SECURITY OVERVIEW
Table of Contents
- Our Security Approach
- Encryption
- Identity and Access Management
- Application Security
- AI Data Protection
- Infrastructure Security
- Monitoring and Logging
- Backups and Data Recovery
- Incident Response and Breach Notification
- Compliance Posture — What We Do and Do Not Claim
- Responsible Disclosure
- Your Responsibilities and Contact
1. OUR SECURITY APPROACH
Legalica OÜ ("Legalica", "we") is a software company. We do not own or operate physical servers or data centers. The Platform runs entirely on Google Cloud Platform (GCP) infrastructure, and our security model is a shared responsibility model: Google secures the physical infrastructure, network, and managed services; Legalica secures the application layer — our code, configuration, access rules, and data flows.
This page describes the security measures we actually operate today. We deliberately avoid marketing superlatives. Where a control is planned but not yet implemented, we say so explicitly.
2. ENCRYPTION
| Layer | Measure |
|---|---|
| In transit | All connections between your browser and the Platform, and between the Platform and third-party AI/API endpoints, use HTTPS with TLS 1.3. |
| At rest | Data stored in Cloud Firestore and Cloud Storage is encrypted at rest by Google Cloud using AES-256. Encryption keys are managed by Google Cloud Key Management Service (Cloud KMS). |
| Passwords | User passwords are never stored in plain text. Firebase Authentication applies strong one-way hashing (scrypt-based) to credentials. |
Note: we do not currently operate customer-managed encryption keys (CMEK) or end-to-end encryption of workspace content. Content you upload is encrypted at rest by the infrastructure provider as described above, and is accessible to the application layer in order to provide the service (e.g., AI analysis of your documents at your request).
3. IDENTITY AND ACCESS MANAGEMENT
- Authentication: handled by Firebase Authentication, supporting email/password (with email verification) and OAuth 2.0 sign-in via Google.
- Brute-force protection: Firebase Authentication applies rate limiting and temporary lockouts on repeated failed sign-in attempts.
- Internal access: access to production systems and customer data is restricted to a minimal number of authorized persons on a need-to-know basis, protected by strong authentication.
- Session security: authenticated sessions use short-lived tokens issued by Firebase; signing out invalidates the session token.
You are responsible for keeping your credentials confidential and for signing out on shared devices. See Section 12.
4. APPLICATION SECURITY
- Database access rules: Cloud Firestore and Cloud Storage are protected by security rules that enforce per-user data isolation — one authenticated user cannot read another user's workspace, documents, or case data.
- Server-side logic: sensitive operations (payments, AI orchestration, registry queries) execute in server-side Cloud Functions; secrets and API keys are never embedded in client-side code.
- Least privilege: service accounts and API credentials are scoped to the minimum permissions required for their function.
- Dependency management: third-party libraries are tracked and updated; known-vulnerability scanning is part of our development workflow.
5. AI DATA PROTECTION
When you use AI features, your prompt and relevant context are sent to a third-party large language model (LLM) provider over an encrypted API connection. The protective measures for this data flow are:
- Zero data retention (ZDR): LLM providers are engaged under API terms that do not retain your prompts or outputs after the response is generated (transient processing).
- No training on your data: our API agreements with LLM providers exclude the use of your content for model training or fine-tuning.
- Cascade routing: if the primary provider (Google Vertex AI, EU region) is unavailable, requests fall back to secondary providers (Moonshot AI, Groq) under equivalent no-retention/no-training terms, and finally to locally executed models that involve no external transfer at all. Details and locations are listed on the Subprocessors and Infrastructure pages.
- Data minimization: only the context necessary to answer your query is transmitted to the AI provider — not your entire workspace.
6. INFRASTRUCTURE SECURITY
Physical and network security are provided by Google Cloud and include: ISO/IEC 27001-certified data center operations, 24/7 physical security, redundant power and networking, native DDoS absorption at Google's network edge, and managed patching of the underlying platform. These are Google Cloud's certifications and controls, not Legalica's — see Section 10.
