Learn · For solo & small law firms
Law firm client intake software that keeps your form and seals every inquiry.
Brun is law firm client intake software built on one idea: a prospective client’s inquiry is privileged the instant they hit submit. So Brun keeps the contact form already on your firm’s website and seals every submission inside the visitor’s browser before it sends, and the vendor only ever stores ciphertext it cannot read.
That makes it secure client intake software for attorneys that doubles as a simple lead board: website inquiries become leads you can conflict-check and work, while the privileged facts stay sealed with a key only your firm holds. No portal, no rebuild, no vendor reading your matters.
What is secure client intake software for a law firm?
Secure legal client intake software is a contact form that does its encrypting inside the prospective client’s browser, before submission. Privileged facts cross the network already sealed and reach the vendor’s storage already sealed — at no point between the client’s device and your own does a readable copy exist.
For a law firm that protection starts before you’ve run a conflict check: Rule 1.18 treats a prospective client’s facts as confidential the moment they’re shared, so nothing about a matter or an opposing party should ever sit readable on a vendor’s server. See the full mechanics of that guarantee on the secure intake page. What that ciphertext actually looks like on our servers shows up further down, in step 2.
Why do ordinary attorney intake forms put privilege at risk?
Attorneys are ethically on the hook for privileged consultation details the instant a prospective client hits submit. Yet conventional intake tools store those inquiries in plaintext on a vendor’s servers, where staff, subprocessors, or a breach could expose them, putting Rule 1.6/1.18 confidentiality and attorney-client privilege at risk before the firm has even opened a matter.
TLS only protects a submission in transit; the moment it arrives, an ordinary contact form hands the intake vendor and your own server a fully readable copy. For a law firm, that plaintext instant is exactly where privilege and Rule 1.6/1.18 confidentiality get put at risk. Here is what a prospective client is really typing into that box:
- Attorney-client privileged consultation details a prospective client types into the contact form.
- Confidential case facts (criminal charges, injury circumstances, financial disputes, family matters).
- Conflict-check data such as adverse-party and opposing-counsel names disclosed before engagement.
- Settlement figures, demand amounts, and prior legal history shared during intake.
- The mere identity of a prospective client seeking counsel on a sensitive matter.
The intake vendor can read every privileged word
Every form vendor, every subprocessor on their list, and anyone who breaches their database sees the same readable version of your prospective client’s matter — the exact facts Rule 1.18 already obligates you to protect.
The ethical duty is yours under Rule 1.6(c) and 1.18
ABA Model Rule 1.6(c) makes safeguarding client information an affirmative ethical duty: lawyers must make reasonable efforts to prevent unauthorized access to or disclosure of information relating to representation. Rule 1.18 extends that same duty of confidentiality to prospective clients the moment they consult about a matter — which includes anything typed into a website intake form. Most intake vendors can technically read submissions stored on their servers, creating a third-party access risk to privileged communications that bar opinions increasingly flag.
How does Brun keep a prospective client’s inquiry unreadable?
Privilege attaches the instant a prospective client hits submit, so Brun locks the inquiry in their browser before it can reach us, and never holds the key that would unlock it. Follow the same inquiry below as it moves from a prospective client’s screen to a conflict-ready lead, staying ciphertext at every stop until it lands on an authorized device at your firm.
Sealed in their browser.
Nothing changes for them: the same intake fields, the same firm branding, no portal to log into and no app to install. They describe their matter and hit send.
Before it ever leaves the device, a small script locks the submission using your firm's public key — the lock, not the key that opens it. What reaches the network is already ciphertext; the privileged facts never travel in the clear.
Screened. Never opened.
Structural checks on the envelope run and pass, and what lands in our database afterward is ciphertext, nothing more. Because we never hold the unlocking key, there is nothing for a vendor employee or a subprocessor to read — and nothing a subpoena aimed at us could turn into a readable privileged communication.
We store gibberish.
stored on our serversWe can’t read this: the inquiry, the lead it becomes, or any note your team adds. What we do see, because the service needs it, is your firm’s account email, billing status, and any support ticket you open with us.
Unlocked on your board.
Your team opens the intake inbox and decryption runs locally, on the reviewing attorney's device, using a key held by your firm and no one else. That screen is the only place the privileged matter details are ever readable.
The decrypted inquiry — re-encrypted with your firm's key — lands on a clean CRM board as a lead you conflict-check, assign, and note as it moves from New to Won toward a retained client.
Nothing on your firm’s page can decrypt anything — a visitor’s browser sees only a public intake handle, useless without your key. Full mechanics →
Ordinary law firm intake form vs. Brun zero-knowledge intake.
