Security for legal diligence
Lexona is designed for high-trust legal environments, with selected UK core application hosting, practice-scoped access, practitioner review, and evidence-led assurance material.
Assurance Roadmap & Status
Five security and governance pillars
The core production application stack is selected for deployment on a UK-located IONOS VPS. Database, document, vector, model-provider, backup, support, and integration locations remain governed by the configured downstream services and their agreements.
- IONOS UK VPS selected as the core application compute target
- Customer legal practice is controller for client and matter data
- YR Legal Services Ltd acts as processor for customer matter data
- Downstream locations and transfer terms recorded per provider agreement
Lexona uses API-based model services only where the executed provider agreement and production account configuration prohibit training on customer content and require zero retention of client and matter prompts and outputs.
- No model training on client or matter data
- Zero-retention terms and settings verified before use
- Production account settings verified against the executed agreement
- API-only model integration
- Provider terms and subprocessors tracked in the draft security pack
Draft processor obligations, data-handling responsibilities, and transfer materials are available for procurement and legal review.
- Draft Article 28 processor terms available for legal review
- DPIA support material available for practice review
- Data-subject request assistance responsibilities set out in the draft DPA
- Controller and processor responsibilities stated consistently
- Draft processor breach notice uses a without-undue-delay standard
Lexona uses explicit practice scoping, authenticated service boundaries, practice-specific vector namespaces, and Postgres RLS as defence in depth. Production RLS activation is a mandatory deployment gate.
- Explicit practice scoping at API and data-access layers
- Practice-specific vector database namespaces
- Role-based practice access controls
- Production RLS role verified before customer onboarding
Registered agent runs create audit records, and supported workflows retain source, actor, timestamp, and practitioner-review events. Provenance and export coverage vary by workflow and must be verified for the contracted use case.
- At least one audit record for registered agent runs with practice context
- Source provenance in supported conveyancing workflows
- Practitioner review controls for supported release workflows
- Workflow-specific audit and export coverage documented during diligence
Infrastructure security controls
Request our security pack
Request draft DPA and DPIA materials, the subprocessor and transfer registers, certification roadmap, control inventory, and current penetration-test status.
Request Security Pack