Security

The controls that protect privileged work, measured from the live service, the code and the dependency tree, with the source of every figure.

Evidence built September 13, 2026

At a glance

TLS 1.3
TLS 1.3 and 1.2 only; 1.1 and 1.0 refused
measured September 13, 2026
0
known vulnerabilities across 284 dependencies
0 critical · 0 high · September 13, 2026
160
security test cases in 14 suites
27 of 33
API route patterns that require an identity
TOTP
two-factor sign-in, enforced on member accounts after enrollment
Limited
sign-in attempts from any one address
Ed25519
signature on every release, verified before install
ed35:4e44:a0c5:540c:e3d7:5bb8:180c:2071
127.0.0.1
the only address the desk listens on
the member’s own machine

Where data lives and where it is answered

The matter file stays on the member’s machine. A question about a matter is treated as sensitive, and a sensitive question is answered only on hardware we own, whatever lane is selected.

Model lanes and how questions about a matter are handled
LaneWhere a question is answeredQuestions about a matter
SovereignHardware we own; the question text is not storedAnswered here
StandardModel providers, reached through our gatewayRouted to the sovereign lane
Your own keyThe provider the member chooses, on the member’s own accountRouted to the sovereign lane
Local
matters, evidence and drafts are kept on the computer the kit runs on
127.0.0.1
the desk listens only on the member’s own machine
Audited
every work session writes its own audit log in the matter
Not stored
question text on our own lane

Network and transport

Measured against the live domain on September 13, 2026, with legacy protocols allowed on the testing side, so a refusal is the server’s.

TLS protocol versions accepted by the server
ProtocolResultNegotiated cipher
TLS 1.3AcceptedTLS_AES_128_GCM_SHA256
TLS 1.2AcceptedECDHE-RSA-AES128-GCM-SHA256
TLS 1.1Refused
TLS 1.0Refused
Certificate and issuance controls
ControlValue
Certificate issuerLet's Encrypt
Certificate keyRSA 2048-bit
Certificate valid untilDec 6 00:29:15 2026 GMT
Authorised certificate authorities (CAA)letsencrypt.org, pki.goog, sectigo.com
Connection from the kit to our gatewayHTTPS on a private Tailscale (WireGuard) network

Response headers

As served by https://law.gagegreengroup.com/, read September 13, 2026.

Security headers served by the live site
HeaderValue
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preload
Content-Security-Policy
  • default-src 'self'
  • script-src 'self' https://js.authorize.net https://jstest.authorize.net 'unsafe-inline'
  • style-src 'self' 'unsafe-inline' https://fonts.googleapis.com
  • font-src 'self' https://fonts.gstatic.com data:
  • connect-src 'self' https://*.supabase.co https://js.authorize.net https://jstest.authorize.net https://api.authorize.net https://api2.authorize.net https://apitest.authorize.net https://vjrfurqoyokxbcdwjdch.supabase.co
  • img-src 'self' data:
  • worker-src 'self'
  • frame-src 'none'
  • base-uri 'self'
  • form-action 'self'
  • upgrade-insecure-requests
X-Frame-OptionsDENY
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
Permissions-Policycamera=(), microphone=(), geolocation=(), payment=(self)
X-DNS-Prefetch-Controloff

Access control

Every API route is classified in one registry, and the edge enforces the class before a request reaches the application. 27 of 33 route patterns require an identity. Limits apply per address; their values are not published.

Rate limits and abuse monitoring
ControlStatus
Requests to each API route, per addressLimited
Requests across the whole API, per addressCapped
Sign-in attempts, per addressLimited
Payment requestsLimited
Repeated reads of matter recordsRaise a security alert

Security tests

160 test cases in 14 suites guard the boundaries above, and run before every release.

Security test suites and case counts
SuiteCases
API access and rate limits11
Account recovery9
Safe rendering3
Document preview2
Invitations and member sandboxes16
Live security checks9
Environment separation13
Sign-in security24
Prompt-injection fencing3
Row-level security11
Matter isolation17
Security-critical routes15
Structured data safety2
Platform hardening25
All suites160

Supply chain and releases

Every commit is scanned before it lands, the dependency tree is audited, and every release of the kit is signed and verified before it installs.

Supply-chain and release controls
ControlMeasured
Commit scanninggitleaks secret scan, secret-shape scan, direct model-provider call guard
Dependency audit0 known vulnerabilities across 284 dependencies, September 13, 2026
LockfileCommitted, so installs are reproducible
Release signatureEd25519, verified against a pinned public key
Key fingerprinted35:4e44:a0c5:540c:e3d7:5bb8:180c:2071
Published kitVersion 9.27: signature verifies, September 13, 2026
Unverified kitThe installer refuses it and writes nothing
Clean-room rehearsal10 of 10 install steps, 70 probes, version 9.27

Verify a kit yourself: python3 kit_signing.py --verify-file INSTALL.json

Subprocessors

Third parties that process data for the platform, each read from the configuration that uses it. The sovereign lane uses none.

Subprocessors and their purpose
SubprocessorPurposeEvidence
VercelWebsite hosting and edge deliveryLive response header
SupabaseMember accounts, sign-in and member recordsContent-Security-Policy
Authorize.NetCard paymentsContent-Security-Policy
Amazon Web Services (SES)Transactional emailEmail configuration
ResendTransactional email, fallbackEmail configuration
TailscalePrivate network between the installed kit and our gatewayKit gateway configuration
Model providersStandard-lane answers to questions not tied to a matterModel lane routing

Report a vulnerability

Write to us with the affected address, the steps to reproduce it and the impact you observed. Please do not access member data or degrade the service while testing.

Published security contact
FieldValue
Contactmailto:law@gagegreengroup.com
Expires2027-03-13T00:00:00.000Z
Preferred-Languagesen
Canonicalhttps://law.gagegreengroup.com/.well-known/security.txt
Policyhttps://law.gagegreengroup.com/security#disclosure

Sources

The part of the code each control was read from, with the SHA-256 of that file when this page was built.

Where each control was read from, with hashes
ControlsRead fromSHA-256
Rate limitsAccess-control and monitoring code2ec1b4857f1d…
Rate limitsRate-limit codefaa61e4b298a…
Route registryRoute access registry2ec1b4857f1d…
Two-factor enforcementMember sign-in codec9309bb5138d…
Release integrityRelease signing tool0ec69ba84916…
Release integrityKit installer146ae43b661e…
Data handlingDesk server0e277405f8ef…
Data handlingModel lane routingbf9ac7a2ee32…
Data handlingKit gateway configurationf2cd46e405c0…

Security you can check, not take on trust.

Gage Law

Gage Green Group · Established 2009

Gage Law provides legal research tools, document preparation, and intelligence services. Gage Law does not provide legal advice, attorney representation, or guarantee any legal outcome. No attorney-client relationship is formed by use of this platform. Users are responsible for verifying all information and consulting qualified legal counsel before taking action.

All information is derived from primary source law, public records, and filed court documents. Results depend on the quality of input and the specific circumstances of each matter. Past performance of the platform does not guarantee future results.

By using this service, you acknowledge that you have read and agree to our Terms of Service and Privacy Policy.