Skip to main content

Browser isolation for law firms

Shield moves page execution off-device. See how that fits law-firm work. Review remaining risks, provider access, and retention.

Estimated reading time: 8 min read
Red and black curved forms around the Legba stitched-doll mark

Law firm work often crosses a browser. Research, court portals, client systems, and outside links converge there. The browser deserves a defined security boundary.

Quick answer: Shield runs the page in an off-device browser. Page code runs there. Shield does not decide privilege, confidentiality, or ethics compliance.

This guide provides general security information. It is not legal advice. Check your jurisdiction's rules, client instructions, contracts, and applicable law.

Why the browser boundary matters

The browser joins outside content with firm systems. Links can lead to research or filing portals. They can also carry social-engineering attempts. Each workflow exposes different code, credentials, files, and client information.

On May 23, 2025, the FBI described Silent Ransom Group. The FBI observed consistent U.S. law-firm targeting. It began in spring 2023. The group used callback phishing and remote-access software. It also used phone calls and in-person device access. Shield only changes a supplied page's execution boundary. It does not stop the full campaign.

CISA describes off-device web processing. It calls browser isolation a logical barrier. Files, policy, identity, and endpoints still need separate controls.

Ethics starts with context

ABA Model Rule 1.6, paragraph c requires reasonable efforts. Those efforts address unauthorized access. They also address inadvertent or unauthorized disclosure. Comment 18 makes the analysis contextual. It considers sensitivity and disclosure likelihood. It also considers cost and implementation difficulty. Effects on representation matter too.

Rule 1.1 Comment 8 also addresses technology competence. Lawyers should understand relevant technology's benefits and risks. The ABA Model Rules remain models. Each jurisdiction controls its adopted rules.

No browser product can preserve privilege by itself. Confidentiality, privilege, and work product are related. They are not interchangeable. Facts and governing law decide the result.

What Shield changes

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device. Shield is the relevant mode here. It changes the page-execution boundary.

QuestionWhat Shield changesWhat remains
Where does page code run?In an isolated browser off your deviceThe endpoint still needs its own controls
Does the page become trustworthy?Nothing about the site's identityVerify the destination before acting
Can a page receive entered credentials?Nothing about deliberate inputYes. Entered data reaches the page
What about uploads and downloads?The page runs off-deviceTransferred files cross the isolation boundary
Does close erase every record?The active isolated session endsSites and providers may retain separate records
Does this establish compliance?NoThe firm applies its facts and governing rules

The technical boundary guide explains these limits. Credential entry remains credential entry. Copied data crosses the boundary. So do files explicitly saved to your device. Sensitive workflows require separate retention verification.

Where a firm may test it

Unfamiliar links

Start with a non-client link. Shield keeps that page's code away from the daily browser. Staff should still verify the destination. They should not enter credentials into an unverified page.

Outside portals

Court, client, and discovery portals need workflow testing. Confirm sign-in, MFA, uploads, downloads, clipboard behavior, accessibility, and support. Do not assume compatibility from a successful page load.

Research without a returning profile

A fresh session separates research from daily browser state. It does not make research invisible. Websites and search providers may retain records. Networks may retain connection records. The isolation provider may retain operational records.

Off-device execution adds vendor questions

Moving page execution off the endpoint changes one risk. It also places an outside provider in the data path. That tradeoff deserves the same diligence as other legal technology.

California, New York, and North Carolina opinions use fact-specific review. Together, they cover security and provider access. They also cover availability, retrievability, client instructions, and technology changes. None prescribes browser isolation.

  • Map every credential, upload, download, and clipboard path.
  • Verify session storage, logs, retention, and deletion.
  • Ask who can access sessions for support.
  • Review hosting locations, subprocessors, and incident terms.
  • Confirm failure, recovery, and account-removal behavior.
  • Reassess the provider after material changes.

Use Comment 18 as the test

  1. Classify the information. Identify the matter and sensitivity.
  2. Describe the threat. Separate link risk from credential and endpoint risk.
  3. Measure the control. Test what runs, transfers, persists, and fails.
  4. Count the tradeoffs. Include cost, friction, availability, and client impact.
  5. Check outside duties. Review client terms, court rules, contracts, and local law.
  6. Record the decision. State approved uses, prohibited data, owners, and review dates.

A low-data link check may pass quickly. A privileged portal workflow deserves deeper review. The same product can produce different answers under different facts.

Run a controlled pilot

  1. Choose a non-client page and dummy account.
  2. Use a managed computer running desktop Chrome.
  3. Verify the destination before entering anything.
  4. Test MFA, files, clipboard, and session closure.
  5. Inspect endpoint records and documented provider retention.
  6. Write the approved and prohibited workflows.
  7. Repeat testing after material product changes.

Browser isolation belongs inside layered security. Keep identity and endpoint controls. Keep email defenses, backups, training, and incident response. A VPN changes the route. Shield changes where the page runs. Neither replaces the other controls.

Sources checked

Sources and product claims were last verified September 3, 2026.

Read the product boundary, accounting guide, and current exposure guidance.

Free for 30 days. No card required.

Test one browser boundary.

Start with a non-client page. Verify credentials, transfers, retention, and firm policy before sensitive work.

See how Shield works

About the authors.

Try it on the next page you do not trust

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.

Free for 30 days. No card required.

Ghost. A private route for your browser. Shield. An isolated browser, off your device. Choose the mode. Close when finished.