Lexitio is built for legal professionals who handle sensitive, privileged client information. Every architectural and operational decision assumes your data requires the highest level of protection — not because a regulator demands it, but because attorney-client privilege is the foundation of legal practice.
LAST UPDATED · JUNE 15, 2026
Each firm's data is completely separate from every other firm's, enforced at two independent layers — the application and the database itself — and encrypted both in transit and at rest.
No architectural decision here assumes trust — every layer checks for itself.
Every sensitive action is recorded to a permanent, tamper-evident trail. Hosting is dedicated US infrastructure with daily, restore-tested backups. If something goes wrong, containment and notification are documented, not improvised.
Vulnerability disclosure. If you believe you've found a security vulnerability in Lexitio, report it to security@lexitio.com. We acknowledge reports within 2 business days, provide regular status updates, and work with researchers on responsible disclosure — we do not pursue legal action against anyone who follows it.
Your matter data, client information, uploaded documents, and query content are never used to train any AI model — including any third-party provider we use.
Our controls are built to the SOC 2 Trust Service Criteria from day one. Type I certification is targeted for Q3 2026, with Type II to follow after the required 6-month observation period. Enterprise firms needing a report or security questionnaire before contracting can reach security@lexitio.com — we maintain a pre-certification questionnaire and can provide a Business Associate Agreement on request.