Short answer.
SealTask can coordinate narrowly scoped legal next actions after firm approval, but it is not a docketing, matter-management, document, billing, or trust-account system. Keep deadlines and authoritative legal records in specialist systems. Task content is encrypted before sync, while timing, membership, status, and other operational metadata remain server-visible.
The task layer sits between legal systems.
Legal practice software is built around matters, documents, time, billing, court rules, and retention. It may still leave an awkward coordination layer that ends up in email flags or general-purpose task apps.
A client identity can carry confidential meaning.
A task title may disclose a client, counterparty, investigation, transaction, or strategy before the body contains a single legal detail.
Encryption at rest does not remove provider access.
Many hosted tools decrypt content on their servers so they can index, process, support, or analyze it. That architecture may be acceptable for a firm after due diligence, but it is not zero knowledge.
A task manager cannot calculate legal deadlines.
Court dates, limitation periods, and rules-based deadlines need a docketing or calendaring system designed for jurisdiction-specific calculation, redundancy, and escalation.
Zero knowledge has a metadata boundary.
Workspace content is encrypted with ChaCha20-Poly1305 before sync. SealTask cannot decrypt task text, list titles, comments, checklists, or attachments. The service can still see the metadata needed to route and synchronize work.
Unreadable to the service
- Readable task titles
- Readable task bodies and notes
- Readable recurring-task template content
- Readable comment bodies
- Readable checklist content
- Readable project titles and descriptions
- Attachment plaintext
- Plaintext account passwords
- Workspace content decryption keys
Server-visible workspace metadata
- Account email addresses and workspace or project membership identities, roles, statuses, invitation states, and access timestamps
- Database identifiers and relationships, including project owner, task and note creators, comment authors, delegation members, attachment uploaders, and per-member task-read cursors
- Project timezone, section identifiers and policies, section timestamps, and task position or order
- Task priority, completion and archive state and timing; note privacy and timestamps; per-member task-read timestamps; project timestamps and archive state; note, comment, and attention counts; and workspace write or collaboration entitlement flags
- Recurrence schedule, timezone, active state, section, iteration, next-run, last-materialized, and task-materialization timestamps
- Comment authorship relationships, counts, and timestamps; comment bodies remain encrypted
- Delegation membership identifiers, roles, statuses, and timestamps; delegation notes remain encrypted
- Attachment, project, and task relationships, including task-to-attachment link timestamps; storage identifiers; ciphertext byte size (which usually approximates original file size); upload capability expiry and protocol; status; and creation, update, or deletion timestamps; attachment content remains encrypted
- Per-membership salts and membership proofs, plus the server-held project-scoped payload-binding key used to verify or compute matching HMACs; this binding key is not a workspace-content decryption key
- Real-time event types; event, project, actor, membership, browser-instance, affected entity, section, and order identifiers; changed-field names; occurrence timestamps; and missed-event counts
This disclosure covers encrypted workspace content and its server-visible metadata. The workspace-content metadata inventory is complete for the enumerated current workspace persistence and SQL models, API-response models, and SSE event models. It is not a complete privacy-data inventory and excludes account authentication, billing, security and audit, abuse-prevention, and service telemetry domains; those domains are described non-exhaustively in the privacy policy. Metadata can itself be sensitive. Attachment ciphertext size usually reveals an approximation of the original file size.
A filing date, urgency, participant relationship, or even the existence of a task can expose a sensitive matter. Keep it in the firm’s legal system when that inference would disclose too much.
Inspect the security architectureWorked example: Matter L-204 approaches a filing.
The example uses a neutral matter identifier and keeps the legal deadline and documents in specialist systems.
SealTask
L-204: confirm draft-review owner.
The task identifies the action and responsible person without copying argument, client name, or evidence.
SealTask
L-204: check that filing receipt was saved.
A completion check can live in SealTask; the receipt itself belongs in the matter file.
Specialist system
Rules-calculated filing deadline and escalation chain.
The docketing system remains authoritative and should provide the firm’s required redundancy.
Specialist system
Draft pleading, evidence, advice, and correspondence.
Substantive and privileged material stays in the legal document or matter-management system.
Encryption reduces provider-side readability. It does not change which system is authoritative, who is authorized, or how a firm supervises legal work.
Task layer versus legal system of record.
The dividing line is not simply sensitive versus non-sensitive. It is coordination versus the authoritative legal record.
| Work item | SealTask | System of record | Why |
|---|---|---|---|
| Owner, next action, and internal matter reference | Yes — after firm approval | Matter-management system | SealTask coordinates; the matter system preserves the full matter record. |
| Court and limitation deadlines | Optional secondary reminder only | Legal docketing system | A general task manager does not calculate rules or provide legal deadline controls. |
| Pleadings, evidence, advice, and privileged documents | No — do not duplicate | Legal DMS or matter file | The legal repository owns versioning, retention, legal hold, and the formal file. |
| Time entries, invoices, and trust accounting | Reminder only | Billing and trust-accounting system | Financial and regulatory records need specialist controls and reporting. |
| Co-counsel operational handoff | Yes — dedicated shared list | Matter file and agreed exchange system | Per-list access can narrow coordination, but authorization and substantive exchange remain governed elsewhere. |
Four legal workflows for a narrow task layer.
Each workflow keeps the action in SealTask and leaves the authoritative legal record where the firm’s policy expects it.
-
01 · Intake
Move a prospective matter through conflict and engagement checks.
Track the next operational step with a neutral internal reference. Keep conflict-search results, identity documents, engagement letters, and substantive intake in the approved legal system.
