SOC 2 Type II
Lawgical completed the SOC 2 Type II examination process for controls relevant to the Security Trust Services Criterion.
The confidential report is available to qualified customers under NDA once finalized.
A clear view of how Lawgical protects customer data, manages risk, and supports security reviews for modern law firms.
Lawgical completed the SOC 2 Type II examination process for controls relevant to the Security Trust Services Criterion.
The confidential report is available to qualified customers under NDA once finalized.
An independent review mapped Lawgical controls to selected HIPAA Privacy, Security, and Breach Notification Rule requirements.
Controls attestation issued May 25, 2026; next review May 25, 2027.
Security program
Technical and operational safeguards work together to protect the confidentiality, integrity, and availability of customer data.
TLS 1.3 protects data in transit. Stored data is protected with AES-256 encryption, plus infrastructure-level and column-level safeguards where appropriate.
Role-based permissions, least-privilege practices, secure session controls, OAuth2, and passwordless sign-in help limit access to authorized users.
Application controls and database Row-Level Security work together to keep each law firm’s records separated from other tenants.
Centralized logging, operational monitoring, anomaly detection, and layered controls help us identify and respond to unexpected behavior.
Lawgical runs on managed cloud services with workload isolation, encrypted storage, secure service identities, and redundancy where available.
Provider-managed backups run daily. Encrypted backup snapshots are used for recovery and expire on controlled, rolling schedules.
Privacy and AI
Our privacy program is built around customer direction, limited use, clear retention practices, and responsible human oversight of AI-enabled workflows.
Read the privacy policyLaw firms control what information they collect and may delete records in the product or submit a verified deletion request.
We retain and process information only as needed to provide the service, meet customer instructions, or satisfy legal obligations.
We do not use identifiable client content from one law firm to build or fine-tune a general-purpose model for unrelated third parties.
AI outputs may be imperfect. Law firms remain responsible for reviewing outputs, making decisions, and providing legal advice.
Documentation
Review public policies or request confidential assurance material from our team.
Encryption, architecture, access controls, backups, recovery, subprocessors, and retention.
Data collection, processing roles, sharing, rights, AI disclosures, and international transfers.
The terms governing use of Lawgical’s website, applications, and services.
Confidential assurance documentation for qualified customers and security reviewers.
Independent controls review mapped to selected HIPAA Privacy, Security, and Breach Notification Rule requirements.
Processing terms, technical safeguards, service providers, locations, and data categories.
Resilience and response
Daily provider-managed backups support recovery, with a documented target RPO of about 24 hours and full-restoration RTO of 24–48 hours.
Critical availability or essential data-flow issues receive an initial response within one hour, followed by investigation, containment, and remediation.
Confirmed incidents affecting client data trigger customer notification within 72 hours and a documented post-incident review for affected customers.
Subprocessors are reviewed for security, reliability, compliance posture, purpose, and handling of customer data.
Personnel with access to personal data are bound by confidentiality obligations and access is limited to legitimate business needs.
Our DPA describes customer and processor roles, safeguards, deletion, audit support, and subprocessor responsibilities.
Security is reviewed as our product, infrastructure, vendors, and customer requirements evolve.
Common questions
Lawgical uses TLS 1.3 for data in transit and AES-256 for data at rest. Managed infrastructure also provides full-disk encryption, with column-level encryption used for highly sensitive fields where appropriate.
Tenant boundaries are enforced in the application and at the database layer. Row-Level Security policies restrict records to authorized firm and user contexts.
Lawgical’s core systems are hosted in the United States on managed cloud infrastructure. Our security overview lists the key provider categories and available regional details.
After verifying the requester and scope, Lawgical schedules deletion from active production systems. Operational deletion typically occurs within 30 days, while encrypted backup copies expire through provider-managed retention cycles.
Lawgical does not use identifiable client content from one law firm to build or fine-tune a general-purpose model that benefits unrelated third parties.
Email our team using the document links above. Qualified customers and prospects can request reports and supporting material, with an NDA used where appropriate.
Send us your question, request supporting documents, or share a vendor security questionnaire.