
Client confidentiality is a professional obligation. Your file storage should reflect that.
Bigby provides solicitors and law firms with encrypted, UK-based cloud storage designed around the confidentiality requirements your practice depends on.
The duty of confidentiality extends to every system that touches client data
Solicitors have one of the oldest and most clearly defined duties of confidentiality in any profession. The SRA Code of Conduct is unambiguous: client information must be kept confidential unless disclosure is required or permitted by law.
That obligation does not pause when a file is uploaded to a cloud service. The platform you choose to store client documents, correspondence, and case files is part of your data processing chain. If it does not meet the standard your clients are owed, the responsibility sits with the firm.

Where standard cloud storage creates professional risk
General-purpose cloud platforms are built for broad consumer and business use. The data handling practices that come with them are not designed with legal professional privilege, SRA obligations, or UK GDPR in mind.
Legal professional privilege
Privileged communications between solicitor and client attract some of the strongest protections in law. Storing those communications on a platform that scans file content, holds broad data usage rights, or processes data outside UK jurisdiction introduces questions about whether that privilege is adequately preserved. It is a question most consumer cloud providers are not equipped to answer.
SRA Code of Conduct
The SRA requires firms to have effective systems and controls to meet their obligations, including around data security. Using a platform with opaque data handling, overseas data storage, or terms that permit content scanning is difficult to reconcile with those requirements. In the event of a complaint or regulatory review, your choice of storage provider may be scrutinised.
UK GDPR and data controller liability
Law firms are data controllers under UK GDPR. Responsibility for how client personal data is stored and processed rests with the firm, not the storage provider. A data breach originating with a third-party service remains the firm’s breach to account for, including any obligation to notify the ICO and affected clients.
Overseas data exposure
The major US cloud providers operate under US law. Legislation such as the CLOUD Act creates a mechanism by which US authorities can compel access to data held by US companies, including data stored in the UK. For family law, criminal defence, immigration, and other sensitive practice areas, that exposure warrants careful consideration.
How Bigby works
Unlike the major cloud platforms, Bigby does not scan, analyse, or profit from the files you store. Here is how that works.
01. Encrypted in transit and at rest
Your files are encrypted on the way to us and while they sit on our UK servers, so they are protected in transit and never stored as readable plain text. We hold the encryption keys, which is what allows features like editing documents in your browser to work.
02. No access to file contents
Bigby does not open, scan, or read the contents of what you store. We have no business reason to and our data processing terms prohibit it.
03. No AI training or secondary use
Your stored content is not used for AI training, advertising targeting, or any analysis of any kind. The subscription fee covers the cost of running the service. That is the entire arrangement.
04. UK data residency throughout
All data is stored on UK-based infrastructure. UK GDPR applies. There is no transfer to US servers and no exposure to US jurisdiction. Your clients’ data does not leave the UK.
Frequently asked questions
Storage that meets the standard your clients are owed
Private, encrypted, UK-based cloud storage from £3.99 per month. Built for practices that cannot afford to treat data security as an afterthought.
See all plansAnnual or monthly billing · All prices in GBP · UK data residency · GDPR compliant