This is a public, non-exhaustive overview. Contractual commitments are governed by the Master Subscription Agreement, DPA, Security Addendum, and BAA where applicable.
Security Designed for Legal Work
Legasus is built for law firms and legal teams that handle confidential, privileged, personal, and often highly sensitive information. Our security program is designed around protecting Customer Data while supporting modern case management, AI-assisted legal work, collaboration, integrations, and client access.
No technology can eliminate all security risk. Our approach is to combine layered technical controls, access management, secure development, monitoring, vendor oversight, incident response, and contractual data protections.
Data Protection
Legasus maintains controls designed to protect Customer Data at rest and in transit using industry-standard encryption.
Customer environments are designed with logical tenant isolation so one Customer cannot access another Customer's data through ordinary authorized use.
Identity and Access
Legasus uses controls including:
- multi-factor authentication;
- role-based access control;
- least-privilege access principles;
- individually attributable administrative access; and
- processes to update/revoke access when roles change.
Customers are responsible for configuring their own users, administrators, permissions, and Client User access appropriately.
Auditability
Legasus maintains audit and security logging appropriate to the platform and feature. Logging may include authentication, administrative, security, application, and material activity events.
Law firms can use supported platform audit features to help understand activity within their environment.
Secure Software Development
Our development practices include security considerations throughout the software lifecycle, including:
- code review;
- change management;
- vulnerability scanning;
- dependency/security review;
- testing; and
- risk-based remediation.
Vulnerability Management and Penetration Testing
Legasus maintains vulnerability-management processes and conducts penetration testing or equivalent independent security testing periodically and based on risk and material system changes.
Qualified customers may request appropriate security assurance information. Sensitive findings and detailed security information are controlled rather than publicly posted.
Backups, Continuity, and Recovery
Legasus maintains backup, business-continuity, and disaster-recovery processes designed to support restoration of material services and Customer Data after operational disruption.
Specific recovery targets, where contractually committed, are stated in the applicable Order Form or SLA rather than generalized across every product configuration.
Incident Response
Legasus maintains documented incident-response procedures covering identification, containment, investigation, remediation, recovery, and communication.
Our contractual security framework provides for notification of confirmed Security Incidents affecting Customer Data without undue delay and, where reasonably practicable, within 72 hours, subject to applicable terms and law.
Security concerns can be reported to security@legasus.ai.
AI and Customer Data
Legasus's default AI data approach is designed around a core principle:
Customer Data is not used to train generalized/shared Legasus models for unrelated Customers unless a Customer separately and expressly agrees in writing.
Where approved third-party AI providers are used, Legasus uses business, enterprise, or API arrangements intended to prevent Customer Data from being used to train the provider's generalized models, subject to provider-specific terms and feature conditions.
Customer-Specific AI
A firm may choose Customer-Specific AI Configuration that allows its own AI environment to adapt to firm-authorized materials, preferences, workflows, terminology, and best practices.
Customer-specific learning is designed to remain isolated to that Customer and is not used to improve another firm's private agents or a generalized/shared model.
Private AI Options
For customers with heightened requirements, Legasus may offer a separately approved Private AI Configuration that can be designed to avoid sending specified AI Inputs to third-party foundation-model inference providers.
The exact Private AI architecture and commitments are defined in the Customer's Order Form or written configuration.
AI Human Review
Legasus AI is designed to assist professionals, not replace professional responsibility. Material AI-generated legal work requires appropriate human review, and material agentic actions use review/approval controls by default where the product provides those controls.
Customers may request certain experimental reduced-approval functionality, but such configurations are not recommended for material legal or irreversible actions without meaningful supervision.
HIPAA
Legasus supports eligible Customers' HIPAA compliance obligations and can enter into a Business Associate Agreement for Services/configurations designated as HIPAA-eligible.
Not every feature, integration, Beta Feature, or third-party service is automatically HIPAA-eligible.
For applicable ePHI, Legasus agrees to HIPAA obligations through the executed BAA and uses approved downstream arrangements where required.
SOC 2
Legasus is currently undergoing a SOC 2 Type II examination.
This describes our current status and is not a statement that a final SOC 2 Type II report has already been issued. Once completed, appropriate assurance documentation may be made available to qualified Customers and prospects under confidentiality protections.
Vendor and Subprocessor Risk
Legasus maintains a vendor-security review process for material providers. Our public Subprocessor List identifies providers that may Process Customer Data on our behalf depending on the features used.
Data Location
Customer Data is primarily hosted in the United States unless an applicable Order Form or written configuration states otherwise.
International data transfers are addressed through our DPA and Data Transfer Addendum where applicable.
Client Portal Security
Client-facing access is intended to be limited, Customer-invited, matter-specific, and subject to access controls. Firms remain responsible for deciding what each Client User may access and for revoking access when appropriate.
Responsible Disclosure
Security researchers can report suspected vulnerabilities through our Responsible Disclosure Policy and security@legasus.ai.
Request Security Documentation
Qualified Customers and prospects may request available security materials, which may include:
- security questionnaires;
- DPA and Security Addendum;
- BAA information;
- subprocessor information;
- penetration-test summary information;
- data-flow/security architecture summaries; and
- SOC 2 materials once available.
Some materials may require confidentiality protection.
Security: security@legasus.ai
Privacy / BAA: privacy@legasus.ai
Legal: legal@legasus.ai