Data at rest is located in the European Union (europe-west3 — Frankfurt). Full architecture details, including the exact data-flow diagram and the liability split between Legalica and infrastructure providers, are documented on the Infrastructure page.
7. MONITORING AND LOGGING
We use Google Cloud Monitoring and Firebase diagnostics to track platform availability, error rates, and anomalous behavior. Application logs are used for security investigation and service reliability. Access to logs is restricted as described in Section 3, and log content is treated as confidential operational data.
8. BACKUPS AND DATA RECOVERY
We believe you deserve an honest answer here:
- Today: Cloud Firestore provides native multi-zone redundancy within the Frankfurt region, protecting against hardware and zone failures. On-demand snapshots can be initiated manually via the Firebase Console.
- Not yet implemented: an automated scheduled backup to a second region. We state this openly because documents describing your legal matters are important. We recommend that you export and keep local copies of critical documents — you can download your data at any time.
- Deletion: when you delete content or your account, data is removed from active systems. Residual copies may persist in provider-managed infrastructure for a limited period consistent with Google Cloud's deletion lifecycle.
9. INCIDENT RESPONSE AND BREACH NOTIFICATION
If we become aware of a personal data breach, we act in accordance with the GDPR and the Estonian Personal Data Protection Act (IKS):
- Supervisory authority: we notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) without undue delay and, where feasible, within 72 hours of becoming aware of the breach (GDPR Art. 33), unless the breach is unlikely to result in a risk to your rights and freedoms.
- Affected users: where the breach is likely to result in a high risk to your rights and freedoms, we inform affected users without undue delay in clear and plain language (GDPR Art. 34).
- Documentation: all breaches — including those not notified — are documented in an internal register (facts, effects, remedial action), as required by GDPR Art. 33(5).
- Provider incidents: for incidents originating with Google Cloud or an LLM provider, we rely on their incident notifications and assess impact on Legalica users before notifying you.
10. COMPLIANCE POSTURE — WHAT WE DO AND DO NOT CLAIM
Transparency matters more to us than badges. The table below states our position precisely:
| Item | Status |
|---|---|
| SOC 2 / ISO 27001 certification of Legalica itself | Not held. We are an early-stage company and do not claim independent certifications we do not have. |
| Infrastructure provider certifications (Google Cloud: ISO 27001, SOC 2/3) | Held by Google and inherited by us at the infrastructure layer only. |
| HIPAA compliance | Not claimed. The Platform is not designed for US regulated health data; do not upload PHI. |
| GDPR compliance program | Active — see the GDPR Commitment page for controller/processor roles, rights handling, and transfer mechanisms. |
| EU AI Act readiness | Active — users are informed that they interact with an AI system, and exported AI-generated documents carry an AI-content notice (Art. 50); see AI Ethics. |
| Independent penetration test | Planned; not yet performed. This page will be updated when it is completed. |
If your organization requires a specific certification or completed assessment before adoption, contact us — we will tell you exactly where we stand rather than oversell.
11. RESPONSIBLE DISCLOSURE
If you believe you have found a security vulnerability in the Platform, please report it to hq@legalica.app with the subject line "Security Report". We ask that you:
- give us reasonable time to investigate and remediate before any public disclosure;
- do not access, modify, or delete other users' data while testing;
- do not perform denial-of-service testing or social engineering against our users or staff.
We will acknowledge receipt of good-faith reports, investigate promptly, and keep you informed of remediation. We do not currently operate a paid bug-bounty program.
12. YOUR RESPONSIBILITIES AND CONTACT
Security is shared. You can help protect your account by:
- using a strong, unique password and keeping it confidential;
- keeping your browser and operating system up to date;
- being cautious with links and attachments claiming to come from Legalica — we will never ask for your password by email;
- exporting and retaining local copies of critical documents (see Section 8).
For security questions or reports, and for privacy-related requests: