Skip to main content
    Lexona LogoLexona
    • Features
    • How it Works
    • Security
    • About
    Sign inBook a Demo
    Security & Assurance

    Security for legal diligence

    Lexona is designed for high-trust legal environments, with selected UK core application hosting, practice-scoped access, practitioner review, and evidence-led assurance material.

    Assurance Status

    Assurance Roadmap & Status

    Draft
    UK GDPR & EU GDPR processor documentation
    DPA and assurance documents require legal approval
    Planned
    UK core application compute — IONOS UK VPS
    Downstream locations remain provider- and agreement-specific
    Planned
    Cyber Essentials
    Not certified
    Planned
    ISO 27001
    Future ISMS and gap assessment; not certified
    Planned
    SRA guidance control mapping
    Professional-use guidance, not certification or endorsement
    Core Pillars

    Five security and governance pillars

    Pillar 1
    UK Core Application Hosting

    The core production application stack is selected for deployment on a UK-located IONOS VPS. Database, document, vector, model-provider, backup, support, and integration locations remain governed by the configured downstream services and their agreements.

    • IONOS UK VPS selected as the core application compute target
    • Customer legal practice is controller for client and matter data
    • YR Legal Services Ltd acts as processor for customer matter data
    • Downstream locations and transfer terms recorded per provider agreement
    Pillar 2
    Downstream Model Controls

    Lexona uses API-based model services only where the executed provider agreement and production account configuration prohibit training on customer content and require zero retention of client and matter prompts and outputs.

    • No model training on client or matter data
    • Zero-retention terms and settings verified before use
    • Production account settings verified against the executed agreement
    • API-only model integration
    • Provider terms and subprocessors tracked in the draft security pack
    Pillar 3
    UK GDPR & EU GDPR Controls

    Draft processor obligations, data-handling responsibilities, and transfer materials are available for procurement and legal review.

    • Draft Article 28 processor terms available for legal review
    • DPIA support material available for practice review
    • Data-subject request assistance responsibilities set out in the draft DPA
    • Controller and processor responsibilities stated consistently
    • Draft processor breach notice uses a without-undue-delay standard
    Pillar 4
    Practice Data Isolation

    Lexona uses explicit practice scoping, authenticated service boundaries, practice-specific vector namespaces, and Postgres RLS as defence in depth. Production RLS activation is a mandatory deployment gate.

    • Explicit practice scoping at API and data-access layers
    • Practice-specific vector database namespaces
    • Role-based practice access controls
    • Production RLS role verified before customer onboarding
    Pillar 5
    Audit and Review Controls

    Registered agent runs create audit records, and supported workflows retain source, actor, timestamp, and practitioner-review events. Provenance and export coverage vary by workflow and must be verified for the contracted use case.

    • At least one audit record for registered agent runs with practice context
    • Source provenance in supported conveyancing workflows
    • Practitioner review controls for supported release workflows
    • Workflow-specific audit and export coverage documented during diligence
    Technical Architecture

    Infrastructure security controls

    HTTPS and Service Boundaries
    HTTPS terminates at Cloudflare's edge; production services are reached only through an outbound-only Cloudflare Tunnel with no inbound web ports. LangGraph and MCP remain internal-only; no certificate pinning is implemented.
    Encryption Architecture
    At-rest protection is provider-managed under downstream agreements. Customer-managed keys and managed KMS/HSM options are a future architecture review.
    UK Host Network Controls
    The IONOS production runbook applies host firewalling, SSH hardening, fail2ban, automatic security updates, and restricted public ports.
    MFA Available
    Supabase TOTP MFA and practice security policies are implemented. SAML/OIDC enterprise SSO is not currently available and is on the roadmap.
    Monitoring Deployment Gate
    Health checks, structured logs, correlation IDs, OTel instrumentation, and ops alerts exist; live production delivery must be verified during deployment.
    Pen-test Status
    No independent production penetration test has been completed. Testing is planned after deployment, with status available in the security pack.
    Security Documentation

    Request our security pack

    Request draft DPA and DPIA materials, the subprocessor and transfer registers, certification roadmap, control inventory, and current penetration-test status.

    Request Security Pack
    Lexona LogoLexona

    Evidence-backed AI workflow software for UK legal professionals. Drafts stay source-linked, supervised, and reviewable.

    Lexona AI: The technology division of YR Legal Services Ltd
    Company No. 16885532 (England & Wales)

    Product
    • Features
    • Security
    • How it Works
    • Enterprise
    Company
    • About Us
    • Careers
    • Contact
    • Blog
    Legal
    • Privacy Policy
    • Terms of Service
    • Cookie Policy
    Trust
    • Security
    • Data Processing
    • Request Information
    • Sub-processors
    © 2026 YR Legal Services Ltd. All rights reserved.
    PrivacyTermsCookies