LitigationOS
Security and deployment

Client facts never leave your perimeter.

Deployment that matches your risk posture, true data isolation rather than row filters, and a citation boundary that only abstracted proposition queries ever cross.

A wave of data points rising across a grid
Deployment

Deployment that matches your risk posture.

Default

Standard secure cloud

For most firms. Each firm’s data lives in its own separate database with its own user management: structurally walled off from every other customer, not filtered out of a shared pool by a query clause.

On request

Fully isolated, air-gapped deployment

On request, your firm receives Legawrite.AI as air-gapped legal AI: a self-contained deployment you can place inside a fully isolated environment, running against your own local, isolated model. No data leaves your walls. Built for firms, insurers and matters where “cloud” is not an acceptable answer.

Isolation and control

True data isolation, not row filters.

Ingestion and connectors

Every matter has its own dedicated, private ingestion address. If an address is ever compromised, regenerate it in one click and the old one goes dead instantly. Connectors to Google Drive, Dropbox and NetDocuments Early access reach only the folders and workspaces you select, and NetDocuments access follows the permissions your document management system already enforces.

The citation boundary

Matter documents, party names and client facts stay in the firm’s tenant. Only abstracted, citation-free proposition queries cross into the verified corpus. In the air-gapped deployment, nothing crosses at all.

isResponsive() makes zero vendor calls

The eDiscovery engine runs entirely on hardware you control and makes zero calls to any AI vendor’s API. There is nothing for anyone to subpoena from us, because we never have your documents.

Your model, inside your walls

In the air-gapped deployment the model is local and yours. Nothing is metered, and nothing leaves the environment you control.

Audit logging

Who did what, when, to which resource. Non-negotiable in legal technology for compliance and malpractice defense, and the raw material of the sealed record.

Attorney checkpoints

Nothing files itself. The attorney is the decision-maker of record, by design. The system never practices law.

Privilege and work product

What the recent decisions actually say.

The risk is not AI per se. The risk is careless disclosure and weak vendor terms.

Courts applying settled privilege and work-product doctrine to AI tools have drawn a line between a client independently using a consumer chatbot under terms that permit training and disclosure, and attorney-directed use of an enterprise or on-premises tool with contractual confidentiality. Attorney direction, enterprise-grade tools and contractual confidentiality protections are the three things a firm must be able to show. On-premises and fully local deployment presents the cleanest posture because it avoids third-party disclosure entirely.

Privilege triage

Three questions a law firm AI policy should ask about any AI system

  • Who processes the input, and under what terms?
  • Where does the data go, and is it used to train anything?
  • Is the use directed by counsel, and is the record of that direction kept?
ⓘNot legal advice. This material describes methods and published law for information. It is not a substitute for a lawyer’s judgment on a specific matter. Where it states law, it states the law as of the date shown.
Trust center

Compliance, controls and documents, in one place.

Legawrite.AI protects the security, availability and confidentiality of firm data. Here is where each framework stands, the 79 controls we operate, and the policies your security team can request.

Compliance

HIPAA badge
HIPAASelf-Attested
SOC 2 Type I badge
SOC 2 Type IIn Progress
ⓘDocumentation under NDA. Policies, attestations and audit reports are provided to customers and prospects under NDA. SOC 2 Type I is in progress, and the report will be listed under Resources once it is issued.
Resources

Policies your security review will ask for.

20 documented policies and charters. Request any of them, or the full set, and we will send them under NDA.

  • Information Security PolicyRequest
  • Access Control and Termination PolicyRequest
  • Incident Response PolicyRequest
  • Breach Notification PolicyRequest
  • Business Continuity and Disaster Recovery PlanRequest
  • Data Classification PolicyRequest
  • Change Management PolicyRequest
  • Network Security PolicyRequest
  • Baseline Hardening PolicyRequest
  • Vendor Management PolicyRequest
  • Risk Assessment and Treatment PolicyRequest
  • Personnel Security PolicyRequest
  • Acceptable Use PolicyRequest
  • HIPAA Internal Privacy PolicyRequest
  • PHI De-identification Policy and ProcedureRequest
  • Chief Information Security Officer PolicyRequest
  • Risk and Governance Executive Committee CharterRequest
  • IT Leadership Committee CharterRequest
  • Board of Directors CharterRequest
  • Company HandbookRequest
Security controls

79 controls across 21 categories.

Every control below is operating today. Select a control to read what it does.

Secure engineering and architecture

8

Isolation is structural, designed in, and reviewed before anything reaches production.

  • Per-firm database isolation

    Each firm's data lives in its own separate database with its own user management, walled off structurally rather than filtered out of a shared pool by a query clause.

  • The citation boundary

    Matter documents, party names and client facts stay in the firm's tenant. Only abstracted, citation-free proposition queries cross into the verified corpus.

