We protect your work because it matters

A clear view of how Lawgical protects customer data, manages risk, and supports security reviews for modern law firms.

SOC 2 Type II

Lawgical completed the SOC 2 Type II examination process for controls relevant to the Security Trust Services Criterion.

The confidential report is available to qualified customers under NDA once finalized.

HIPAA controls

An independent review mapped Lawgical controls to selected HIPAA Privacy, Security, and Breach Notification Rule requirements.

Controls attestation issued May 25, 2026; next review May 25, 2027.

Security program

Security at every layer.

Technical and operational safeguards work together to protect the confidentiality, integrity, and availability of customer data.

Encryption

TLS 1.3 protects data in transit. Stored data is protected with AES-256 encryption, plus infrastructure-level and column-level safeguards where appropriate.

Identity and access

Role-based permissions, least-privilege practices, secure session controls, OAuth2, and passwordless sign-in help limit access to authorized users.

Tenant isolation

Application controls and database Row-Level Security work together to keep each law firm’s records separated from other tenants.

Monitoring and defense

Centralized logging, operational monitoring, anomaly detection, and layered controls help us identify and respond to unexpected behavior.

Secure infrastructure

Lawgical runs on managed cloud services with workload isolation, encrypted storage, secure service identities, and redundancy where available.

Backups and recovery

Provider-managed backups run daily. Encrypted backup snapshots are used for recovery and expire on controlled, rolling schedules.

Privacy and AI

Customer data stays customer data.

Our privacy program is built around customer direction, limited use, clear retention practices, and responsible human oversight of AI-enabled workflows.

Read the privacy policy

Customer control

Law firms control what information they collect and may delete records in the product or submit a verified deletion request.

Purpose limitation

We retain and process information only as needed to provide the service, meet customer instructions, or satisfy legal obligations.

Responsible AI

We do not use identifiable client content from one law firm to build or fine-tune a general-purpose model for unrelated third parties.

Human review

AI outputs may be imperfect. Law firms remain responsible for reviewing outputs, making decisions, and providing legal advice.

Documentation

Start your security review.

Review public policies or request confidential assurance material from our team.

Ask a security question

Resilience and response

Prepared for the unexpected.

Recovery

Daily provider-managed backups support recovery, with a documented target RPO of about 24 hours and full-restoration RTO of 24–48 hours.

Incident response

Critical availability or essential data-flow issues receive an initial response within one hour, followed by investigation, containment, and remediation.

Accountability

Confirmed incidents affecting client data trigger customer notification within 72 hours and a documented post-incident review for affected customers.

Governance beyond the product.

Vendor oversight

Subprocessors are reviewed for security, reliability, compliance posture, purpose, and handling of customer data.

Confidentiality

Personnel with access to personal data are bound by confidentiality obligations and access is limited to legitimate business needs.

Data processing terms

Our DPA describes customer and processor roles, safeguards, deletion, audit support, and subprocessor responsibilities.

Continuous improvement

Security is reviewed as our product, infrastructure, vendors, and customer requirements evolve.

Common questions

Security review FAQ.

How is customer data encrypted?

Lawgical uses TLS 1.3 for data in transit and AES-256 for data at rest. Managed infrastructure also provides full-disk encryption, with column-level encryption used for highly sensitive fields where appropriate.

How is one law firm’s data separated from another’s?

Tenant boundaries are enforced in the application and at the database layer. Row-Level Security policies restrict records to authorized firm and user contexts.

Where is data hosted?

Lawgical’s core systems are hosted in the United States on managed cloud infrastructure. Our security overview lists the key provider categories and available regional details.

What happens when a customer requests deletion?

After verifying the requester and scope, Lawgical schedules deletion from active production systems. Operational deletion typically occurs within 30 days, while encrypted backup copies expire through provider-managed retention cycles.

Does Lawgical use client data to train shared AI models?

Lawgical does not use identifiable client content from one law firm to build or fine-tune a general-purpose model that benefits unrelated third parties.

How can my security team review confidential documents?

Email our team using the document links above. Qualified customers and prospects can request reports and supporting material, with an NDA used where appropriate.

Need more details?

Send us your question, request supporting documents, or share a vendor security questionnaire.

Contact security