Trust & security
Privileged material deserves a straight answer.
Legal teams hold some of the most sensitive information their clients will ever hand over. This page sets out how Lexoria protects it, where it lives, who can reach it, and what we will put in writing.
ISO/IEC 27001:2022
Certified ISMS
GDPR
Article 28 DPA available
EU residency
Frankfurt & Dublin
AES-256 / TLS 1.3
At rest and in transit
Data protection
GDPR, in the role we actually occupy.
For the content you put into the platform — client records, matter files, documents — you are the controller and Lexoria is your processor. We act on your documented instructions and nothing else. We do not mine customer content, and we do not use it to train models.
For the limited data we hold about our own relationship with you — account administration, billing, support correspondence — Lexoria is the controller. That processing is described in our privacy notice.
What we commit to in the DPA
- Processing only on instruction — documented, with no secondary use of customer content.
- Confidentiality obligations binding every person authorised to process the data.
- Article 32 technical measures, described specifically rather than by reference to the article.
- Sub-processor transparency — a maintained register and advance notice of changes, with a right to object.
- Assistance with data-subject requests, including tooling to locate and export a person's data.
- Breach notification without undue delay, with the detail you need for your own obligations.
- Deletion or return at the end of the contract, on a stated schedule.
- Audit and information rights, satisfied through our documentation pack or a direct audit for Enterprise customers.
The current DPA is available before signature and before any data is loaded — request a copy.
Data residency
In the European Union, and it stays there.
Lexoria runs entirely on European infrastructure. Primary processing and storage are in Frankfurt, with replication to Dublin for resilience. Backups never leave the EU. There is no ordinary-course transfer of customer content outside the EEA.
Enterprise customers whose own regulatory position requires it can have data pinned to a single member state, and can restrict support access to named EU-resident personnel. Both commitments are made contractually, not merely as configuration.
Primary region
Frankfurt, DE
Production databases, object storage, application tier
Secondary region
Dublin, IE
Encrypted replicas and backup retention
Recovery objectives
< 1 h
Recovery time objective
< 5 min
Recovery point objective
Technical measures
The controls behind the certificate.
Certification says an auditor checked. These are the things they checked.
Encryption in transit
All connections use TLS 1.2 or above, with TLS 1.3 preferred and HSTS enforced across every Lexoria domain. Internal service-to-service traffic is encrypted within our private network.
Encryption at rest
Data at rest — including databases, object storage and backups — is encrypted with AES-256. Keys are held in a managed key service with scheduled rotation and access recorded separately from the data.
Access control
Least-privilege access, enforced two-factor authentication for all Lexoria staff, and just-in-time elevation for production. Customer content is not accessible to staff by default.
Secure development
Peer review on every change, automated dependency and static analysis in the pipeline, and separate development, staging and production environments. Production is never seeded with customer data.
Monitoring and response
Centralised logging, anomaly alerting and a documented incident response procedure with defined severities, on-call rotation and post-incident review.
Resilience
Encrypted backups taken continuously with point-in-time recovery for 35 days, replicated across two EU availability zones. Restore procedures are tested twice a year.
Sub-processors
Who else touches the data.
We keep the register short deliberately. Customers on the register's notification list receive at least 30 days' notice before a new sub-processor is engaged, with a right to object.
| Category | Purpose | Processing location |
|---|---|---|
| Cloud infrastructure | Hosting, storage and managed databases | Germany (Frankfurt), Ireland (Dublin) |
| Transactional email | Service notifications, alerts and password resets | European Union |
| Error monitoring | Application diagnostics and crash reporting | European Union |
| Support desk | Ticketing and support correspondence | European Union |
| Payment processing | Subscription billing and invoicing | European Union |
Named entities and current contact details are provided in the DPA pack. Categories shown here describe a fictional service.
Common questions
From security reviews.
These come up in almost every procurement process, so they are answered here rather than in a questionnaire six weeks later.
Request the full packCustomer data is stored and processed exclusively in the European Union, in data centres located in Germany and Ireland. Enterprise customers can pin data to a single member state where their own regulatory position requires it.
No customer content is transferred outside the European Economic Area in the ordinary course of the service. Where a sub-processor's support function could involve access from outside the EEA, that access is restricted, logged, and covered by standard contractual clauses; the current position for each sub-processor is set out in the register below.
Yes. Our standard DPA, incorporating the Article 28 requirements and the current standard contractual clauses, is available on request and can be executed before any data is loaded. Enterprise customers may negotiate amendments.
Lexoria operates an information security management system certified to ISO/IEC 27001:2022, covering the platform and the teams that build and operate it. The certificate and current statement of applicability are available under NDA.
An independent penetration test is commissioned at least annually and after any significant architectural change. A summary report is shared with customers on request; the full report is available to Enterprise customers under NDA.
Our incident procedure requires assessment against the notification thresholds without undue delay. Where Lexoria acts as processor, we notify affected controllers without undue delay after becoming aware, with the information needed for their own notification obligations.
You can export your data throughout the subscription and for 30 days afterwards. Following that window, customer content is deleted from production within 30 days and purged from backups as those backups age out, within a maximum of 90 days.
Yes. We complete customer security questionnaires, provide our standard documentation pack up front, and will join a call with your security or risk function. Enterprise agreements can include an audit right.
Reporting a vulnerability
Tell us, and we will not make it awkward.
If you believe you have found a security issue in Lexoria, write to security@info-lex.lt with enough detail to reproduce it. We acknowledge reports within two business days and will keep you updated until it is closed. We do not pursue researchers who act in good faith, stay within their own test account, and give us reasonable time before disclosing.
Book a demo
Send us your security questionnaire.
We would rather answer it before the commercial conversation than after. Most packs come back within three business days.
No card required EU-hosted DPA available on request