  • Air-gapped deployment on request

    A self-contained deployment runs inside a fully isolated environment against the firm's own local model. In that mode, nothing crosses the boundary at all.

  • Zero vendor calls in isResponsive()

    The eDiscovery engine runs on hardware the firm controls and makes no calls to any AI vendor's API.

  • Environment separation

    Development, test and production environments are logically separated, and sensitive data is prohibited outside production.

  • Source code access controls

    Every source code change is logged and attributed, and repository access requires multi-factor authentication.

  • Source code change approval

    Changes are tested, peer reviewed and approved before they deploy to production.

  • Secure development procedures

    A secure development policy governs how systems are designed, built and maintained, including defined emergency change procedures.

Identification and authentication

10

Only verified people reach systems and firm data, and only with the access their role requires.

  • Multi-factor authentication

    Multi-factor authentication is required for all production platform access, which blocks credential-only attacks.

  • Production access management

    Production access is provisioned, changed and revoked under documented access control procedures.

  • Access control procedures

    Every access grant or change goes through a formal request and approval workflow with a recorded business justification.

  • Least-privilege production access

    Production permissions are held to the minimum necessary, limiting lateral movement if a credential is compromised.

  • Infrastructure authentication

    Unique credentials, SSH keys and multi-factor authentication are required for all production infrastructure.

  • Quarterly access reviews

    Quarterly reviews find and remove dormant accounts, excessive privileges and unauthorized access.

  • Password policy

    Password requirements for sensitive systems are documented and enforced.

  • Session timeout enforcement

    Sessions end automatically after inactivity so unattended systems are not left open.

  • Matter ingestion address rotation

    Every matter has its own private ingestion address. If one is ever exposed, it is regenerated in one click and the old address stops working immediately.

  • ePHI access authorization and monitoring

    Access to ePHI is authorized under supervision and monitored on an ongoing basis to prevent unauthorized use or disclosure.

Cryptographic protections

3

Firm data stays confidential in storage and on the wire.

  • Encryption at rest

    Sensitive databases are encrypted at rest with strong encryption, protecting data even if storage is compromised.

  • Encryption in transit

    Data in transit is encrypted with industry-standard protocols to prevent interception over public networks.

  • Production key management

    Production keys are restricted to authorized personnel, with formal procedures for rotation and storage.

Data classification and handling

3

Rules based on sensitivity govern how firm data is stored, moved, retained and destroyed.

  • Data classification and access control

    Sensitive data is classified and restricted to authorized personnel, with handling rules set by sensitivity level.

  • Data retention and deletion policy

    Retention periods and secure deletion methods are defined, so data is not kept beyond business need.

  • Firm data deletion at termination

    Firm data is deleted or anonymized after contract termination, leaving no residual exposure.

Continuous monitoring

3

Always-on visibility across systems, and a record of every action taken.

  • Audit logging

    Who did what, when, to which resource. The record supports compliance and malpractice defense, and it is the raw material of the sealed record.

  • Centralized log collection and monitoring

    Production logs are collected centrally to detect, investigate and respond to security events.

  • Login attempt monitoring

    Login attempts are logged and monitored for unauthorized or suspicious patterns.

Network security

3

Encrypted access paths, filtered traffic and continuous detection.

  • Secure connection requirements

    Authorized personnel reach production only through encrypted channels such as TLS or VPN.

  • Firewall rule management

    Firewall configuration is limited to authorized administrators, and every change is logged and reviewed.

  • Intrusion detection

    Network traffic is monitored continuously, and suspected threats alert security personnel.

Web security

1

Customer-facing systems are shielded from injection, fraud and abuse.

  • Web application firewall

    A web application firewall filters malicious traffic, with rules reviewed by management every year.

Vulnerability and patch management

3

Gaps are found and closed before they can be exploited.

  • Vulnerability scanning and remediation

    External-facing systems are scanned regularly, and high-risk findings are remediated on documented timelines.

  • Patch management

    Patches are applied promptly with automatic updates and routine compliance checks.

  • Penetration testing

    Annual penetration testing identifies vulnerabilities, and high-risk findings are tracked to remediation.

Endpoint security

4

Laptops, workstations and mobile devices are managed and hardened.

  • Anti-malware protection

    Anti-malware and automated scanning protect production infrastructure on a scheduled basis.

  • Removable media controls

    Sensitive data is prohibited on removable media, with rare exceptions requiring encryption and documented approval.

  • Mobile device management

    Device management enforces security policy on all endpoints, with remote wipe for lost devices.

  • Secure workstation configuration

    Workstations are configured to prevent unauthorized access to client data and ePHI.

Configuration management

1

Documented baselines keep insecure configuration out of production.

