsoft (Graph) | The same, for Outlook and Microsoft 365 mailboxes. | The outbound message and its recipients. | Firm-enabled, then per-attorney consent |
| Twilio | Sends SMS notifications. | A phone number and a short prompt to sign in. It is built as a notification bridge and does not carry privileged content. | Firm-enabled |
| Apple (APNs) | Delivers push notifications to the iOS companion app. | A device token and the notification payload. | Firm-enabled, off by default |
Payments, billing, and trust accounting
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| Stripe | Processes card payments for invoices. | Client name and email, invoice amounts, and a matter reference. Card details go from the payer's browser to Stripe. | Firm-enabled |
| LawPay / AffiniPay | Processes retainer and trust payments under the rules that apply to client funds. | Payment amounts and matter references. Card details are typed into fields hosted by AffiniPay inside the payer's browser and never pass through BRON. | Firm-enabled |
| Plaid | Reads trust-account bank transactions so the three-way reconciliation can be performed against the bank record. | Bank account connection and transaction history for the account the firm links. | Firm-enabled |
| A client's e-billing system | Receives LEDES invoice submissions at an endpoint the firm configures. | Billing narratives, timekeeper records, and matter data. Narratives frequently describe legal work. | Firm-enabled |
BRON records and reconciles trust activity. It does not move client money on its own. See the terms for what that division of responsibility means.
Courts, dockets, and legal research
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| CourtListener and RECAP (Free Law Project) | Looks up opinions, verifies citations, and reads federal dockets. | Citation strings, case captions, court identifiers, and docket numbers. Docket lookups carry matter-identifying but publicly filed information. | On by default, and works without a key |
| LexisNexis | Case law research through a firm's own subscription. | Search terms and citations. | Firm-enabled |
| Thomson Reuters (Westlaw) | Case law research through a firm's own subscription. | Search terms and citations. | Firm-enabled |
| Docket Alarm or UniCourt | Reads state-court dockets. The firm picks one. | Case number and court. | Firm-enabled |
| OpenLaws | Retrieves statutes and regulations. | Statutory citations and search terms. | Firm-enabled |
| Congress.gov | Retrieves federal legislative material. | Legislative search terms. | Firm-enabled, off by default |
| Google (Programmable Search) | General web research inside the product. | Research queries, which can include the names of parties being researched. | Firm-enabled, off by default |
Party and entity screening
Two of these are contacted without any key, so they are active on a default install. They receive the names of the parties and companies in a matter.
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| GLEIF | Resolves a company to its legal entity identifier and corporate family. | A legal entity name, then its identifier. | On by default, and works without a key |
| SEC EDGAR | Looks up public company filings and registered agent addresses. | A company name. | On by default, and works without a key |
| OpenSanctions | Screens a party against sanctions and politically-exposed-person lists. | A person or company name. | Firm-enabled, off by default |
Filing and service of process
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| Tyler Technologies (Odyssey File & Serve) | Submits e-filings through a gateway the firm stands up. It is the only e-filing provider supported; any other value is refused rather than ignored. | The filing itself, meaning full document content and the case caption. | Firm-enabled |
| A process server the firm chooses | Receives service orders at an endpoint the firm configures. BRON does not select the vendor. | Recipient name and physical address, case reference, and document titles. | Firm-enabled |
Practice-management systems
These connect a firm's existing case-management system. Each one exchanges credentials and syncs records in both directions.
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| Clio, MyCase, PracticePanther, Smokeball, Filevine | Syncs matters, contacts, and time entries with the firm's practice-management system. | Matter records, contact details, and time entries. Sync credentials are sent to authenticate. | Firm-enabled |
Document timestamping
| Provider | What it does | What reaches it | When it is used |
|---|---|---|---|
| OpenTimestamps calendar servers | Anchors a fingerprint of a signed document and of the audit record so their existence at a date can be verified independently. | A SHA-256 digest and nothing else. No document content, no names, and no personal information. No money or cryptocurrency moves. | On by default |
Runs inside the deployment, not sent to a third party
These are worth naming because they are often assumed to be outside services. In BRON they are not, so the data they handle stays in the deployment.
- Electronic signature. Signing is built in house. There is no e-signature vendor. A previous third-party signing service was decommissioned and no code path reaches it.
- Text recognition of scanned documents. Runs in the application process. Scanned pages are not sent to an outside recognition service.
- Text analysis and re-ranking. Runs as a companion service reachable only on the local machine. An operator can point it at a remote host, which requires deliberately setting two separate values.
- Malware scanning. When enabled, it runs inside the deployment rather than at a cloud scanning vendor, so document bytes are not transmitted for scanning. See the security section of the privacy policy for its default state, which is off.
Not used
- No analytics or tracking vendors. There is no analytics package, product-telemetry service, session recording, heatmap, advertising pixel, or tag manager anywhere in the application.
- No third-party error-tracking service.Errors are held briefly in the browser's memory and leave the device only when a signed-in person submits a support report, which shows them what it contains.
- No external fonts or content delivery networksfor the interface. Fonts are served from the application's own address.
Three scripts do load from another company, each only on the screen that needs it: the payment fields on the client retainer screen, the bank-linking dialog used for trust reconciliation, and the Microsoft library required by the Word and Outlook add-ins. Each corresponds to a provider listed above.
Changes to this list
A firm that has a signed services agreement should look to that agreement for any notice commitment about new sub-processors. This public page is updated as the product changes and is not itself a notice mechanism.
[OWNER: if you intend to offer advance notice of new sub-processors, or a data processing agreement, state the commitment and the notice period here. The repository records neither, so nothing is promised above.]
Questions
Signed-in users can ask through Support. Prospective firms can use Request a consultation. A client of a law firm should direct questions about how their own matter is handled to their firm, which decides which of these providers it enables.