LegalPunkt Security & Governance
LegalPunkt maintains the highest standards of security and data protection. We offer fully fine-grained access control, fully encrypted data in transit and at rest, full agent explainability, and a complete log of actions. Most importantly, we never train our agents on user data. The platform is fully GDPR compliant.
The Security Center tab within your LegalPunkt Settings panel serves as an informational and monitoring hub, giving you full visibility into our security posture, deployment structures, active certifications, compliance documentation, and real-time audit logs.
Compliance Documents
Through the Security Center, administrators can request access to official, audited compliance reports and structural architecture documentation to facilitate internal vendor risk assessments (VRAs):
- Security Whitepaper
A comprehensive architectural guide that outlines LegalPunkt's network topology, end-to-end data encryption schemes, threat models, and secure development lifecycle (SDLC) controls. It includes details on database isolation, vulnerability testing frequency, and active penetration test digests. - Information Security Policy
A copy of our internal security rules, detailing access restriction rules, employee background screening policies, incident response runbooks, password management, and operational security guidelines. - Architecture Diagram
Visual representations of the LegalPunkt database isolates, data routing flow across standard and tenant VPCs, firewall rules, and container orchestration schemas.
To request access to any of these documents, click the Request Access action next to the document name in the Security Center interface.
Identity & Access Management
Your Identity, Your Rules
LegalPunkt integrates directly with major enterprise Identity Providers (IDPs) such as Google Workspace, Microsoft Azure AD (Entra ID), Okta, and GitHub. This direct integration allows your security team to:
- Seamlessly enforce corporate Single Sign-On (SSO) frameworks.
- Enforce Multi-Factor Authentication (MFA) at the IDP level.
- Define continuous session validity rules, ensuring automated timeouts after periods of inactivity.
Granular Access Control
Manage user actions with attribute-based access control (ABAC), strict permission boundaries, and session governance aligned precisely with your internal security policies and regulatory frameworks. You can define access rights down to the individual user or project context—controlling exactly who has permission to read, modify, or export legal intelligence.
Adaptive Directory Sync (SCIM)
Keep your user registries automatically synchronized in real-time. Whenever an employee joins, leaves, or transitions between legal departments, SCIM directory synchronization automatically updates their access states across all secure project contexts. This instant de-provisioning prevents stale authorization tokens and eliminates the risk of unauthorized access from former staff.
Data Protection & Encryption
Encryption at Rest & in Transit
LegalPunkt secures proprietary customer assets and sensitive contract schemas using advanced cryptographic protocols. Service data transmitted over the internet is encrypted-in-transit using Transport Layer Security (TLS 1.3), and all databases and snapshots are encrypted-at-rest using AES-256 keys.
Hardware Security Modules (HSMs)
All customer secrets, cryptographic keys, and API access credentials are isolated in high-availability vaults backed by dedicated, physical Hardware Security Modules (HSMs). Keys are never exposed in plaintext to application components or cloud provider staff.
Pipeline Anonymisation
Data processed through our pipelines undergoes thorough anonymization. Before sending documents or queries to underlying language models, our sanitization engine automatically scrubs and masks sensitive Personally Identifiable Information (PII) and privileged identifiers, keeping your business transactions and client communications private and protected.
Zero-Knowledge AI Engine
LegalPunkt implements strict zero-knowledge parameters for processing to guarantee absolute confidentiality:
- Immediate Cache Purging: Once our reasoning model concludes a playbook review, contract parsing, or document generation, all session cache states and working memory pools are purged immediately.
- No AI Training on User Data: No client information, document inputs, or generated legal intelligence is ever retained, stored, or ingested for subsequent AI training cycles. Your proprietary data belongs strictly to you.
Protected Infrastructure (Flexible Deployment Models)
LegalPunkt offers the flexibility to choose the physical sovereignty of your legal workspace through three distinct deployment models:
1. Managed Zero-Trust Multi-Tenant Cloud SaaS
Our standard SaaS tier offers instant provisioning, fully automated software updates, and scaling pipelines without operational overhead. Data resides in secure, logically separated virtual databases within our main regional infrastructure (AWS EU-Central-1, Frankfurt), ensuring that no cross-contamination of workspace data occurs.
2. Dedicated Single-Tenant Cloud
Dedicated private instances deployed on isolated cloud clusters within a private Virtual Private Cloud (VPC) on AWS or Azure in your preferred geographic region (EMEA, US, or APAC). This isolates your data on both the database and application levels, ensuring zero co-mingling of workspace databases.
3. On-Premises VPC
Deploy protected software containers directly within your private network or corporate firewall. This allows your organization to retain total physical custody over all operational and document contexts, guaranteeing that no data leaves your controlled servers.
Live Environment Monitoring & Extended Audits
The Security Center displays real-time status monitors (All Systems Operational) and allows you to audit the operational controls that govern LegalPunkt's infrastructure, applications, and organization.
Access Security
We maintain strict access boundaries to prevent unauthorized data exposure:
- Encryption-in-Transit: Encrypts all data in flight across the internet.
