DEMO EXPERIENCE — Fictional law firm. Use fictional accident details. Not legal advice or a request for representation.

Demo guide

Everything you need to understand this interactive demo and its safety boundaries.

What this is

The 5-Minute Firm is a fictional personal-injury law firm built to demonstrate an intake-to-consultation flow. It is not a real law firm, does not provide legal advice, and forms no attorney-client relationship. Use only fictional accident details.

Three server-controlled modes

  • Simulated

    Default. Sends nothing. Uses labelled sample appointments and mock data. All adapters run here today.

  • Connected demo

    Would use the real demo location and approved test recipients. Enabled only by a server-side allowlist — never a public URL parameter. Currently unavailable (no integration connected).

  • Unavailable

    The integration was dismissed or not configured. The adapter falls back to Simulated and reports this clearly.

Safety boundaries

  • No public URL parameter can enable live sending.
  • Private case data is never in SSR output without authorization.
  • Staff auth uses hashed passwords + secure HttpOnly cookie sessions — never a hardcoded password accepted in the browser.
  • Visitor sessions are scoped: two sessions cannot read each other's inquiries.
  • Resume links are hashed, expiring, single-use, and scoped to one inquiry — no email/phone/policy number in the URL.
  • Cookie-authenticated writes are protected against CSRF (double-submit token).
  • Public endpoints are rate-limited; email/SMS sending is never unrestricted.
  • Events carry correlation IDs and outcomes — no credentials or full sensitive payloads are logged.
  • The demo and protected routes use noindex.
  • Analytics never capture form field values.
  • No provider success is claimed without a confirmed result.

Persistence

No durable database is connected in this environment. Records live in a simulated in-memory store that does not survive server restarts. The full schema (tables, indexes, foreign keys) for DemoSession, Inquiry, Intake, Attachment, Appointment, ConsentRecord, DeliveryEvent, ActivityEvent, BriefVersion and IntegrationJob is defined in schema.server.ts and would be run by a durable provider when one is connected. Process memory is never treated as a connected backend.

Adapters

CRM

Intake capture

Calendar

Scheduling

Messaging

Confirmations

Storage

Case records (simulated in-memory)

Summaries

Templated case brief

Try the flow

  1. Start at /start.
  2. Complete the intake form.
  3. Pick a consultation slot.
  4. See your confirmation.
  5. Log in as a demo attorney at /attorney/login (user: attorney, pass: demo5min).
  6. Review inquiries on the attorney dashboard.