File protection software — Law firms

Protecting the files your clients entrust to you

QRlocker is software that installs on your computers and automatically encrypts your confidential files — at the office, at home, and at the courthouse. You didn't train to manage cybersecurity, and you won't have to: nothing changes in the way you work.

NIST post-quantum encryption Your keys never leave your device Compatible with your current storage 2-click install on Windows, macOS, and Linux

Where it starts

The risk isn't technical. It's ethical.

You're bound by attorney-client privilege — but your files don't always know that. An exposed file isn't just an IT failure: it's a breach of the trust a client placed in you personally.

The laptop taken to a hearing

Lost or stolen, it hands over every file in plain text. The login password protects nothing: all it takes is pulling the drive.

The firm's cloud folder

The provider technically has the ability to access the files. You trust them — your clients, for their part, trusted you.

The last-minute USB drive

The most sensitive document in the case, in a jacket pocket, the night before closing arguments.

Independent practices don't have a dedicated IT department, and most security tools require technical expertise that a lawyer's day-to-day work doesn't allow time for. Large firms, meanwhile, have deployed solutions from major cybersecurity vendors — but often at the cost of their sovereignty: the encryption keys are held by the vendor, and the files remain technically accessible to third parties.

QRlocker addresses both situations: protection that every lawyer uses themselves, with no technical expertise required, with keys that stay on their own devices — never with a vendor, never with us.

What QRlocker does

Security follows your data, not the network

QRlocker is a data protection software solution that works with any existing storage system — local, cloud, USB, NAS — without changing how it works.

Encryption at rest

Files are automatically encrypted when stored — at all times.

In-memory decryption

Data is only decrypted during active use. Otherwise, it stays protected.

Automatic re-encryption

Files lock instantly when closed. Re-encryption speed: 300 Mbps.

Any storage medium

Works on cloud, local drives, USB, and NAS — no IT changes required. In the Enterprise Edition, the firm chooses the approved storage locations.

In practice

Just one extra step in your day

It's the question every lawyer asks before installing anything: what will this change about the way I work? Here's the answer, straight up.

Once, at setup

You copy your client files into a vault — a simple copy-paste from your file explorer, with the full folder structure intact. One vault per client, per practice group, or a single vault for all your files: it's your choice.

Then, every day

New
You open QRlocker and your vault

This is the only thing added to your routine. A few seconds.

Unchanged
A window opens, identical to your file explorer

Your entire folder structure is there: your client folders, subfolders, and files, in the same locations and under the same names.

Unchanged
You open the client folder, then the file

With your usual software. No proprietary format, no conversion, no extra steps — and no waiting: decryption is too fast to notice.

Unchanged
You work, you save, you close

Re-encryption is instant on close. There's nothing for you to trigger, nothing to check.

A vault opened: your client folders, in the same places, under the same names.

No VPN. No digital certificate to manage. No IT involvement.

The real question

Who holds the keys to your files?

Encrypting your data is pointless if a third party holds the key. That's the entire difference between "secure" storage and storage you alone control.

Standard cloud storage
  • Encryption keys are generated and held by the provider.
  • The provider, its subcontractors, and its administrators can technically access the files.
  • A request sent to the provider concerns readable data.
  • Confidentiality relies on a contractual commitment, not a technical impossibility.
With QRlocker
  • Keys are generated and held exclusively on your device.
  • CyferAll cannot access them. Neither can your hosting provider.
  • A request sent to your provider can only concern unreadable files.
  • Confidentiality relies on a technical impossibility, not a promise.

And the quantum deadline: a confidential file today may need to stay confidential for thirty years. Data encrypted with today's standards is already being collected for future decryption by quantum computers. QRlocker uses the post-quantum encryption standardized by NIST (FIPS 203), designed to withstand that deadline.

Compliance

Three obligations, one answer

Attorney-client privilege

Technical protection that gives IT-level substance to the confidentiality obligation governing your practice — at the office and on the go.

GDPR

Continuous encryption at storage, including file names. GDPR waives the requirement to notify affected individuals when the exposed data is unintelligible to an unauthorized third party — which is exactly what encryption you alone hold the keys to guarantees.

Your clients' requirements

More and more of your corporate clients are subject to NIS2 and are passing their security requirements on to their counsel. QRlocker lets you meet them without launching an IT project.

Continuity

Two backups, because one isn't enough

Real-time backup

Continuous sync with the primary vault. An always up-to-date copy, at the storage location you define.