For a law firm the stakes are simple: does a breach, a subpoena, or a bar audit hand someone else your client’s privileged facts? An ordinary contact form leaves that answer to the vendor’s security. Brun removes the question by never holding anything readable in the first place.
| Ordinary law firm intake form | Brun zero-knowledge intake | |
|---|---|---|
| Where the inquiry is encrypted | In transit only (TLS), then decrypted on arrival | In the prospective client's browser, before it sends |
| Can the intake vendor read privileged facts | Yes — submissions sit in plaintext on their servers | No — they store ciphertext only |
| What a vendor breach exposes | Readable case facts, party names, and contact details | Ciphertext only |
| What a subpoena to the vendor returns | Readable privileged consultation details | Ciphertext only |
| Conflict-check data (adverse parties, opposing counsel) | Stored in plaintext, exposed in transit and at rest | Sealed until your authorized team decrypts it |
| Rule 1.6(c) / 1.18 confidentiality posture | Third-party access risk to prospective-client information | Vendor has no ability to access the content |
| Setup | Often a portal, hosted form, or website rebuild | Two changes to the form your firm already has |
Do I have to replace my firm’s website to use it?
No. You keep the contact form already on your firm’s site. Change one attribute: your firm's contact form action becomes /public/intake/{public_handle}. Nothing your prospective clients see changes — fields, layout, and design stay put. A single script tag, added to that same page, takes care of encrypting each submission before it leaves the prospective client's browser. The integration stops there — no developer sprint, no hosted portal, no rebuild of the site.
- <form action="/your-old-endpoint">
+ <form action="…/public/intake/your-handle">
+ <script src="…/intake.js">Legal client intake software questions, answered.
What is the best client intake software for a solo or small law firm?
Brun captures the inquiries your website already receives and turns them into a workable pipeline without asking prospective clients to log into anything new. It keeps the exact contact form already on your firm's website, encrypts every submission inside the visitor's browser before it sends, and lands the result on a clean board your team works as leads, while the underlying privileged details stay protected. The plan choices appear once you reach signup, and every plan carries the same browser-side encryption — privacy is never something you pay more to get.
How does encrypted client intake protect attorney-client privilege?
Privilege and your Rule 1.18 duty to prospective clients attach the moment someone shares case facts with you — including through a web form. Brun encrypts the inquiry in the prospective client's browser, so what reaches Brun's servers is ciphertext we cannot read. Only your firm holds the keys to decrypt it. That means no vendor employee, subprocessor, or server breach can expose privileged consultation details, which is exactly the kind of unauthorized-access risk Rule 1.6(c) tells you to prevent.
Do I have to replace my law firm's website to use secure intake?
No. That is the core difference. Most legal intake platforms hand you their own hosted form or a portal link to bolt on. Brun keeps your existing website contact form — same fields, same design, same URL — and adds browser-side encryption underneath it. Your prospective clients notice nothing; your firm gets confidential intake without a redesign or a developer project.
Can the software provider read my clients' confidential inquiries?
With Brun, no — and that is the point of a zero-knowledge design. Because each inquiry is encrypted in the browser before it ever leaves the visitor's device, Brun stores only ciphertext it has no ability to decrypt. Conventional intake and CRM vendors store submissions in plaintext, meaning their staff or systems can technically view privileged matter details. If a vendor can read it, so can a breach or a subpoena aimed at them.
How does encrypted intake handle conflict checks?
Conflict checking depends on adverse-party and opposing-counsel names that prospective clients disclose at intake — some of the most sensitive data your firm holds. In Brun, those details arrive as a decrypted lead only your authorized team can open, so you can run conflicts against information that was never exposed to a third party in transit or at rest. Sensitive party names don't sit in plaintext on a vendor's database waiting to leak.
Is browser-encrypted intake compliant with bar confidentiality rules?
Brun is built to support your obligations under ABA Model Rules 1.6(c) and 1.18, which require reasonable efforts to safeguard both client and prospective-client information. By encrypting submissions in the browser and storing only data the vendor cannot read, Brun removes the third-party access risk that bar ethics opinions increasingly warn about with digital intake forms. Every plan carries that same browser-side encryption, so firms in regulated or high-stakes practice areas aren't choosing between confidentiality and cost.
Go deeper on encrypted legal intake.
- What zero-knowledge secure intake isPlainly put: contact-form submissions encrypted in the browser before they send, stored as ciphertext no vendor can read.
- Why your intake must be encryptedWhat a readable inquiry costs a firm — breach exposure, subpoenas aimed at vendors, AI training — and how encryption shuts each door.
- Secure intake and regulated confidentialityHow the encryption relates to regulated, privilege-bound work — and why Brun still signs no BAA.
- Brun overviewSecure website intake feeding a simple lead board — the whole product, sized for small firms.
- See your industryEvery vertical Brun serves, recruiting through real estate — browse the whole set.
Not legal advice
This page describes Brun’s architecture and how it relates to attorney-client confidentiality; it is general information, not legal advice. Your obligations under the ABA Model Rules and your state bar depend on your specific practice — confirm your compliance posture with qualified counsel.
Privileged inquiries only your firm can read
Start protecting your client intake.
Brun is encrypted client intake software for solo and small law firms: a prospective client’s inquiry leaves their browser sealed, sits with us as ciphertext, and opens as a conflict-ready lead only inside your firm. Two small edits to your form and you’re live the same day.