ExampleMatter intake L-204: confirm conflicts result owner.
-
02 · Matter work
Coordinate research, drafting, and review.
Assign the next action and owner while pleadings, advice, evidence, and privileged analysis remain in the document or matter-management system.
ExampleL-204: prepare draft for partner review.
-
03 · Recurring controls
Repeat administrative reviews without copying the record.
Use recurring tasks for trust-account review prompts, file-closing checks, access reviews, or retention reviews. Record the evidence in the system required by firm policy.
ExampleMonthly: verify closed-matter access list.
-
04 · Limited collaboration
Share a workstream with co-counsel or a contractor.
Create a dedicated matter list. For an expert witness, contract paralegal, or lateral team member with a defined sunset, optionally set an access-end date on the invitation; leave it unset when the firm requires manual removal. Use Access review to inspect each collaborator’s project grants and last activity. At the calendared ethical-wall or matter-close checkpoint, remove that person across all projects the firm lets you manage, and close legal source-system permissions independently.
ExampleDisclosure review workstream: batches and ownership only.
Product fit for a solo or small practice.
SealTask supplies encrypted task content, per-list collaboration, revocation, recurring work, and private search. It deliberately does not attempt to be a legal practice suite.
Recurring tasks without recurring plaintext
Set repeating operational work once. The task content stays encrypted on the client before sync; due dates and recurrence timing remain operational metadata.
One shared list, not blanket access
Personal (€5.90/month) adds per-list sharing. Invite a collaborator only to the list they need. Removing a collaborator revokes their server-authorized access to the project. Using access review to remove them from every manageable project applies that same server-side revocation to each project. On the server that commits the change, active real-time streams are signaled after the commit; changes committed on another server and bulk or otherwise unsignaled changes are rechecked within the current authorization lease, at most 30 seconds. Bytes already delivered or buffered by the transport cannot be recalled. The current release does not automatically rotate any affected project key or re-encrypt projects for remaining members, and removal cannot erase content or key material obtained while the collaborator was authorized. If future sensitive work needs a fresh cryptographic boundary, create a new project and share it only with current members.
Private search on the device
Search runs after local decryption in the browser. SealTask does not need a readable server-side search index of workspace content.
A €0 solo starting point
Free includes one workspace, two projects, 100 MB of encrypted attachments, and 30-day audit history. No credit card is required.
What this guide does not claim.
SealTask is not a docketing system, conflict checker, legal document repository, billing platform, trust-accounting product, e-discovery platform, or legal-hold system. It does not calculate court deadlines, and it is not currently SOC 2 certified.
Using encrypted software does not by itself satisfy a lawyer’s duties. A firm still needs vendor due diligence, device security, access governance, supervision, retention rules, incident procedures, jurisdiction-specific analysis, and any client consent or contractual terms that apply.
Removing a collaborator revokes their server-authorized access to the project. Using access review to remove them from every manageable project applies that same server-side revocation to each project. On the server that commits the change, active real-time streams are signaled after the commit; changes committed on another server and bulk or otherwise unsignaled changes are rechecked within the current authorization lease, at most 30 seconds. Bytes already delivered or buffered by the transport cannot be recalled. The current release does not automatically rotate any affected project key or re-encrypt projects for remaining members, and removal cannot erase content or key material obtained while the collaborator was authorized. If future sensitive work needs a fresh cryptographic boundary, create a new project and share it only with current members.
Questions this guide should answer.
Is SealTask approved by a bar association?
No. SealTask does not claim bar-association approval. Lawyers and firms must evaluate technology under the rules, ethics opinions, client terms, and professional obligations that apply to them.
Can SealTask staff read client or matter names in tasks?
SealTask cannot decrypt readable task, project, note, comment, checklist, recurring-template, or attachment content, and it does not receive plaintext passwords or workspace content keys. The service can still see operational metadata such as account and membership identities, relationships, task state and timing, recurrence schedules, attachment sizes and statuses, and real-time event identifiers. Metadata can itself be sensitive; the security architecture lists the complete current workspace inventory.
Should court deadlines be entered in SealTask?
Only as a secondary reminder if firm policy permits. The authoritative deadline belongs in a legal docketing system with the calculation, redundancy, and escalation controls the firm requires.
Can I share a matter list with co-counsel?
The product supports per-list sharing on paid plans. The firm must first confirm authorization, confidentiality terms, information scope, supervision, and the approved system for substantive documents.
Does end-to-end encryption make the firm compliant?
No. Encryption is one control. Compliance and professional responsibility depend on the whole operating environment, including people, devices, policies, contracts, retention, and incident response.
Sources and further reading.
- 01
SealTask security architecture Open page Encryption, key handling, server visibility, and recovery tradeoffs
- 02
SealTask pricing Open page Current Free, Personal, Team, and self-hosted terms
- 03
Best encrypted task management Open page A source-backed comparison of encryption models and product tradeoffs
- 04
ABA Model Rule 1.6 — Confidentiality of Information Open source Includes the duty to make reasonable efforts against inadvertent or unauthorized access or disclosure
- 05
SRA — Confidentiality of client information Open source Guidance for solicitors on confidentiality, disclosure, and information handling
- 06
NIST SP 800-171 Rev. 3 — Least Privilege Open source A primary-source access-control reference for limiting and reviewing privileges
Coordinate the next action, not the whole matter file.
Start solo on Free. Review the security architecture and your firm’s requirements before placing any client-related information in a new tool.