Trust & Security

Built for the record.

Legalancer carries depositions, transcripts, and case files for legal teams. This page explains how we protect them: the standards we follow, and where we stand on each.

Where We Stand

Compliance posture

Most trust pages are wallpaper. This one is a status board: what’s live, what’s being built, and what comes next. Each item says exactly what it is, because the security teams reading it know the difference.

Active Today

In place and operating now.

Email Integrity Active

DMARC Enforced

Every email we send is authenticated with SPF, DKIM, and DMARC at full enforcement (p=reject). Receiving mail servers are told to reject anything that claims to be from Legalancer and isn’t.

Security Baseline Active

MVSP Conformance

Legalancer meets the Minimum Viable Secure Product (v3) baseline: the checklist enterprise security teams use to screen the vendors they let near their data.

Framework Active

NIST CSF 2.0 Aligned

Our security program is aligned to the NIST Cybersecurity Framework 2.0. AI features are governed under the NIST AI Risk Management Framework.

Privacy Active

TDPSA & CCPA

We honor Texas (TDPSA) and California (CCPA/CPRA) privacy rights: access, correction, and deletion on request. We don’t sell personal data, and client data stays in the United States.

In Progress

Being implemented and documented now.

Health Data In Progress

HIPAA

We’re building our program around the HIPAA Security Rule: a formal risk analysis, workforce training, access controls, and Business Associate Agreements with the vendors that handle client content. Customer BAAs come with it.

Payments In Progress

PCI DSS

Payments happen entirely on our payment processor’s secure hosted pages, so card details never touch Legalancer’s systems. We’re completing our first SAQ A self-assessment and will re-attest every year.

Cloud Security In Progress

CSA STAR — Level 1

We’re completing the Consensus Assessments Initiative Questionnaire (CAIQ v4) for publication in the Cloud Security Alliance’s public STAR registry.

Planned

On the roadmap. These take outside auditors, time, and budget.

Independent Audit Planned

SOC 2 Type II

SOC 2 is an audit, not a checklist: an independent CPA firm examines our controls over a multi-month window. It’s on our roadmap.

Day to Day

How the platform is secured

Encrypted in transit and at rest

TLS on every connection, AES-256 on every stored file and database, and an extra layer of application-level encryption on the most sensitive fields.

Multi-factor authentication

MFA is required on all staff accounts and available to every user.

Strict portal isolation

Customers, contractors, and staff each work in their own portal. Every request re-checks role and ownership on the server, not just in the interface.

Everything on the record

Every action on a job is written to a permanent activity log: who did what, and when.

U.S. data residency

All data is hosted in U.S. cloud regions under agreements that support HIPAA obligations. Nothing is hosted outside the country.

Revocable share links

File-share links are stored only as one-way hashes and can be revoked at any time. If a link leaks, one click kills it.

Vulnerability management

Continuous dependency monitoring, with critical patches applied on a fixed schedule.

Incident response

A written response plan with named roles, customer notification commitments, and documented recovery steps.

Least-privilege access

Staff see only what their role requires; destructive operations are restricted to administrators and logged.

AI, Governed

Your documents never leave the building.

Legalancer’s AI runs on our own private instance inside Legalancer’s environment. Documents never go to an outside AI service, and nothing it reads trains a model.

It’s the role NCRA’s COPE guidance gives AI in this profession: strictly assistive, never a substitute for the certified professional.

  • AI here is a quality-control tool. It flags likely errors in a draft, and it never “cleans up” how people actually spoke.
  • Every transcript is reviewed and certified by a person. Nothing AI produces changes a page or reaches a client without human sign-off.
  • Every run is logged: the instructions, your firm’s rules, and what it found.
  • Your admins hold the keys. AI features ship switched off, and what they read is restricted to administrators, enforced on the server.

Talk to Us

Questions, documents, disclosures

Found something? Tell us.

We welcome good-faith security research. Report a vulnerability and we’ll acknowledge it within two business days. We won’t pursue legal action over research done in good faith, which means not accessing data that isn’t yours and not disrupting the service. Security questionnaires and BAA requests go to the same address.

[email protected]

Statuses on this page are kept current as our program evolves. “Active” marks a control or self-assessment in operation today, “In Progress” marks one being implemented now, and “Planned” marks work on the roadmap.