This Security Addendum forms part of the Legasus Master Subscription Agreement and Data Processing Addendum between AIDAN LLC d/b/a Legasus (“Legasus”) and Customer. It describes the baseline administrative, technical, and organizational measures Legasus maintains to protect Customer Data for Services covered by this Addendum.
Capitalized terms not defined here have the meanings given in the Master Subscription Agreement or DPA.
1. Information Security Program
Legasus will maintain a written information security program reasonably designed to protect the confidentiality, integrity, and availability of Customer Data and to address reasonably foreseeable threats to the Services.
The program will include controls appropriate to Legasus's size, systems, processing activities, and risk profile and will be reviewed and updated as reasonably necessary.
2. Security Governance and Responsibility
Legasus will maintain assigned responsibility for information-security functions and processes, including:
- security policy and risk management;
- access management;
- vulnerability management;
- secure software development;
- security incident response;
- vendor/security review;
- business continuity and disaster recovery; and
- security awareness and operational accountability.
Security responsibilities may be distributed among internal personnel and qualified service providers.
3. Data Hosting and Location
Customer Data is primarily hosted and processed in the United States unless an Order Form or written configuration states otherwise.
Legasus may use cloud infrastructure and approved Subprocessors to provide the Services. The Subprocessor List identifies material providers that Process Customer Data on Legasus's behalf.
Nothing in this Addendum constitutes a universal promise that all technical metadata or provider processing occurs exclusively within one geographic region unless an Order Form expressly provides a data-residency commitment.
4. Encryption
Legasus will use industry-standard encryption designed to protect Customer Data:
- at rest in covered production storage; and
- in transit over public or untrusted networks.
Legasus may update cryptographic implementations over time in response to accepted standards, security guidance, provider capabilities, and risk. This Addendum intentionally does not bind Legasus to a single named algorithm or protocol version unless an Order Form expressly provides otherwise.
5. Identity and Access Management
5.1 Role-Based Access
Legasus will maintain role-based or functionally equivalent access controls designed to limit access to Customer Data and production systems according to legitimate business need.
5.2 Least Privilege
Legasus personnel access to systems containing Customer Data will be based on least-privilege principles appropriate to the individual's duties.
5.3 Multi-Factor Authentication
Legasus will use multi-factor authentication for appropriate privileged or sensitive access and will make or require MFA for Customer access in accordance with supported product functionality and security settings.
5.4 Unique Access
Personnel with privileged access will use individually attributable credentials or equivalent mechanisms designed to support accountability.
5.5 Access Changes
Legasus will maintain processes to grant, modify, review, and revoke personnel access in response to role changes, termination, and identified security needs.
6. Tenant Isolation
Legasus will maintain logical controls designed to segregate Customer environments and prevent one Customer from accessing another Customer's Customer Data through ordinary authorized use of the Services.
Customer-specific AI memory, retrieval data, preferences, embeddings, or similar Customer-Specific AI Configuration will be logically isolated from unrelated Customers in accordance with the MSA.
7. Audit Logging and Monitoring
Legasus will maintain logging and monitoring appropriate to the Services and risk, which may include:
- authentication events;
- administrative actions;
- security events;
- application or infrastructure events;
- material user or data-access activity where supported; and
- system health or anomaly indicators.
Legasus will protect security logs against unauthorized modification using controls appropriate to the environment.
The nature and retention of logs may vary by service, system, legal requirement, and security need.
8. Secure Software Development
Legasus will maintain secure software-development practices reasonably designed to reduce security risk, including as appropriate:
- code review;
- change control;
- dependency and vulnerability review;
- separation of development/testing and production responsibilities where appropriate;
- testing before material production deployment;
- security consideration in design and implementation; and
- remediation of identified material vulnerabilities based on risk.
Legasus may use automated and manual security tooling as part of the development lifecycle.
9. Vulnerability Management
Legasus will maintain a vulnerability-management process that includes regular scanning or assessment of relevant systems and risk-based remediation.
