Southlake, TX
Secure Client Communication Texting for Southlake TX Attorneys
Secure is a word rather than a specification. A Southlake firm evaluating text messaging for client communication will hear it used freely, and it tells the firm almost nothing about what it needs to know.
Book a Demo
What a firm actually needs is a set of factual answers about where messages live, who can reach them, how long they persist, and how they come back out. Those answers are specific, they can be written down, and once the firm has them its own counsel can decide whether the arrangement is adequate for its obligations.
This page is a list of the questions and an explanation of why each one matters. It makes no claim about what any platform provides or satisfies. Cleod9 provides cloud communication for Dallas-Fort Worth businesses, including business text messaging, and the right way to use this page is to take the questions to a specific conversation and get the answers in writing. It is operational guidance, not legal advice, and what the firm's professional obligations require is for the firm and its own counsel to determine.
Three things the firm is trying to establish
Underneath every question on this page are three plain concerns.
Where does a message exist, and for how long. A text message exists in more places than people assume: the sending platform, the carriers that carried it, the recipient's device, and possibly a backup of that device. The firm controls one of those.
Who can reach it. Both outside the firm and, more relevantly, inside it. Internal access is the exposure firms think about least and the one most likely to matter.
How does it come back out. If the firm needs a thread as part of a matter file, or needs to produce it, or needs to leave the provider entirely, what is the mechanism and who can perform it.
The questions to put in writing
Ask these specifically, and ask for the answers in a document rather than in a conversation:
- Where is message content stored, and is it stored in a form the provider's own staff could read.
- How long is message history retained by default, and is that period configurable by the firm.
- Who inside the provider can access message content, under what circumstances, and is that access logged.
- Who inside the firm can read threads, and can that be limited by person or by role.
- Can the ability to read a thread be separated from the ability to send in it.
- How is a user's access removed, how quickly does it take effect, and what happens to anything on that person's device.
- How does the firm export a thread, in what format, and can it be done without the provider's involvement.
- How is a message deleted, who can do it, and what remains afterward.
- What happens to the firm's message history if the firm leaves the provider.
- Is the firm notified if the provider becomes aware of a problem affecting its data, and by what means.
A provider that answers these plainly has thought about them. One that responds with general assurances has told the firm something useful in a different way.
Internal access is the exposure firms ignore
Firms spend their attention on the outside and leave the inside undecided.
In a small firm where every staff member can read every client thread, the firm has made a decision about confidentiality whether or not anyone said so. That may be entirely fine, and it should be a decision rather than a default.
Ask whether access can be scoped, and then decide what the firm wants. Most land somewhere between everyone and nobody: the people who handle client communication can read and send, others can see only what they need, and the ability to send to a group is held by fewer people still.
Individual logins, always. A shared account makes it impossible to establish who read or wrote anything, and the log is the only thing that answers that question later.
Access removal is the control firms actually use
Of everything on this page, the one that gets exercised is removing somebody's access, and it is the one most often untested.
Ask exactly how it is done, how fast it takes effect, and whether it reaches a mobile device that is offline at the time. Then have somebody at the firm actually do it once, on a test account, so the procedure is known rather than described.
Two people at the firm should be able to perform it. A control only one person can operate fails on the day that person is the reason it is needed.
Put it on the departure checklist beside the email account and the building key, and put the equivalent on the arrival checklist. Access that accumulates over years is the quiet version of the same problem.
Retention has two opposite failure modes
Keeping messages too long and deleting them too soon are both real risks, and they pull against each other.
A thread that no longer exists when the firm needs it is a problem. A thread that persists for years in a system nobody thinks about is a different problem. Which risk matters more depends on the firm's practice and its obligations, and that judgment belongs to the firm's own counsel rather than to a default setting.
What the firm needs from the provider is factual: what the default is, whether it can be changed, and whether the change applies going forward or to existing history. Then the policy can be written to mean something.
Export is a security question, not just a convenience
A thread that cannot be moved into the matter file lives only in the messaging system, which means the firm's record of a client communication depends on a vendor relationship continuing.
Ask how export works in practice. Whether it produces something readable, whether it includes timestamps and both sides of the conversation, whether it can be done for one thread or only in bulk, and whether firm staff can do it themselves.
Then test it once during setup rather than discovering the answer when somebody needs a thread urgently.
The half the firm cannot secure
A message the firm sends arrives on a device the firm does not control. It may sit on a lock screen visible to whoever is nearby, in a phone shared within a household, backed up somewhere, or forwarded in one tap.
