Secure Drop
Anonymous · Encrypted · No login required
Your message is sealed and anonymous. We cannot identify you. No account or login is needed.
Your message
Max 3 files, 10 MB each
Secure Channel
Anonymous · Bidirectional · Encrypted
Start an anonymous conversation. You'll receive a thread code to check for replies later.
Your message
Max 3 files, 10 MB each
Thread Code
Enter your thread code above to check for replies.
Law Firms

A secure front door for sensitive client communication.

City of Hats can give a firm a branded route for client intake, documents, consultations, matter updates, and supported secure communication. Technology can strengthen confidentiality, but it does not create legal privilege or replace the firm’s conflicts, records, and professional-responsibility procedures.

Best fitFirms improving confidential client intake and follow-up
Typical accessBranded browser portal with secure Hat workflows
Important boundaryNot a privilege guarantee or practice-management system
What this solution does

Reduce sensitive work in ordinary email

Prospective and current clients often send confidential information through whatever channel is easiest to find. A configured client experience can set expectations early, collect only the needed information, route it to authorized staff, and offer a more appropriate path for documents and conversations.

Structured client intake

Guide prospective clients through appropriate initial information without implying that submission alone creates a lawyer-client relationship.

A defined document route

Offer an approved alternative to uncontrolled attachment chains for supported exchanges.

Confidential communication options

Move appropriate conversations into Hat-based workflows while keeping endpoint and participant risks visible.

Core workflows

Support the client journey without confusing the legal boundary

The firm determines when a person is only a prospective client, when conflicts review occurs, when an engagement begins, and which system holds the official matter record.

Prospective-client intake

Collect configured preliminary information with a clear no-engagement notice and conflicts-review boundary.

Consultation requests

Route scheduling requests while keeping final calendar and engagement status in the approved system.

Document exchange

Provide a dedicated path for supported files, subject to authorization, malware, retention, and matter-record procedures.

Client messaging

Use secure channels for appropriate communication and define when telephone, in-person, or another controlled method is required.

Matter updates

Present configured status or next-step information without replacing legal advice or the authoritative matter file.

Staff handling

Use Operations to route configured requests to intake, legal, investigation, billing, or administrative teams.

How it works

Build confidentiality into the intake path

The design should begin before information is submitted: notices, conflicts, identity, minimum collection, staff access, and the official file all need an owner.

01

Define legal and information stages

Separate public inquiry, prospective-client intake, conflicts review, engagement, active matter communication, and post-matter retention.

02

Configure access and hand-offs

Set notices, staff roles, secure-channel invitations, document rules, integration points, retention, and escalation.

03

Validate professional obligations

Review confidentiality, privilege, supervision, client identity, records, accessibility, jurisdiction, incident response, and staff training before launch.

Security and privacy

Encryption supports confidentiality; it does not define privilege

Privilege and professional duties depend on law, facts, participants, purpose, waiver, firm behavior, and jurisdiction. A secure tool reduces some technical risks but cannot decide those legal questions.

Protected Hat communication

Supported Hat-channel content uses City of Hats encryption controls; endpoints, screenshots, exports, and authorized recipients remain relevant.

Identity is a workflow decision

Pseudonymity can protect a source or initial inquiry, while other matters require verified identity and conflicts checks.

Need-to-know access

The firm must configure and review access for lawyers, staff, contractors, experts, investigators, and administrators.

Official-file boundary

The firm decides what must enter its document or practice-management system and how that transfer is recorded and retained.

Scope clarity

Important boundary

A strong fit when

Your firm wants a clearer confidential intake and client communication layer and can define conflicts, engagement, authorization, official records, and retention.

What it does not replace

It is not a conflicts database, legal-advice system, court-filing service, e-discovery platform, trust-accounting tool, complete DMS, or automatic guarantee of privilege or professional compliance.

Confirm before deployment

Review professional-responsibility rules, privilege notices, client identity, conflicts, records, supervision, retention, legal holds, discovery, exports, incident response, and jurisdiction-specific requirements.

Straight answers

Questions teams ask before a demo

Product scope reviewed: 10 August 2026

Does using City of Hats make a conversation privileged?

No. Privilege depends on law and the facts of the relationship and communication. A secure tool may support confidentiality but cannot create, preserve, or determine privilege by itself.

Does the portal replace our practice-management or document system?

No. The firm’s approved matter, document, conflicts, billing, or records systems may remain authoritative and require a defined integration or hand-off.

Can prospective clients submit information anonymously?

A configured workflow may allow pseudonymous initial contact when appropriate. The firm must decide when identity, conflicts, sanctions, or client-verification procedures become necessary.

Are documents protected from every kind of disclosure?

No. Encryption protects defined transport and storage boundaries, but authorized recipients, compromised endpoints, screenshots, exports, legal process, human error, and later handling remain part of the risk model.

What should the firm review before deployment?

Review intake notices, conflicts, privilege, identity, staff and vendor access, official records, retention and legal holds, export and discovery, incident response, client support, and applicable professional rules.

Review the legal boundary before the client journey.

Bring your intake stages, conflicts process, official systems, jurisdictions, access model, and retention obligations to the solution review.