Built so your clients' business stays your business.
PageMax handles enquiries from people at some of the hardest moments of their lives, on behalf of firms bound by confidentiality. The platform is engineered around that fact: encrypted everywhere, resident in the EU, each firm's data sealed off from every other firm's, nothing published until a named person at your firm approves it, and every action on a record that cannot be quietly rewritten.
The commitments.
-
Encrypted everywhere
Your firm's data is encrypted in transit and at rest.
-
Resident in the EU
Compute and database run in Frankfurt, on EU infrastructure. Public sites are served by an EU-headquartered edge network.
-
One firm, one boundary
Each firm's data is isolated at the database layer, enforced by policy, and never used for another firm.
-
Never training data
Your information is used to do your firm's work: writing your pages, handling your enquiries. It is never used to train AI models, so nothing you share becomes part of a model.
-
Two factors, every account
Every sign-in requires a second factor from an authenticator app, so a stolen password alone gets nobody in. Each person has their own login, and what they see follows their role.
-
Read-only support
When PageMax support views a firm's dashboard, the view is read-only, and both entry and exit are logged.
-
A tamper-evident record
Every action on the platform is written to a tamper-evident audit ledger, and history stays history.
-
Hard AI spend ceilings
Every AI action carries a hard cost cap per call, a daily run cap and an emergency stop, and each firm has a monthly ceiling the platform will not cross.
Nothing publishes without a named person at your firm
Every change, whether the system proposed it or someone at your firm asked for it, is staged as a draft first. A question is answered on the spot; anything that would alter your website becomes a proposed change that shows exactly what it will do before it does anything. If a request is unclear, the system asks before it acts. It never guesses.
That draft then waits for a named solicitor at your firm. The approval is recorded with the name and the time, and the gate cannot be skipped: not by PageMax, and not by a firm admin in a hurry.
Who can see an enquiry
An enquiry assigned to a solicitor is visible only to that solicitor. Everyone else at the firm sees what their role needs and nothing more.
An injury enquiry is health data, and the platform treats it that way by construction. The reporting engine that answers questions about your numbers works on counts and outcomes; it is technically blocked from reading names, emails or phone numbers. And sensitive enquiry data does not sit around: it is redacted and aged out on a schedule, so the firm stays on the right side of GDPR without anyone minding a calendar.
A record that cannot be quietly rewritten
Each entry on the ledger is chained to the one before it, so altering an old row breaks the chain after it. Every request is logged end to end: who asked, what was done, when, and the before and after.
When a change goes live, the dashboard tells you and links straight to the live page, and the month's activity is laid out in a plain-English work log where every line is a real, recorded action. That accountability includes us: nothing PageMax does on your dashboard happens off the record.
GDPR treated as a hard gate
Enquiry data sent to your firm belongs to your firm. PageMax processes it on the firm's instructions, and a data-processing agreement is part of onboarding, not an extra to ask for.
The same plain-dealing runs through the product itself. When the system learns from what prospective clients keep asking, it works from de-identified question themes and never the raw enquiry, and where the platform generates an image with AI, the image is labelled as such.
Leaving is designed too
If your firm leaves, you take a full export of your content and your data, and then we delete it. Your firm always owns its own domain, so the address your clients know goes wherever you go.
No certificates on the wall. The controls themselves.
PageMax is an early-stage Irish company and holds no ISO or SOC certification today. Rather than borrow reassurance, we publish how the system is governed, control by control, and let you read it. Everything on this page describes controls that are running now, not a roadmap.
Questions firms ask.
How is my data protected?
It is encrypted in transit and at rest, and it stays in the EU: compute and database in Frankfurt, public sites served by an EU-headquartered edge network. Your firm's data is isolated at the database layer and never used for another firm, and every action taken on the platform lands on a tamper-evident record.
Who can see my firm's data?
Your own people, by role: each person has their own two-factor login and sees what their role needs, and an enquiry assigned to a solicitor is visible only to that solicitor. On our side, support access is read-only and both entry and exit are logged. The reporting engine is technically blocked from reading names, emails or phone numbers.
Is my data used to train AI?
No. We use your information to do your firm's work, and only your firm's. It is never used to train AI models, and your data is never used to produce another firm's content.
What happens when we leave?
You take a full export of your firm's content and data, and then we delete it. Your firm always owns its domain.
Serious about how this is run? So are we. Ask us anything on this page and we will answer it plainly.
Get access