Security & Compliance Built for Legal Data
Legalica protects the most sensitive professional data — client confidences, litigation strategies, corporate structures, and regulatory files — with defense-in-depth security, EU data residency, and an honest, published compliance posture.
Key features

TLS 1.3 in transit and AES-256 at rest for all platform data. Customer-managed encryption keys, private registry tunneling, and granular access controls protect client confidentiality.
Zero-Data Retention AI processing — your queries, documents, and registry searches are never used to train AI models. EU-hosted primary inference in Frankfurt (europe-west3).



GDPR-aligned data processing on Google Cloud infrastructure certified under SOC 2 Type II and ISO 27001. PCI-DSS-compliant payments via our Merchant of Record. Full audit trails and subprocessor governance.
Google Cloud Platform infrastructure in europe-west3 (Frankfurt) with regional redundancy, Cloud Armor DDoS protection, and Firebase Authentication with MFA support.
Security Architecture Overview
Legalica operates on a shared responsibility model with Google Cloud Platform as the infrastructure provider. Legalica controls the application layer, business logic, encryption key management, security rules, and AI orchestration. Google controls physical servers, data centers, network infrastructure, and the database engine.
| Layer | Controls |
|---|---|
| Application | Role-based access, audit logging, input validation, prompt injection defenses, secure session management |
| Data | AES-256 encryption at rest, customer-managed keys, EU-only storage for structured data, encrypted backups |
| Network | TLS 1.3 for all connections, Cloud Armor DDoS protection, private registry tunneling for external searches |
| Identity | Firebase Authentication with secure password hashing, OAuth 2.0, multi-factor authentication (TOTP/SMS) |
| Infrastructure | Google Cloud europe-west3 (Frankfurt), regional redundancy, automated patching — SOC 2 / ISO 27001 certified at the provider level |
| AI / LLM | Zero-Data Retention contracts, no model training on user data, pre-transmission anonymization for cross-border inference |
Zero-Data Retention (ZDR) Promise
Legalica's AI processing is governed by contractual Zero-Data Retention terms with all LLM providers:
- User queries are processed in transient memory only
- No query data is retained by LLM providers after response generation
- No user data is used for model training or fine-tuning
- For Tier 2 providers, data undergoes pre-transmission anonymization to remove identifiable Personal Data
Data Residency & Sovereignty
All customer data is stored in the European Union by default. Firestore databases, Cloud Storage buckets, and authentication data are configured in europe-west3 (Frankfurt). Cross-region backup replication to europe-west2 (London) is available for enterprise customers.
Data transfer outside the EU occurs only for specific AI inference providers under Standard Contractual Clauses (SCC 2021/914) and with Zero-Data Retention guarantees. Drive files remain in the user's chosen Google region.
Compliance Frameworks
| Framework | Status | Application |
|---|---|---|
| GDPR | Fully implemented | Data processing, subject rights, DPO, records of processing |
| SOC 2 Type II | Infrastructure certified via Google Cloud; Legalica's own audit program planned (see Trust Center) | Security, availability, confidentiality |
| ISO 27001 | Inherited from Google Cloud infrastructure (Google's certification, not Legalica's) | Information security management |
| PCI-DSS | Via Creem, our Merchant of Record | Payment card processing |
| EU AI Act | Compliance program active | Transparency, human oversight, risk management |
Identity & Access Management
- Authentication: Secure password hashing, OAuth 2.0 with Google/Microsoft, email verification, brute-force protection
- Multi-Factor Authentication: TOTP and SMS support for all accounts
- Authorization: Workspace-level role-based permissions for documents, matters, KYC data, and registry searches
- Audit Trail: Every document access, edit, export, and AI query is logged with timestamp and user identity
Incident Response
In the event of a security incident, Legalica follows a joint detection and escalation process with Google Cloud. Affected customers are notified without undue delay, targeting 36 hours from provider notification, as published in the Trust Center.
AI Ethics & Responsible Use
Legalica maintains an AI Ethics Committee that oversees bias detection, human oversight, and compliance with the EU AI Act. All AI-generated content is labeled as such and requires human review before legal use. Read our full AI Ethics Policy.
Contact
For security questions, incident reports, or compliance inquiries: security@legalica.app
For legal and data protection questions: legal@legalica.app
Legalica's security and compliance documentation provides informational guidance, not legal advice. Always consult a qualified attorney or compliance professional licensed in the relevant jurisdiction before making decisions. Laws vary by jurisdiction and are subject to change.