Read-only access. We cannot move money, ever.

We connect to your trust account through a read-only bank connection. IOLTAWatch can retrieve your transaction history and current balance. It cannot initiate a transfer, create a payee, change account settings, or move a single dollar. This is a technical constraint, not just a policy: our read-only connection does not expose any payment endpoints.

Your IOLTA account login credentials are never stored on IOLTAWatch servers. When you connect your bank, you authenticate directly with your bank through a secure, read-only connection flow. We receive only an encrypted access token, which we store encrypted. You can revoke access at any time from your bank's connected apps settings, and IOLTAWatch immediately loses access to your account.

Encrypted in transit and at rest.

All data transmitted between your browser and IOLTAWatch is encrypted using TLS 1.2 or higher. We do not support older, insecure protocol versions.

All data stored in our database, including transaction records, client matter balances, and reconciliation reports, is encrypted at rest using AES-256, the same standard used by financial institutions and government agencies.

Bank connection tokens are encrypted at the application layer before storage, in addition to our database's disk-level AES-256 encryption. Tokens are never exposed to your browser or to any third party.

The services we rely on to deliver the product.

IOLTAWatch relies on established, industry-standard providers to operate the Service: a read-only bank connection for balance and transaction retrieval, encrypted database hosting for your account and reconciliation data, and a payment processor for subscription billing.

Card payments are handled entirely by a PCI-DSS-compliant payment processor. Card numbers and other payment details never touch IOLTAWatch's own servers.

Your records are yours. Full stop.

Florida Bar Rule 5-1.2 requires you to retain trust account records for five years. IOLTAWatch stores and archives every reconciliation PDF we generate on your behalf for the duration of your subscription, and retains those records indefinitely after cancellation so you keep your compliance history.

You can export your complete archive at any time, all reconciliation PDFs, transaction records, and matter balances, in a single download. No support ticket required.

To request permanent deletion of your data, contact privacy@ioltawatch.com. Deletion requests are fulfilled within 30 days, subject to any legal retention obligations.

Your firm's data is isolated from every other customer's.

Client names, matter IDs, and account balances are isolated to your firm: every request is authenticated and scoped to your firm's account, so other customers cannot access your data. Our bank connections are read-only, so IOLTAWatch itself can never move funds on your behalf.

Our small operations team may access customer data as needed to run, support, and debug the Service. That access is never used for any purpose other than operating the Service. If you contact us for support and the issue requires us to inspect your data, we will request your permission first.

Cloud software is Bar-approved, with the right precautions.

Florida Bar Rule 4-1.6 requires attorneys to make reasonable efforts to prevent inadvertent disclosure of client information. The Bar has confirmed that cloud-based software is permissible as long as the attorney exercises reasonable care in selecting and using the service.

IOLTAWatch is designed to satisfy that standard: your data is encrypted, access is restricted to your firm, and it is never shared with third parties for any purpose other than delivering the product. We do not sell, license, or monetize your data in any form.

For guidance on evaluating cloud services under Rule 4-1.6, see the Florida Bar's Rules Regulating the Florida Bar.

If something goes wrong, we tell you within 72 hours.

In the event of a security incident that affects the confidentiality, integrity, or availability of your data, IOLTAWatch will notify you by email within 72 hours of confirming the incident. The notification will include the nature of the incident, the data affected, the steps we have taken to contain it, and any actions we recommend you take.

If you discover a potential security vulnerability, please report it to security@ioltawatch.com. We will acknowledge your report within one business day.

Security questions? We answer them directly.

If you have questions about this page or our practices, contact us. You will reach a person, not a support bot.

Security & compliance inquiries

security@ioltawatch.com

Response time: one business day. For urgent matters related to a Florida Bar audit or subpoena, indicate "URGENT" in the subject line.