Information Security Policy
Last updated: 14 September 2026 · Version 1.0
This policy sets out how YR Legal Services Ltd protects the information entrusted to Lexona.AI, across the lexona.ai website and the Lexona platform, and the rules our people and systems follow.
1. Purpose and scope
The policy applies to all information YR Legal Services Ltd processes for Lexona.AI: the Client and Matter Data that legal practices put into the platform, which we process on their behalf, and the personal and business information we control ourselves. It covers the systems that run the website and the platform, and everyone who works on them or has access to them.
2. Responsibilities
- A named owner at YR Legal Services Ltd is accountable for this policy, for security risk decisions and for managing security incidents.
- Everyone with access to Lexona systems or data follows this policy and reports any suspected security issue straight away.
- Security questions and reports go to security@lexona.ai.
3. Protecting client and matter data
- Client and Matter Data is processed only to provide the service to the customer practice and as it instructs.
- Lexona does not use Client or Matter Data to train AI models.
- Each practice's data is kept separate, and access is scoped to the practice a user belongs to.
- Core application compute is hosted in the EU. Database, authentication, document storage and vector search services are hosted in the United Kingdom.
- After a customer agreement ends, Client and Matter Data is deleted, normally within 30 days, as our Privacy Policy and the customer's agreement describe.
4. Access control
- Access follows least privilege: people and services get only the access their role needs.
- Platform access is role-based and scoped to the user's practice, and practice administrators manage their own users.
- Access to production systems is limited to named personnel who need it, and is removed when it is no longer needed.
- Automated tests of cross-practice access run in continuous integration on application changes.
5. Authentication
- Passwords are handled by our authentication service and are never stored in plain text.
- Multi-factor authentication is available to every platform user, and enforcement for administrative accounts is being rolled out.
- Enterprise single sign-on is on our roadmap.
6. Encryption and secrets
- Connections to the website and the platform use HTTPS (TLS).
- Data at rest is protected by the encryption controls our infrastructure and data-service providers apply, where applicable.
- Secrets are kept out of source code and restricted to the systems that need them.
7. Secure development and change
- Application changes are reviewed and run through automated checks, including authentication, access-control and cross-practice tests, before they are merged.
- Automated scanning checks changes for exposed secrets, and dependencies are audited for known vulnerabilities every week.
- Input from outside the system is validated, and user content is escaped when it is displayed.
- Development and production run as separate environments with separate credentials.
8. Operations and monitoring
- Internal services are not exposed directly to the internet, and public traffic reaches the platform over HTTPS.
- Production services are health-checked automatically.
- Audit records are kept for AI runs and approval events, and credentials must never be written to logs.
- Security updates to frameworks and dependencies are applied through the change process in section 7.
9. AI systems
- AI outputs are drafts. A practitioner reviews and approves them before they can be exported.
- Outputs are linked to the source documents behind them, so they can be checked.
- AI models are used through provider APIs. Where configured and contractually available, model providers are used with enterprise privacy controls designed to limit provider retention and model training.
- Lexona does not make decisions about individuals by automated means alone.
10. Service providers
- We keep a register of the service providers that process personal data for us, recording what each one receives.
- Providers are reviewed before they process personal data, and again when their service or terms change.
- Customers and prospective customers can request the list of subprocessors through a security pack request.
11. Third-party platform integrations
Connections to other platforms follow these rules. Third-party integrations are subject to provider approval, API availability, applicable permissions and the terms of the relevant platform.
- A firm connects a platform by authorising Lexona through that platform's own sign-in.
- Lexona acts within the permissions the firm and its users grant.
- Files imported from a connected document-storage account are copied into the practice's workspace so they can be processed, and are protected like uploaded documents.
- Practice-management integrations, starting with the proposed LEAP PMS integration, are being designed to read platform data when a user runs a workflow, without syncing or keeping copies, and to save outputs back only after a practitioner approves them.
12. Security incidents
- Anyone can report a suspected security incident to security@lexona.ai.
- Our incident owner assesses each report, contains the issue, investigates the cause and records what was done.
- Customers affected by an incident involving their data are told without undue delay, as their agreements set out.
- We learn from each incident and update our controls where needed.
13. Reporting a vulnerability
If you believe you have found a security vulnerability in the Lexona website or platform, email security@lexona.ai with a description, the steps to reproduce it, the affected address or feature, and how to contact you. Our reporting details are also published in security.txt.
- Please do not access, change or delete data that is not yours, or degrade the service for others.
- Please give us a reasonable opportunity to fix the issue before disclosing it publicly.
- We aim to acknowledge reports as soon as practicable and will keep you updated on our response.
14. Business continuity
- Our services are defined in version-controlled configuration, so they can be rebuilt.
- A database backup is taken before every production deployment.
- Recovery arrangements are reviewed as part of our assurance programme.
15. Assurance and review
Our assurance programme is progressing: Cyber Essentials certification, ISO 27001 and independent penetration testing are the next milestones on our roadmap. Our Security page shows the current status of each.
This policy is reviewed at least once a year, and whenever our systems, services or risks change significantly. Questions about it go to security@lexona.ai.