Standing

Security & compliance.

Lexitio is built for legal professionals who handle sensitive, privileged client information. Every architectural and operational decision assumes your data requires the highest level of protection — not because a regulator demands it, but because attorney-client privilege is the foundation of legal practice.

LAST UPDATED · JUNE 15, 2026

SOC 2 Type II infrastructureAES-256TLS 1.3BAA-covered AIRBAC + MFAAppend-only audit logSOC 2 audit in progress
Encryption
AES-256 at rest, TLS 1.3 in transit, HTTPS enforced everywhere.
AI, under BAA
Privileged content and PHI processed only under a Business Associate Agreement — never used to train public AI models.
Data isolation
Row-level isolation keeps each firm's matters and strategy logically segregated from every other customer.
Access controls
Role-based permissions plus MFA restrict who reaches matter, discovery, or financial files.
Edge protection
Enterprise edge defenses and infrastructure monitoring guard availability and access.
Audit + review gate
An append-only log records every action; every AI output is flagged for attorney review before it leaves the app.
Chapter One

How your data is isolated and protected.

Each firm's data is completely separate from every other firm's, enforced at two independent layers — the application and the database itself — and encrypted both in transit and at rest.

Every query filtered by tenant_id, plus PostgreSQL row-level security as a second, independent layer
AES-256 at rest, TLS 1.2+ in transit, bcrypt password hashing with per-user salts
Role-based permissions enforced at the API layer, not just the interface
MFA, rate limiting, and blocklisted logout tokens on every account
Scoped API keys for programmatic access, hashed before storage

No architectural decision here assumes trust — every layer checks for itself.

Exhibit A — Isolation, Encryption & Access
Tenant isolation
✓
Application-level isolation
Every query is filtered by tenant_id, enforced at the ORM layer on every route.
✓
Database-level Row Level Security
PostgreSQL RLS on every tenant-scoped table — a second, independent layer.
Encryption
✓
Encryption in transit
TLS 1.2+ on every connection; unencrypted HTTP is redirected to HTTPS.
✓
Encryption at rest
AES-256 on object storage and the managed PostgreSQL database.
✓
Password hashing
bcrypt with per-user salts. Plaintext passwords are never stored or logged.
Access control
✓
Role-based access control
Admin, attorney, paralegal, staff — enforced at the API layer, not just the UI.
✓
JWT authentication, with logout invalidation
Logged-out tokens are blocklisted and rejected before expiry.
✓
API key support
Per-key permission scopes (sk-lex_ prefix); keys are hashed before storage.
✓
MFA and rate limiting
TOTP-based MFA on every account; login attempts are rate-limited and lock out.
Exhibit B — Operations & Incident Response
Audit logging
✓
Immutable audit log
Matter, document, AI, login, and permission events — logged with user, tenant, timestamp, IP.
✓
Append-only & retained
Cannot be modified or deleted; retained for the life of your account.
✓
Firm-accessible logs
Admins view their own audit log any time from Settings — no support ticket needed.
Infrastructure
✓
Managed cloud hosting
Dedicated US infrastructure — no consumer-grade or shared hosting.
✓
Daily, restore-tested backups
Encrypted pg_dump to offsite storage, 30-day retention, verified by periodic restore tests.
✓
Docker isolation
Isolated per service; the database port is never publicly accessible.
Incident response
✓
Detection
24/7 log monitoring and alerting; anomalous access patterns trigger automated alerts.
✓
Containment
Confirmed-breach access is isolated within 1 hour; row-level security limits the blast radius.
✓
Notification
Affected firms notified within 72 hours, consistent with GDPR and applicable US state law.
✓
Post-incident review
Every incident gets a post-mortem: root cause, timeline, remediation steps.
Chapter Two

How we operate, and how we respond.

Every sensitive action is recorded to a permanent, tamper-evident trail. Hosting is dedicated US infrastructure with daily, restore-tested backups. If something goes wrong, containment and notification are documented, not improvised.

Append-only audit log — every action, retained for the life of your account
Dedicated US hosting, Docker-isolated, database never publicly exposed
Daily encrypted backups, restore-tested on a schedule, offsite
24/7 detection and alerting on anomalous access
Affected firms notified within 72 hours of a confirmed breach

Vulnerability disclosure. If you believe you've found a security vulnerability in Lexitio, report it to security@lexitio.com. We acknowledge reports within 2 business days, provide regular status updates, and work with researchers on responsible disclosure — we do not pursue legal action against anyone who follows it.

AI processing & data use

Your data is never used to train a model.

Your matter data, client information, uploaded documents, and query content are never used to train any AI model — including any third-party provider we use.

Provider terms
AI queries are processed via Anthropic's API under a zero-data-retention agreement — Anthropic is contractually barred from using that input or output to train models.
No persistent memory
AI conversations are stateless. No chat history is retained on third-party AI infrastructure between sessions.
Prompt isolation
Each AI request is scoped to the current matter's data only — it cannot reach data from other matters or other firms.
SOC 2 Compliance Roadmap
IN PROGRESSSOC 2 Type I — target Q3 2026

Our controls are built to the SOC 2 Trust Service Criteria from day one. Type I certification is targeted for Q3 2026, with Type II to follow after the required 6-month observation period. Enterprise firms needing a report or security questionnaire before contracting can reach security@lexitio.com — we maintain a pre-certification questionnaire and can provide a Business Associate Agreement on request.

Contact

Questions, or a diligence request.

Security issues — security@lexitio.com
Enterprise / BAA requests — enterprise@lexitio.com
Privacy PolicyTerms of ServiceBusiness Associate AgreementSOC 2 Roadmap