"It Has SSL" Is Not the Same as "It's Confidential"
Most law firm websites have SSL — the padlock icon, HTTPS in the address bar — and it's easy to treat that as the whole answer to whether an intake form is secure. SSL matters: it encrypts the connection between a visitor's browser and the server, so the submission can't be intercepted in transit. But it says nothing about what happens after that submission arrives — where it's stored, for how long, who inside or outside the firm can access it, or whether the server it lands on is shared with unrelated websites. A prospective client filling out an intake form with details about a legal matter is trusting more than the transit encryption; they're trusting the whole chain behind it.
What a Prospective Client Is Actually Trusting You With
A law firm intake form often collects exactly the kind of information a client would expect a firm to protect the same way it protects anything else confidential — names, contact details, and a description of the legal matter itself, sometimes before any attorney-client relationship has formally begun. That's a meaningful trust placed in a piece of website infrastructure that, on a lot of sites, gets the same generic contact-form plugin as a restaurant's reservation request. This is general information, not legal advice — what specifically needs to be protected, and how, depends on a firm's practice area and its own professional obligations, which is a conversation for the firm and its counsel.
The Questions Worth Asking Your Current Setup
Rather than assuming an intake form is handled appropriately, it's worth getting specific answers: Is the submission encrypted in transit? Where does the data go once submitted — a database on shared hosting, an email inbox, a third-party form service? Who has access to it, and for how long is it retained? Is the hosting environment isolated, or shared with other, unrelated websites that could be a lower-security entry point into the same server? A firm that can't answer these with certainty has an intake form running on assumptions rather than a reviewed setup.
Downtime Is a Cost, Compromise Is an Incident
These two risks are different in kind. If an intake form goes down, a prospective client simply can't reach the firm through that channel — a business cost and a reputational one, but a recoverable one. If an intake form or the data behind it is actually compromised, that's a security incident that calls for immediate investigation, an assessment of what was exposed, and a decision about notification obligations — not something a firm wants to be figuring out reactively, under pressure, for the first time.
What a Reasonable Setup Looks Like
- SSL and CDN-level protection as the baseline, not the whole answer.
- Hardened, monitored hosting rather than shared, unmanaged hosting where the firm's site is one of many unrelated tenants on the same server.
- A clear answer on data handling — where form submissions go, who can access them, and how long they're retained — that the firm has actually reviewed, not assumed.
- Continuous uptime and security monitoring, so an issue is caught quickly rather than discovered when a client reports it.
Why This Gets Assumed Rather Than Checked
Most firms didn't build their own website, and the person who set up the contact form years ago is often long gone from the conversation by the time anyone asks how it actually works. "It has SSL, it should be fine" becomes the working assumption by default, not because anyone concluded it after review — simply because no one raised the question. Given what an intake form collects, it's a question worth raising deliberately rather than by default.
How CriticalWP Approaches This
CriticalWP's managed hosting for law firms includes SSL and Cloudflare Enterprise CDN protection on every plan, hardened and monitored infrastructure rather than shared hosting, and continuous uptime monitoring with prioritized response given the operational and reputational impact of downtime for a firm site. For firms with specific confidentiality or data-handling requirements, we review those directly — this is general information, not legal advice, and the specifics of what your firm needs are worth a direct conversation.