Security built in. Trust earned.
We follow security best practices today and are actively pursuing formal certifications. This page will be updated as we achieve them.
From encryption to access management, LegaLite enforces rigorous standards to ensure your data stays secure, private, and compliant.
Your business deserves a partner you can trust. That’s why we design every element of LegaLite with security, privacy, and resilience in mind.
Compliance & certifications
LegaLite aligns with leading security and privacy frameworks.
SOC 2 ready
Built according to SOC 2 Trust Service Criteria
ISO 27001 & 27002 aligned
Aligned with ISO 27001 Annex A controls covering access control, encryption, development practices, incident response, and continuity.
GDPR aligned
Even though LegaLite does not primarily target the EU, we uphold GDPR principles for data subject rights and processing transparency.
Ghana data protection
LegaLite is built around the 8 Data Protection Principles, incorporating purpose limitation, data minimization, support for user rights such as access, correction, and deletion, working toward registration with the Data Protection Commission, and safeguards for cross border data transfers.
Access controls
LegaLite provides robust, granular control over user and workspace permissions.
Authentication
Secure login, hashed passwords, protected sessions
Role based access control (RBAC)
Workspace permissions and case level access
Authorization Enforcement
Strict checks across all platform resources
Audit logs
Detailed history of activities, actions, and document events
Session management
Short lived tokens and automatic revocation on logout
Data protection
We ensure that all legal information is protected end to end.
End to end encryption and key management
TLS 1.2+ encryption in transit, AES-256 encryption at rest, secure document storage, and provider managed encryption keys.
Strong Data Governance
Secure secrets management, defined retention controls, and protected access controlled file handling.
You own your data
You can export all your data at any time, and you have the option to permanently delete your account whenever you choose. Beyond that, our enterprise grade security controls give you full authority over where your data is stored, how long it’s retained, how encryption keys are managed, and complete visibility into how your information is handled across the platform.
FAQs
You own your data. We do not use customer data for model training or secondary commercial purposes. You can request exports, see audit logs, and ask for deletions, we provide clear controls in the product and contractual guarantees for enterprise agreements.
Not yet. We are actively working toward SOC 2 Type II and have ISO 27001 in our roadmap. We publish audit results and certificates here when available.
At LegaLite, protecting your data is our top priority. All data is encrypted in transit using TLS 1.2 or higher, and at rest with AES-256 encryption. For customers who require additional control, we also offer the option to encrypt data with their own encryption keys. If this is of interest, please let us know.
Once your contract ends, all of your data, along with any dedicated storage resources associated with your account, is permanently deleted. Before this happens, you’ll have the opportunity to request a full export of your data to ensure you retain everything you need.