No platform changes that, and any assurance that suggests otherwise should be read carefully.
What follows from it is a content rule rather than a technology decision. Messages carry logistics: appointments, scheduling, confirmations that something arrived, and requests to arrange a conversation. Case substance stays out, and anything sensitive becomes a message asking for a time to talk.
A firm that holds that line has removed most of the risk before any of the questions above are answered, which is why the content rule is the first thing to write and the last thing to relax.
What not to rely on
Three things that look like answers and are not.
A word in marketing material. Secure, protected, and enterprise-grade are descriptions rather than commitments, and none of them tell the firm where a message is stored or who can read it.
A certification name without scope. Certifications cover defined systems and defined controls, and the useful question is what specifically is covered and by which document, which a provider can answer in writing.
A verbal assurance during a sales conversation. Not because anyone is being dishonest, but because the person answering may not know, and a written answer is one somebody has checked.
Write the policy after the answers, not before
Firms sometimes draft a communication policy first and then adopt a platform, which produces a policy the platform cannot actually support.
The better order is to get the factual answers, take them to the firm's own counsel, and let the policy be written against what the arrangement genuinely does. Then the policy is enforceable, which is the only kind worth having.
Whatever it says, it should cover at minimum: what may be sent by message and what may not, who may send, that messages go from the firm's number rather than personal phones, how a thread reaches the matter file, how long history is kept, and how access is removed when somebody leaves.
Client consent and expectations
Separately from the technical questions, clients should know what the channel is and what it is for.
Whether the firm needs a client's agreement to communicate by text, what it should tell them about the limits of the channel, and how any of that is documented are questions for the firm and its own counsel. Many firms settle it at engagement, in writing, alongside the other communication preferences.
Operationally, the firm should be able to show for any client the date consent was recorded, the number, and the wording used. Requests to stop are honored promptly and recorded where the next person will see them, including when a client writes them in their own words rather than as a keyword.
Common questions
Is regular text messaging appropriate for client communication at all?
That is precisely the question for the firm's own counsel, and the answer depends on what the firm sends. Many firms conclude that a logistics-only channel is appropriate and that anything substantive belongs elsewhere, which is a decision about content rather than about the platform.
Should the firm use a separate number for client messaging?
Usually the firm's own number is right, since clients recognize it and it keeps threads with the firm rather than with individuals. What matters more is that it is never an individual's mobile.
What about messages sent from an attorney's personal phone?
The firm cannot supervise them, cannot export them, cannot remove access to them, and loses them when that person leaves. Every question on this page becomes unanswerable at once.
How often should this be reviewed?
Once a year, and whenever the provider changes something material. Ask the provider how the firm would be told about such a change, which is itself one of the questions worth having in writing.
The page to keep
The output of this exercise is a short document the firm can hand to its own counsel:
- The written answers to the ten questions above, dated.
- The firm's decision on internal access, and who currently has it.
- The retention period in effect and who can change it.
- The tested procedure for removing access, and the two people who can perform it.
- The tested export procedure.
- The content rule: what may be sent by message and what may not.
- The date this was last reviewed.
The client who is not alone with their phone
There is a category of matter where the risk is not a vendor, a server, or a departing employee. It is somebody in the same house.
Family matters, employment disputes, anything involving a person the client lives or works with. In those situations a message from the firm arriving on a lock screen, or sitting in a thread on a phone somebody else can pick up, is a real exposure that no platform question addresses.
Ask the client, once, at the start: is this number private to you, and is text a safe way to reach you. Most will say yes and think nothing of it. The ones for whom it matters will be glad to have been asked, and their answer changes how the firm communicates with them for the life of the matter.
Record the answer where anyone contacting that client will see it, not in a note somebody has to go looking for. A preference captured and then invisible is the same as never having asked, and this is the category where a single message sent to the wrong device causes harm that cannot be undone.
Where the answer is no, the firm falls back to whatever channel the client says is safe. That is a conversation to have with the client rather than a setting to configure, and it is worth the two minutes it takes.
Talking to Cleod9
Cleod9 is a Dallas-Fort Worth provider supporting its own customers, so a Southlake firm works with someone in the same metro rather than a distant queue. The platform is described on the Cleod9 services page.
Bring the ten questions and ask for written answers. Then test the two procedures that matter, access removal and export, before the channel goes into daily use. What the answers mean for the firm's obligations is for the firm's own counsel to decide, and that decision is much easier to make from a page of specifics than from a conversation about features.