Remediation prioritization may consider severity, exploitability, exposure, compensating controls, affected data, provider dependencies, operational risk, and available patches.
Legasus may temporarily apply compensating controls where immediate permanent remediation is not reasonably practicable.
10. Penetration Testing
Legasus will conduct penetration testing or equivalent independent security testing periodically and based on risk, material architectural changes, compliance needs, and industry practice.
Legasus may make an executive summary or other limited evidence of testing available to qualified Customers under appropriate confidentiality restrictions. Full reports, exploit details, source code, raw vulnerability findings, and information that could materially increase security risk need not be disclosed.
11. Malware and Threat Protection
Legasus will use controls reasonably designed to detect, prevent, or respond to malicious activity affecting production systems, which may include cloud-provider security controls, endpoint protections, access controls, monitoring, network protections, dependency scanning, and other technical measures appropriate to the environment.
12. Backups and Recovery
Legasus will maintain backup and recovery processes reasonably designed to support restoration of material Customer Data and Services following operational failure or disaster.
Backups may use retention and rotation periods that vary by system, data type, security need, legal requirement, and infrastructure architecture. Unless an Order Form expressly provides otherwise, Legasus does not guarantee a universal fixed backup-retention period.
Backups that contain Customer Data will remain subject to applicable security and confidentiality obligations while retained.
13. Business Continuity and Disaster Recovery
Legasus will maintain business continuity and disaster-recovery procedures designed to support continued or restored operation of material Services after a disruptive event.
Plans may address:
- critical systems and dependencies;
- backup and restoration;
- alternative operational procedures;
- communication and escalation;
- cloud/provider dependencies;
- incident coordination; and
- periodic review or testing.
Any specific recovery-time or recovery-point commitment must be stated in an Order Form or applicable SLA.
14. Incident Response
Legasus will maintain documented incident-response procedures addressing preparation, identification, containment, investigation, mitigation, remediation, recovery, communication, and post-incident review as appropriate.
Legasus will maintain channels for reporting suspected security incidents at security@legasus.ai.
15. Customer Security Incident Notification
15.1 Notification Standard
Legasus will notify Customer without undue delay and, where reasonably practicable, within seventy-two (72) hours after Legasus confirms a Security Incident affecting Customer Data, unless notification is prohibited or restricted by law.
This timeframe begins upon Legasus's confirmation of a Security Incident affecting Customer Data, not upon every unsuccessful attack, alert, anomaly, or security event.
15.2 Content and Updates
To the extent reasonably known and appropriate, notification may include:
- a description of the incident;
- the known or suspected categories of affected Customer Data;
- the known or estimated scope;
- mitigation steps taken or planned;
- recommended Customer actions where appropriate; and
- a point of contact for follow-up.
Legasus may provide information in stages as an investigation develops and may withhold information that would materially impair security, another customer's confidentiality, law-enforcement activity, privilege, or legal obligations.
15.3 Cooperation
Legasus will take commercially reasonable steps to investigate, contain, mitigate, and remediate a Security Incident within Legasus's responsibility and will reasonably cooperate with Customer's legally required response.
16. Personnel Security
Legasus will maintain reasonable personnel-security practices appropriate to role and legal requirements, which may include:
- confidentiality obligations;
- security awareness;
- access limitations;
- onboarding/offboarding controls;
- role-based access changes; and
- background screening where appropriate, lawful, and used by Legasus for the relevant role.
This Addendum does not create a promise that every employee or contractor will undergo an identical background-check process in every jurisdiction.
17. Vendor and Subprocessor Security
Legasus will maintain a vendor/security review process reasonably designed to evaluate material service providers that Process Customer Data or materially affect the security of the Services.
Where required by the DPA or BAA, Legasus will impose contractual security and data-protection obligations on applicable Subprocessors.
Legasus may consider factors such as:
- security documentation;
- independent assurance reports;
- compliance posture;
- data-processing scope;
- incident history where known;
- contractual controls;
- access and retention;
- geographic processing; and
- material changes in provider risk.
