DMARC Enforced
Every email we send is authenticated with SPF, DKIM, and DMARC at full enforcement (p=reject). Receiving mail servers are told to reject anything that claims to be from Legalancer and isn’t.
Where We Stand
Most trust pages are wallpaper. This one is a status board: what’s live, what’s being built, and what comes next. Each item says exactly what it is, because the security teams reading it know the difference.
In place and operating now.
Every email we send is authenticated with SPF, DKIM, and DMARC at full enforcement (p=reject). Receiving mail servers are told to reject anything that claims to be from Legalancer and isn’t.
Legalancer meets the Minimum Viable Secure Product (v3) baseline: the checklist enterprise security teams use to screen the vendors they let near their data.
Our security program is aligned to the NIST Cybersecurity Framework 2.0. AI features are governed under the NIST AI Risk Management Framework.
We honor Texas (TDPSA) and California (CCPA/CPRA) privacy rights: access, correction, and deletion on request. We don’t sell personal data, and client data stays in the United States.
Being implemented and documented now.
We’re building our program around the HIPAA Security Rule: a formal risk analysis, workforce training, access controls, and Business Associate Agreements with the vendors that handle client content. Customer BAAs come with it.
Payments happen entirely on our payment processor’s secure hosted pages, so card details never touch Legalancer’s systems. We’re completing our first SAQ A self-assessment and will re-attest every year.
We’re completing the Consensus Assessments Initiative Questionnaire (CAIQ v4) for publication in the Cloud Security Alliance’s public STAR registry.
On the roadmap. These take outside auditors, time, and budget.
SOC 2 is an audit, not a checklist: an independent CPA firm examines our controls over a multi-month window. It’s on our roadmap.
Day to Day
TLS on every connection, AES-256 on every stored file and database, and an extra layer of application-level encryption on the most sensitive fields.
MFA is required on all staff accounts and available to every user.
Customers, contractors, and staff each work in their own portal. Every request re-checks role and ownership on the server, not just in the interface.
Every action on a job is written to a permanent activity log: who did what, and when.
All data is hosted in U.S. cloud regions under agreements that support HIPAA obligations. Nothing is hosted outside the country.
File-share links are stored only as one-way hashes and can be revoked at any time. If a link leaks, one click kills it.
Continuous dependency monitoring, with critical patches applied on a fixed schedule.
A written response plan with named roles, customer notification commitments, and documented recovery steps.
Staff see only what their role requires; destructive operations are restricted to administrators and logged.
AI, Governed
Legalancer’s AI runs on our own private instance inside Legalancer’s environment. Documents never go to an outside AI service, and nothing it reads trains a model.
It’s the role NCRA’s COPE guidance gives AI in this profession: strictly assistive, never a substitute for the certified professional.
Talk to Us
We welcome good-faith security research. Report a vulnerability and we’ll acknowledge it within two business days. We won’t pursue legal action over research done in good faith, which means not accessing data that isn’t yours and not disrupting the service. Security questionnaires and BAA requests go to the same address.
Statuses on this page are kept current as our program evolves. “Active” marks a control or self-assessment in operation today, “In Progress” marks one being implemented now, and “Planned” marks work on the roadmap.