Skip to content

Trust & security

Privileged material deserves a straight answer.

Legal teams hold some of the most sensitive information their clients will ever hand over. This page sets out how Lexoria protects it, where it lives, who can reach it, and what we will put in writing.

ISO/IEC 27001:2022

Certified ISMS

GDPR

Article 28 DPA available

EU residency

Frankfurt & Dublin

AES-256 / TLS 1.3

At rest and in transit

Data protection

GDPR, in the role we actually occupy.

For the content you put into the platform — client records, matter files, documents — you are the controller and Lexoria is your processor. We act on your documented instructions and nothing else. We do not mine customer content, and we do not use it to train models.

For the limited data we hold about our own relationship with you — account administration, billing, support correspondence — Lexoria is the controller. That processing is described in our privacy notice.

What we commit to in the DPA

  • Processing only on instruction — documented, with no secondary use of customer content.
  • Confidentiality obligations binding every person authorised to process the data.
  • Article 32 technical measures, described specifically rather than by reference to the article.
  • Sub-processor transparency — a maintained register and advance notice of changes, with a right to object.
  • Assistance with data-subject requests, including tooling to locate and export a person's data.
  • Breach notification without undue delay, with the detail you need for your own obligations.
  • Deletion or return at the end of the contract, on a stated schedule.
  • Audit and information rights, satisfied through our documentation pack or a direct audit for Enterprise customers.

The current DPA is available before signature and before any data is loaded — request a copy.

Data residency

In the European Union, and it stays there.

Lexoria runs entirely on European infrastructure. Primary processing and storage are in Frankfurt, with replication to Dublin for resilience. Backups never leave the EU. There is no ordinary-course transfer of customer content outside the EEA.

Enterprise customers whose own regulatory position requires it can have data pinned to a single member state, and can restrict support access to named EU-resident personnel. Both commitments are made contractually, not merely as configuration.

Primary region

Frankfurt, DE

Production databases, object storage, application tier

Secondary region

Dublin, IE

Encrypted replicas and backup retention

Recovery objectives

< 1 h

Recovery time objective

< 5 min

Recovery point objective

Technical measures

The controls behind the certificate.

Certification says an auditor checked. These are the things they checked.

Encryption in transit

All connections use TLS 1.2 or above, with TLS 1.3 preferred and HSTS enforced across every Lexoria domain. Internal service-to-service traffic is encrypted within our private network.

Encryption at rest

Data at rest — including databases, object storage and backups — is encrypted with AES-256. Keys are held in a managed key service with scheduled rotation and access recorded separately from the data.

Access control

Least-privilege access, enforced two-factor authentication for all Lexoria staff, and just-in-time elevation for production. Customer content is not accessible to staff by default.

Secure development

Peer review on every change, automated dependency and static analysis in the pipeline, and separate development, staging and production environments. Production is never seeded with customer data.

Monitoring and response

Centralised logging, anomaly alerting and a documented incident response procedure with defined severities, on-call rotation and post-incident review.

Resilience

Encrypted backups taken continuously with point-in-time recovery for 35 days, replicated across two EU availability zones. Restore procedures are tested twice a year.

Sub-processors

Who else touches the data.

We keep the register short deliberately. Customers on the register's notification list receive at least 30 days' notice before a new sub-processor is engaged, with a right to object.

Lexoria sub-processor register
Category Purpose Processing location
Cloud infrastructure Hosting, storage and managed databases Germany (Frankfurt), Ireland (Dublin)
Transactional email Service notifications, alerts and password resets European Union
Error monitoring Application diagnostics and crash reporting European Union
Support desk Ticketing and support correspondence European Union
Payment processing Subscription billing and invoicing European Union

Named entities and current contact details are provided in the DPA pack. Categories shown here describe a fictional service.

Common questions

From security reviews.

These come up in almost every procurement process, so they are answered here rather than in a questionnaire six weeks later.

Request the full pack

Reporting a vulnerability

Tell us, and we will not make it awkward.

If you believe you have found a security issue in Lexoria, write to security@info-lex.lt with enough detail to reproduce it. We acknowledge reports within two business days and will keep you updated until it is closed. We do not pursue researchers who act in good faith, stay within their own test account, and give us reasonable time before disclosing.

Book a demo

Send us your security questionnaire.

We would rather answer it before the commercial conversation than after. Most packs come back within three business days.

No card required EU-hosted DPA available on request