18. AI Provider Security and Data Protection
Where Legasus uses an approved third-party AI provider to Process Customer Data, Legasus will use business, enterprise, or API arrangements intended to prevent use of Customer Data to train the provider's generalized models, subject to the applicable provider terms and separately disclosed optional-feature conditions.
Legasus will limit AI-provider access to data reasonably necessary for the enabled functionality and will maintain a public Subprocessor List identifying applicable AI providers.
Where a Customer purchases an approved Private AI Configuration, the additional architecture commitments stated in the applicable Order Form will control.
19. Data Minimization and Environment Controls
Legasus will design and operate the Services to avoid unnecessary access to Customer Data where reasonably practicable. Production access by Legasus personnel will be limited to legitimate support, security, maintenance, legal, or operational needs consistent with the Agreement.
Legasus may use deidentified, synthetic, or nonproduction data for development and testing where reasonably appropriate, while recognizing that some troubleshooting or migration tasks may require controlled production access.
20. Data Disposal
Legasus will maintain procedures designed to delete, render inaccessible, or securely dispose of Customer Data when deletion is required under the Agreement, DPA, BAA, or applicable law, subject to backup rotation, legal retention, and technical limitations described in the Terms.
21. SOC 2 and Assurance
As of the date of this Addendum, Legasus is undergoing a SOC 2 Type II examination. This statement describes current status and does not represent that a final SOC 2 Type II report has already been issued.
Upon completion, Legasus may make its SOC 2 report or appropriate assurance documentation available to qualified Customers and prospects subject to confidentiality and access controls.
Legasus may adopt, replace, or supplement security assurance frameworks as its compliance program evolves.
22. HIPAA Security
For Customer Data that constitutes electronic Protected Health Information and is processed under an executed BAA through HIPAA-eligible Services, Legasus will maintain safeguards required of Legasus as a Business Associate under applicable provisions of the HIPAA Security Rule.
The BAA controls if there is a conflict concerning PHI.
23. Customer Responsibilities / Shared Responsibility
Security is a shared responsibility. Customer is responsible for controls within Customer's environment and use, including:
- assigning appropriate Administrators;
- maintaining current Authorized User lists;
- promptly removing departed or unauthorized users;
- protecting credentials and API/MCP secrets;
- using available MFA and authentication controls;
- configuring permissions and Client User access appropriately;
- securing Customer devices, networks, browsers, and endpoints;
- protecting Customer Data after export or download;
- configuring integrations and connected third-party accounts securely;
- avoiding unauthorized sharing of credentials or links;
- monitoring suspicious Customer-account activity;
- promptly reporting suspected compromise to Legasus; and
- complying with Customer's own regulatory and professional security obligations.
Legasus is not responsible for a security incident caused solely by Customer's failure to meet responsibilities within Customer's control, except to the extent Legasus independently contributed to the incident.
24. Security Assessments and Customer Review
Upon reasonable request from a qualified Customer or prospect, Legasus may provide appropriate security documentation such as:
- completed security questionnaires;
- trust-center information;
- relevant independent assurance documentation when available;
- penetration-test summaries;
- security architecture summaries; or
- data-flow information.
Legasus may require an NDA or other confidentiality protections before disclosing sensitive material.
Nothing requires Legasus to provide:
- source code;
- secrets or credentials;
- raw vulnerability findings;
- information belonging to another Customer;
- unrestricted infrastructure diagrams;
- full internal security policies where disclosure would create material risk; or
- information prohibited by law or contract.
25. Changes to Security Measures
Legasus may modify its security architecture and controls as technology, threats, providers, and standards evolve, provided Legasus does not materially reduce the overall security of the Services during an active paid subscription without a legitimate security, legal, technical, or operational reason.
Specific negotiated controls stated in an Order Form will be governed by that Order Form.
26. Contact
Security inquiries and incident reports: security@legasus.ai
Privacy: privacy@legasus.ai
Legal: legal@legasus.ai