Security built in. Trust earned.

We follow security best practices today and are actively pursuing formal certifications. This page will be updated as we achieve them.

From encryption to access management, LegaLite enforces rigorous standards to ensure your data stays secure, private, and compliant.

Security principles

Your business deserves a partner you can trust. That’s why we design every element of LegaLite with security, privacy, and resilience in mind.

Compliance & certifications

LegaLite aligns with leading security and privacy frameworks.

SOC 2 ready

Built according to SOC 2 Trust Service Criteria

ISO 27001 & 27002 aligned

Aligned with ISO 27001 Annex A controls covering access control, encryption, development practices, incident response, and continuity.

GDPR aligned

Even though LegaLite does not primarily target the EU, we uphold GDPR principles for data subject rights and processing transparency.

Ghana data protection

LegaLite is built around the 8 Data Protection Principles, incorporating purpose limitation, data minimization, support for user rights such as access, correction, and deletion, working toward registration with the Data Protection Commission, and safeguards for cross border data transfers.

Access controls

LegaLite provides robust, granular control over user and workspace permissions.

Authentication

Secure login, hashed passwords, protected sessions

Role based access control (RBAC)

Workspace permissions and case level access

Authorization Enforcement

Strict checks across all platform resources

Audit logs

Detailed history of activities, actions, and document events

Session management

Short lived tokens and automatic revocation on logout

Data protection

We ensure that all legal information is protected end to end.

End to end encryption and key management

TLS 1.2+ encryption in transit, AES-256 encryption at rest, secure document storage, and provider managed encryption keys.

Strong Data Governance

Secure secrets management, defined retention controls, and protected access controlled file handling.

Customer controls

You own your data

You can export all your data at any time, and you have the option to permanently delete your account whenever you choose. Beyond that, our enterprise grade security controls give you full authority over where your data is stored, how long it’s retained, how encryption keys are managed, and complete visibility into how your information is handled across the platform.

Frequently asked questions

FAQs

You own your data. We do not use customer data for model training or secondary commercial purposes. You can request exports, see audit logs, and ask for deletions, we provide clear controls in the product and contractual guarantees for enterprise agreements.

Not yet. We are actively working toward SOC 2 Type II and have ISO 27001 in our roadmap. We publish audit results and certificates here when available.

At LegaLite, protecting your data is our top priority. All data is encrypted in transit using TLS 1.2 or higher, and at rest with AES-256 encryption. For customers who require additional control, we also offer the option to encrypt data with their own encryption keys. If this is of interest, please let us know.

Once your contract ends, all of your data, along with any dedicated storage resources associated with your account, is permanently deleted. Before this happens, you’ll have the opportunity to request a full export of your data to ensure you retain everything you need.