How Comsend Works
Security, privilege, and retention — explained for the people who rely on them.
Consumers vs Lawyers
Consumer Security
A consumer wants nobody to read their messages. End-to-end encryption. Disappearing messages. No records. The ideal consumer app leaves no trace behind.
Legal Security
A lawyer needs exactly the right people to read the message — and a provable record that it happened. The content must remain confidential. But the communication itself must survive as evidence.
Consumer apps treat retention as a bug. Legal practice treats it as a regulatory requirement. Under the Legal Profession Act, trust records must be kept for seven years. Client files must be retained through the matter lifecycle and beyond. A disappearing message is not a feature — it is a liability.
Comsend bridges this gap. Messages are encrypted in transit — no third party can read them. But they are also ingested into the vault at the point of receipt, with the same chain of custody as any other evidence. The lawyer decides what is privileged. The system ensures nothing is lost.
The principle: Consumer apps protect the message from everyone. Comsend protects the message from everyone except the people who need it — the lawyer, the client, and the court — while maintaining a verifiable record.
Anonymous vs Retained
An anonymous messaging app lets anyone talk to anyone with no record. That is useful for whistleblowers. It is dangerous for legal practice.
When a client sends you instructions on an anonymous platform, you cannot prove who sent it, when, or that it has not been altered. A court cannot rely on a screenshot of a WhatsApp message. The Evidence Act requires a foundation — and an anonymous app provides none.
Comsend does not offer anonymous communication. Every message is tied to a verified identity. Every message is timestamped by the server, hashed on receipt, and stored with a complete audit trail. The content remains encrypted and privileged. The metadata — who, when, to whom — is preserved as a business record.
Privilege protection: Legal professional privilege protects communications made for the dominant purpose of legal advice or litigation. Comsend marks privileged messages at the infrastructure level. They cannot be disclosed through the disclosure gateway because there is no architectural path for them to leave the privileged subsystem.
How Secure It Is
In transit
- SIP calls use TLS 1.3 between the app and your phone system. The audio is encrypted from handset to PBX.
- Signal messages are end-to-end encrypted by the Signal Protocol. Comsend captures the message after it is decrypted on your device and transmits it to your vault over TLS.
- Push notifications travel over TLS to your own push server. The wake payload contains only a token — never message content.
At rest
All data in the vault — messages, call logs, recordings, transcripts — is stored on encrypted storage. Backups are encrypted. Archives are encrypted. Nothing sits in plaintext on disk.
Architectural isolation
The Comsend edge server, the phone system, the vault, and the mail server run in separate, isolated containers on separate network segments. A compromise of one cannot reach another. The edge server is a relay — it does not store messages, and an attacker who compromises it has intercepted nothing.
Legal Professional Privilege
Privilege is a substantive right — not a policy preference. A privileged document cannot be compelled in evidence. But privilege is fragile. It can be lost through disclosure to a third party, inadequate marking, or mixed-purpose communication.
Comsend protects privilege at the architectural level:
- Auto-tagging: Every message ingested from a lawyer account is automatically tagged as potentially privileged at the moment of capture.
- Disclosure gateway: The vault will not release a privileged document unless a lawyer explicitly reclassifies it. There is no "select all and send" that accidentally includes privileged material.
- Subsystem isolation: Privileged documents live in a separate storage namespace. A disclosure request against the general register cannot sweep them up.
- Audit trail: Every access to a privileged document is logged — who, when, and why. The audit proves the document was treated as privileged from creation.
The lawyer's call: The system can tag, isolate, and protect. But the lawyer must apply the dominant-purpose test. A settlement offer is privileged. An invoice request is not. The scaffolding is provided — the judgement is yours.
Lawyer Identification
Before Comsend provisions an account, it verifies the practitioner against the Queensland Law Society public register — a source of truth that cannot be faked.
- The practitioner's email is matched against the known-lawyer roll, a regularly synced copy of the QLS register enriched with QBA barrister data.
- A one-time sign-in link is sent only to the email address on file — never to a typed address.
- Once verified, the identity is bound to the device — email, QLS record, and device key form the trust anchor.
Identification is continuous. If a certificate is suspended, access is restricted at the next QLS sync. If a lawyer changes firms, access to the previous firm's matters is revoked. If a session originates from an unrecognised device, the system demands a second factor.
Clients are identified through induction: photo ID captured, verified, and recorded. Their phone number is linked to their client record. When a Signal message arrives from that number, it is filed automatically — because the system already knows who they are.
SIP Calling & Receiving
Comsend is a SIP client for the phone system you already own — not a separate phone service.
- Outbound: You dial from Comsend. The app sends the call over TLS to your phone system, which routes it to the PSTN. The recipient sees your caller ID — your firm number, your name.
- Inbound: A client calls your number. The phone system routes it to your extension. Comsend rings — even if closed — through a secure wake signal on your own infrastructure.
- Internal: Call Deborah's extension. Transfer a client to Trent. Conference with counsel. All through your phone system.
Calls are recorded automatically — client-aware, with no consent announcements required for Queensland calls. Calls are treated as Queensland-based regardless of the number — no recording announcements are played. When you certify a recording or transcript for court, nominate the jurisdiction and Comsend uses the right evidence-certificate template for it, so the evidence is legally admissible where it matters. The recording is stored on your phone system, ingested into the vault, and transcribed by private AI. The audio is the original record; the transcript is the searchable index — $10 per transcript on request, or free with legal practice management integration or the storage add-on.
Signal & Retention
Signal provides encryption. Comsend adds retention, filing, and evidentiary integrity — without breaking the encryption. The bridge runs in three directions:
Live sync
- A client sends a photo on Signal. It is encrypted end-to-end. Your phone decrypts it. Comsend captures the decrypted photo, hashes it, signs the hash with your device key, and stores it in the vault — with the same chain of custody as any other evidence.
- The message metadata — sender, recipient, timestamp, body, attachments — is written to the vault and filed to the client matter by phone number match.
History import — from before Comsend was installed
- Signal Desktop stores complete message history in an encrypted database. The Comsend import tool decrypts this database and ingests every message, photo and document — capturing history from before Comsend was installed.
- Imported history is staged and deduplicated, then matched to clients by phone number — so the old Signal conversations join the same matter file as everything else.
Backup — the point of it all
Without Comsend, Signal messages exist only on two phones. If either is lost, wiped, or upgraded, those messages are gone. With Comsend, every message is backed up into the vault at the point of receipt — filed, retained, and auditable — so a client's Signal instructions survive device loss exactly the way email does.
Encryption is not weakened: messages remain end-to-end encrypted between you and the other party. Comsend captures the message on your device after Signal has decrypted it for you — it never sits in the middle of the Signal conversation. Full detail: Services & Capabilities →
Infrastructure
Every component runs on hardware you control, in Australia:
- Phone system: Handles SIP registration, call routing, voicemail, and recording. Connected to the PSTN through an Australian provider — the provider carries the call but cannot hear it.
- Edge server: Handles authentication and push routing. Does not store messages or calls. A relay, not a store.
- Push server: Delivers wake signals to devices on your network. No Google. No Apple.
- Vault: Where all records live. Messages, calls, recordings, and transcripts are ingested here and enter the retention lifecycle.
- Signal integration: Linked to each practitioner's Signal account. Receives messages in real time and files them to the vault.
Network access: Comsend requires WireGuard to connect to your practice network. Without the VPN, emergency calling still works — but message ingestion, push, and vault access require the secure tunnel. Privileged communications should never traverse the open internet.
Independent security verification: what can be checked, how encryption works →