Long-term backup, in one click

An independent, timestamped copy, created with a simple right-click on your vault. Protects against accidental deletion and file corruption.

Why two? A real-time backup alone isn't enough: if a file is deleted or corrupted, syncing replicates the error instantly. QRlocker's layered approach ensures both continuity and recovery integrity.

Who it's for

Built for every type of firm

International firms & large practices

Security tools already in place, but encryption keys held by the vendor. QRlocker gives the firm exclusive control of its files back.

Solo practitioners & small firms

The same confidentiality obligations as a large firm, without the IT department to handle them.

Litigation teams

Sensitive files constantly moving between the office, home, and the courthouse.

Prosecutors & judges

Cases requiring the highest level of confidentiality.

There are several of you at the firm

QRlocker Enterprise Edition

The same protection for every lawyer, with firm-wide governance via QRadmin — without changing how your teams work.

Firm-wide policies

The firm sets a central storage location for all vaults, password and key renewal frequencies, and the encryption algorithm — automatically applied to every install. Files stop scattering across removable media.

Account lifecycle control

Suspend, reactivate, or securely regain control of any account in real time — departures, incidents, or audits — while vault data stays intact.

Vault sharing, including with your clients

Private vaults between colleagues, vaults shared by practice group or by case, and secure sharing with your clients — replacing email for exchanging sensitive documents.

Enterprise Edition included at the same rate of $30 per user per month.

No extra cost for QRadmin, centralized policies, or vault sharing.

Technical transparency

QRlocker isn't a black box

We didn't invent any of the standards we use. They're published, defined, and independently verifiable — including the post-quantum standard adopted by the U.S. government, combined with military-grade AES-256 encryption.

For your CISO or IT provider — list of standards
FIPS 203 / ML-KEMPost-quantum encryption (lattice-based key encapsulation)
FIPS 197 / AES-256Advanced Encryption Standard
FIPS PUB 202 / SHA3-512Hash function
FIPS PUB 198-1 / HMACMessage authentication
NIST SP 800-57Cryptographic key lifecycle management
NIST SP 800-90 (A, B & C)Random number generation
NIST SP 800-207Zero Trust architecture

Frequently asked questions

What lawyers ask us

Do I have to change how I work?

No. A QRlocker vault works just like an ordinary folder on your computer. You open, edit, and save your files with the software you already use. Encryption and re-encryption happen without any action on your part.

Does QRlocker slow down opening my files?

No. Encryption and decryption run at 300 Mbps, well beyond the read speed needed for the documents a firm handles: a several-hundred-page brief opens in a fraction of a second. On large files — recordings, expert reports, scanned exhibits from a litigation file — opening time remains comparable to an unencrypted file. This throughput is measured on everyday office hardware, not a test machine: a computer with a six-year-old Intel i5 processor handles it without issue.

What does CyferAll see of my files?

Nothing. This isn't a contractual commitment, it's a consequence of the architecture: encryption keys are generated and kept on your device, and are never sent to us. We have no technical way to read your files, or even their names.

What devices does QRlocker run on?

QRlocker currently installs on Windows, macOS, and Linux — so you can equip an entire firm regardless of its IT setup. Android and tablet versions are on our development roadmap.

Can I keep using the firm's cloud?

Yes, and that's exactly the point. QRlocker layers on top of your existing storage — cloud, server, NAS, local drive, USB stick — without changing how it works. Your files are simply dropped in encrypted.

Do my colleagues or clients need to install anything?

To view a shared vault, yes: QRlocker must be installed on their device, since that's where decryption happens. Installation takes two clicks. We help you with this during onboarding.

What happens if I lose my password?

You reset it yourself. Our multi-factor authentication system sends you a code by email and a second code by SMS: both are required to set a new password. Two separate channels, so neither one alone is enough in the event of a compromise. CyferAll never gets involved in this process and has no visibility into your passwords.

How long does it take to get up and running?

An individual install takes a few minutes. For a firm, plan on half a day of guided setup to define security policies, import users, and create the first shared vaults.

Work is mobile. Data travels. Risk follows.

QRlocker guarantees that wherever your files go, they stay encrypted, under your exclusive control, and recoverable. Simple. Smart. Innovative.

$30 per person / month Install in 2 clicks No VPN Zero IT involvement
Alain Fernando-Santanaalain@cyferall.com

LET US HELP YOU SECURE YOUR STORED DATA WITH QRLOCKER