- Asset Inventory: Maintains a comprehensive, annually reviewed register of all system assets.
- User Access Reviews: Governs access levels through scheduled reviews of server, database, and application permissions.
- Access Control and Termination Policy: Outlines strict joiner/mover/leaver access processes.
- Removal of Access: Ensures immediate deletion of access privileges upon employee termination.
- Encryption and Key Management Policy: Regulates key generation, usage, and rotation.
- Encryption-at-Rest: Ensures data on disks is fully encrypted.
- Access to Product is Restricted: Restricts production infrastructure access to authorized staff using unique SSH keys.
- Least Privilege in Use: Limits user permissions to the absolute minimum required to perform their roles.
- Administrative Access is Restricted: Restricts admin rights to ensure separation of duties.
Network Security
Our networks are continuously audited to defend against threats and vulnerabilities:
- Logging and Monitoring for Threats: Automatically collects logs to identify anomalous patterns or potential security breaches.
- Automated Alerting for Security Events: Instantly notifies security incident response teams of alerts.
- Network Security Policy: Documents firewall and segregation rules.
- Endpoint Security: Enforces full disk encryption, anti-virus, and password policies on all corporate endpoints.
- Network Traffic Monitoring: Evaluates incoming and outgoing traffic configurations.
Confidentiality
We enforce clear rules on how sensitive documents are handled, stored, and deleted:
- Data Retention and Disposal Policy: Governs how long client data is stored and how it is securely overwritten when no longer needed.
- Access to Customer Data is Restricted: Strictly restricts data visibility based on need-to-know principles.
- Data Classification Policy: Tags and handles files based on their level of sensitivity.
- Retention of Customer Data: Governs contractual retention agreements.
- Disposal of Customer Data: Automatically scrubs customer workspaces upon request or contract termination.
Availability
We build systems with high redundancy to prevent downtime and data loss:
- Business Continuity and Disaster Recovery Policy: Details procedures to restore services after catastrophic disruptions.
- Backup Restoration Testing: Validates that backup data can be successfully restored through annual testing.
- Testing the BC/DR Plan: Evaluates disaster recovery readiness through simulated tabletop exercises.
- High Availability Configuration: Deploys active-active clustering to eliminate single points of failure.
Vulnerability Management
We proactively identify and remediate weaknesses in our applications and infrastructure:
- Vulnerability Scanning: Conducts automated scans to identify missing patches and configurations.
- Third-Party Penetration Test: Engages independent cybersecurity firms annually to simulate external attacks.
- Vulnerability and Patch Management Policy: Defines strict SLAs for patching critical vulnerabilities.
Change Management
Every update to the platform is tracked and reviewed:
- Configuration and Asset Management Policy: Standardizes configuration settings.
- Approval for System Changes: Requires independent peer reviews before pushing code to production.
- Production Data Use is Restricted: Prohibits the use of production client data in test or staging environments.
- Segregation of Environments: Separates development, testing, staging, and production networks.
- Change Management Policy: Audits all code, infrastructure, and configuration changes.
- Secure Development Policy: Enforces OWASP secure coding standards.
- Software Change Testing: Automated and manual validation of code changes.
- Baseline Configurations: Benchmarks systems against secure standards.
Incident Response
We are prepared to respond to and mitigate security events quickly:
- Lessons Learned: Reviews incidents to improve future defensive controls.
- Incident Response Plan Testing: Runs tabletop simulations of incident responses.
- Tracking a Security Incident: Records and tracks security events from discovery to resolution.
- Incident Response Plan: Defines communication, containment, and eradication protocols.
Organizational Management
Security is integrated into our corporate culture and governance structures:
- Roles and Responsibilities: Outlines security duties for all roles.
- New Hire Screening: Enforces background checks and confidentiality agreements.
- Advisor Meetings on Security: Board-level review of security and risk metrics.
- Organizational Chart: Identifies lines of communication and authority.
- Performance Review Policy: Integrates security compliance into performance evaluations.
- Internal Control Monitoring: Reviews active security controls for effectiveness.
- Acceptable Use Policy: Details employee guidelines for using corporate systems.
- Independent Advisor: Works with external advisory boards for independent governance.
- Code of Conduct: Sets ethical and security behavior expectations.
- Information Security Program Review: Annual evaluation of the ISMS by senior leadership.
- Internal Control Policy: Defines operational controls.
- Cybersecurity Insurance: Protects against the financial impacts of security incidents.
- Disciplinary Action: Establishes penalties for security policy violations.
- Information Security Policy: Dictates the overarching security goals of the company.
Risk Assessment
We continuously evaluate current and emerging risks:
- Risk Assessment: Evaluates potential threats to data confidentiality, integrity, and availability.
- Risk Assessment and Treatment Policy: Defines risk tolerance and mitigation strategies.
- Vendor Risk Management Policy: Manages security compliance for external suppliers.
Physical Security
Our server hardware and facilities are physically protected:
- Physical Access Reviews: Audits entry logs for company facilities.
- Physical Security Policy: Sets guidelines for physical access controls at data centers and offices.
