Security & Compliance Built for Legal Data

Legalica protects the most sensitive professional data — client confidences, litigation strategies, corporate structures, and regulatory files — with defense-in-depth security, EU data residency, and an honest, published compliance posture.

Key features

Legalica Defense-in-Depth Security Architecture
Defense-in-Depth Security
  • TLS 1.3 in transit and AES-256 at rest for all platform data. Customer-managed encryption keys, private registry tunneling, and granular access controls protect client confidentiality.

  • Zero-Data Retention AI processing — your queries, documents, and registry searches are never used to train AI models. EU-hosted primary inference in Frankfurt (europe-west3).

Explore Security Details
Legalica Regulatory Certifications and Compliance
Regulatory Certifications
  • GDPR-aligned data processing on Google Cloud infrastructure certified under SOC 2 Type II and ISO 27001. PCI-DSS-compliant payments via our Merchant of Record. Full audit trails and subprocessor governance.

  • Google Cloud Platform infrastructure in europe-west3 (Frankfurt) with regional redundancy, Cloud Armor DDoS protection, and Firebase Authentication with MFA support.

View Compliance Framework

Security Architecture Overview

Legalica operates on a shared responsibility model with Google Cloud Platform as the infrastructure provider. Legalica controls the application layer, business logic, encryption key management, security rules, and AI orchestration. Google controls physical servers, data centers, network infrastructure, and the database engine.

LayerControls
ApplicationRole-based access, audit logging, input validation, prompt injection defenses, secure session management
DataAES-256 encryption at rest, customer-managed keys, EU-only storage for structured data, encrypted backups
NetworkTLS 1.3 for all connections, Cloud Armor DDoS protection, private registry tunneling for external searches
IdentityFirebase Authentication with secure password hashing, OAuth 2.0, multi-factor authentication (TOTP/SMS)
InfrastructureGoogle Cloud europe-west3 (Frankfurt), regional redundancy, automated patching — SOC 2 / ISO 27001 certified at the provider level
AI / LLMZero-Data Retention contracts, no model training on user data, pre-transmission anonymization for cross-border inference

Zero-Data Retention (ZDR) Promise

Legalica's AI processing is governed by contractual Zero-Data Retention terms with all LLM providers:

  • User queries are processed in transient memory only
  • No query data is retained by LLM providers after response generation
  • No user data is used for model training or fine-tuning
  • For Tier 2 providers, data undergoes pre-transmission anonymization to remove identifiable Personal Data

Data Residency & Sovereignty

All customer data is stored in the European Union by default. Firestore databases, Cloud Storage buckets, and authentication data are configured in europe-west3 (Frankfurt). Cross-region backup replication to europe-west2 (London) is available for enterprise customers.

Data transfer outside the EU occurs only for specific AI inference providers under Standard Contractual Clauses (SCC 2021/914) and with Zero-Data Retention guarantees. Drive files remain in the user's chosen Google region.

Compliance Frameworks

FrameworkStatusApplication
GDPRFully implementedData processing, subject rights, DPO, records of processing
SOC 2 Type IIInfrastructure certified via Google Cloud; Legalica's own audit program planned (see Trust Center)Security, availability, confidentiality
ISO 27001Inherited from Google Cloud infrastructure (Google's certification, not Legalica's)Information security management
PCI-DSSVia Creem, our Merchant of RecordPayment card processing
EU AI ActCompliance program activeTransparency, human oversight, risk management

Identity & Access Management

  • Authentication: Secure password hashing, OAuth 2.0 with Google/Microsoft, email verification, brute-force protection
  • Multi-Factor Authentication: TOTP and SMS support for all accounts
  • Authorization: Workspace-level role-based permissions for documents, matters, KYC data, and registry searches
  • Audit Trail: Every document access, edit, export, and AI query is logged with timestamp and user identity

Incident Response

In the event of a security incident, Legalica follows a joint detection and escalation process with Google Cloud. Affected customers are notified without undue delay, targeting 36 hours from provider notification, as published in the Trust Center.

AI Ethics & Responsible Use

Legalica maintains an AI Ethics Committee that oversees bias detection, human oversight, and compliance with the EU AI Act. All AI-generated content is labeled as such and requires human review before legal use. Read our full AI Ethics Policy.

Contact

For security questions, incident reports, or compliance inquiries: security@legalica.app

For legal and data protection questions: legal@legalica.app

Legalica's security and compliance documentation provides informational guidance, not legal advice. Always consult a qualified attorney or compliance professional licensed in the relevant jurisdiction before making decisions. Laws vary by jurisdiction and are subject to change.