Industries · Legal
Software and security for firms that hold privilege.
We build and secure the systems law firms run on. GRM LAW, a Brisbane firm, already runs day-to-day on a portal we built.
A law firm’s systems hold the one thing it cannot lose: client confidence, backed by legal professional privilege. Matter files, trust records, and client identities now live in cloud practice systems the firm licenses rather than controls, and the obligations around them keep tightening. AML/CTF tranche 2 captures legal practitioners providing designated services from July 2026.
GRM LAW, a Brisbane firm, runs on a secure operations and compliance portal we built and still ship to weekly: intake, conflicts, matter register, AML/CTF readiness, and the audit trail underneath. Its end-of-month close draws the bank leg of the trust reconciliation through the Xero integration services we build on the Accounting API, so the statement figure arrives by API with no retyping step.
What you carry, and what we do about it.
Matter data lives in cloud practice systems and portals: privileged material, one credential away.
We penetration-test practice systems, portals, and the networks around them, then hand back a ranked fix list, with a re-test to confirm the fixes.
Penetration testingAML/CTF tranche 2 captures legal practitioners providing designated services: programs, customer due diligence, records.
We run compliance readiness programs that map the obligation to your practice, close the gaps, and build the evidence trail an assessor expects.
Compliance readinessTrust accounting records have to be complete, attributable, and producible when the examiner asks.
The portals we build carry append-only audit ledgers, machine-enforced on every state change: the same discipline behind the portal we built for GRM LAW.
Secure-by-design buildsClient confidentiality is the product, and identity is where it leaks: the compromised inbox, the over-privileged account.
We review and harden the Microsoft 365 tenant your firm signs in to (conditional access and MFA coverage, privileged-role and app-consent audit).
Entra ID & Microsoft 365 identity security
The obligations in play
- Legal professional privilege
- Confidentiality duties under the profession’s conduct rules mean a systems compromise is a privilege problem as well as a security one.
- AML/CTF Act, tranche 2
- Legal practitioners providing designated services are reporting entities from 1 July 2026: programs, customer due diligence, and records.
- Trust account rules
- State legal-profession legislation sets record-keeping and external-examination obligations over trust money.
- Privacy Act 1988
- The Australian Privacy Principles govern client personal information, with the Notifiable Data Breaches scheme behind them.
Not legal advice; your advisers own the interpretation.
Built and running
GRM LAW
A Brisbane law firm runs day-to-day on the secure operations and compliance portal we built: intake, conflicts checks, matter register, and AML/CTF readiness, with role-based access, a hardened content-security policy, and an append-only audit ledger enforced on every state change.
See the workThe services behind this work.
Offensive testing
We test applications, APIs, networks and cloud environments for vulnerabilities that can be reproduced and exploited.
Read more
Compliance readiness
Black Shard works with organisations preparing for the Essential Eight, SMB1001 and ISO 27001, as well as businesses reviewing their obligations under the Australian Privacy Principles.
Read more
Software engineering
We design, build and operate applications, internal systems and cloud infrastructure for Australian businesses.
Read more
Practice systems tested, audit trails in place.
Brisbane head office. Work delivered across Australia.

