Herarx is in early access — free tier, always. Paid plans coming for power users. See pricing →

Everything included

Every tool you need.
Nothing you don't.

A focused platform for people who handle sensitive, structured work. No feature bloat, no add-ons — everything below is included on the free tier.

Core platform

Built around how you actually work

Case management

Create structured case records with titles, descriptions, status, priority, and tags. Assign team members with specific roles and keep everything organized in one controlled workspace.

Status tracking Tags & categories Team assignment Case templates

File management

Upload, annotate, and organize documents within each case. Per-file access controls let you decide who can see what. Every file access is logged with who and when.

File upload Per-file permissions Access logging Annotations

Contact management

Store structured contact information and link contacts to one or more cases. Keep relationships visible across all your matters so nothing falls through the cracks.

Linked to cases Structured fields Cross-case visibility

Internal messaging

Secure messaging between team members — completely separate from email, logged as part of the case record, and kept inside your workspace where it belongs.

Case-linked messages Full message log Team only

Notifications & reminders

Stay on top of case activity with notifications for new actions, file uploads, and team updates. Set reminders for important deadlines so nothing slips.

Activity alerts Custom reminders Notification preferences

Search

Find cases, files, contacts, and activity across your entire workspace instantly. Powerful full-text search that respects your access permissions.

Full-text search Cross-entity Permission-aware

Security first

Security controls you can actually see

Every security feature is visible, configurable, and documented — not hidden away in a settings menu you'll never find.

Two-factor authentication

TOTP-based 2FA compatible with Google Authenticator, Authy, and similar apps. Full hardware security key support via WebAuthn/FIDO2. Both methods available on every account.

TOTP WebAuthn / FIDO2 Hardware keys

Full audit trail

Every login attempt, file access, case action, role change, and permission update is logged with a timestamp, user identity, and context. Immutable, reviewable, always on.

Immutable log Timestamped Action context

Role-based access (RBAC)

Granular permissions at the case level. Assign specific roles to team members — read-only, editor, manager — with inheritance and override support per case.

Per-case roles Granular permissions Role inheritance

CSRF & session protection

All forms carry CSRF tokens. Sessions expire automatically on inactivity. Password reset flows are time-limited and single-use.

CSRF tokens Auto session timeout Secure reset flows

Password security

Passwords are stored using bcrypt hashing — never in plain text, never reversible. Password strength requirements enforced on all accounts.

bcrypt hashing Strength enforcement Never plain text

Transport encryption

All connections to Herarx are encrypted in transit using TLS. No data travels unencrypted between your browser and our servers.

TLS / HTTPS In-transit encryption

Files encrypted at rest

Uploaded files are encrypted at rest and stored on a dedicated file server in a different geographic location from both the database and web server. Even if one layer is compromised, your files remain isolated.

Encrypted at rest Geographically isolated Separate from DB

Collaboration

Work together, stay in control

Every collaboration feature in Herarx is designed so you never lose visibility over what your team is doing.

Team workspaces

Invite colleagues to your organisation and assign them to cases with the right roles. Keep private cases private and shared cases visible to the right people.

Secure case sharing

Share specific cases or files with external parties via secure, time-limited links — with controls over what they can see and do.

Tasks & checklists

Create tasks within cases, assign them to team members, and track completion. Keep everyone aligned on what needs to happen next.

Honest limitations

What we don't yet have

We'd rather be upfront about gaps than oversell. These are real limitations we're actively working on.

SSO / SAML integration Single sign-on with your company's identity provider isn't available yet. It's on the roadmap for larger teams.
Independent security audit We haven't yet completed a formal third-party security audit. We apply security best practices but can't yet point to external certification.