  • Baseline configuration management

    Production systems are hardened to documented baselines and deployed through infrastructure as code for consistent rollout and rollback.

Business continuity and disaster recovery

6

Tested recovery plans keep the service running and data intact through disruption.

  • Business continuity and disaster recovery plan

    Continuity and recovery plans are documented, tested every year and revised based on results.

  • Emergency operations continuity

    Communication, responsibilities and escalation paths are defined in advance to keep operations running during a disruption.

  • Backup and restore testing

    Backups run on a schedule, and restore tests confirm exact copies can be recovered after data loss.

  • Emergency access procedures

    Documented procedures keep firm data and ePHI available during a disruption without weakening security controls.

  • Data preservation during system changes

    Complete, retrievable copies of data are preserved before any system is moved, replaced or decommissioned.

  • Capacity and performance monitoring

    Automated monitoring tracks capacity and performance against thresholds and alerts before availability is affected.

Incident response

4

Practiced procedures for containment and clear communication.

  • Security incident logging

    Security incidents are logged, escalated to leadership and analyzed for root cause.

  • Incident response procedures

    Incident response procedures are documented, tested every year and refined from lessons learned.

  • HIPAA incident response policy

    HIPAA incident response obligations are documented in policy and acknowledged by all personnel.

  • ePHI breach notification timeline

    Business associates must report ePHI breaches within 60 days of discovery.

Governance

7

Named accountability and written policy, reviewed on a fixed cadence.

  • Information security policies

    Security policies and procedures are documented and reviewed every year.

  • Security roles and responsibilities

    Security roles are documented and acknowledged by all personnel.

  • Information security officer designation

    Designated security personnel own and oversee the information security program.

  • IT leadership committee meetings

    IT leadership meets monthly to review security activity against organizational commitments.

  • Attorney checkpoints

    Nothing files itself. The attorney is the decision-maker of record, by design, and the system never practices law.

  • Whistleblower mechanism

    Anonymous channels let personnel report security concerns or fraud without fear of retaliation.

  • Disciplinary process

    Violations of security policy lead to disciplinary action, up to termination.

Compliance

3

Regulatory obligations are written down, owned and retained.

  • HIPAA Security Officer designation

    A designated HIPAA Security Officer owns the security policies, with the role and contact details documented.

  • HIPAA Security Rule policy acknowledgment

    HIPAA Security Rule obligations are written into policy and acknowledged by everyone who handles ePHI.

  • HIPAA documentation retention

    HIPAA compliance documentation is retained securely for six years from creation.

Risk management

2

Threats are identified, ranked and treated before they become incidents.

  • Annual risk assessment

    An annual risk assessment addresses threats to the confidentiality, integrity and availability of firm data.

  • Security and privacy risk management

    Documented processes govern how risks are identified, assessed, treated and reviewed.

Human resources security

4

Screening, agreements and prompt offboarding for everyone with access.

  • Employee background checks

    Candidates are screened before they receive access to systems or sensitive information.

  • Employee confidentiality agreements

    Employees sign confidentiality agreements covering company and firm data.

  • Contractor confidentiality agreements

    Contractors sign confidentiality agreements before receiving access to sensitive data.

  • Termination access revocation

    A termination checklist revokes access, recovers credentials and returns assets within defined timeframes.

Security awareness and training

2

Everyone is trained at hire and every year after.

  • Security awareness training

    All personnel complete security awareness training at hire and annually.

  • ePHI privacy training

    Personnel with ePHI access receive additional HIPAA privacy training at hire and annually.

Third-party management

6

Vendors and subprocessors are held to the same standard we are.

  • Vendor management program

    Prospective and existing vendors are evaluated every year against documented security requirements.

  • Business associate agreements

    Business associate agreements bind subcontractors to HIPAA privacy and security requirements.

  • Business associate safeguards and reporting

    Business associate agreements require appropriate safeguards and timely incident and breach reporting.

  • Contractor compliance flow-down

    Subcontractors must flow compliance requirements down to their own processors.

  • Vendor confidentiality and privacy agreements

    Vendor agreements carry confidentiality and privacy terms fitted to the services provided.

  • Contractual security commitments

    Security commitments are written into the master services agreement and terms of service.

Change management

2

Material changes are communicated before they land.

  • Material system change communication

    Changes that affect security or availability are communicated to personnel with timing and expected impact.

  • Firm notification of major changes

    Major changes that affect availability or functionality are communicated to firms before implementation.

Asset management

2

Every production asset is known, owned and retired safely.

  • Technology asset inventory

    All production assets are inventoried, classified and assigned an owner.

  • Secure media disposal

    Media that held sensitive data is purged or destroyed so nothing is recoverable from retired equipment.

Physical and environmental security

2

Facilities and hosting are protected against physical access.

  • Visitor management policy

    Visitors sign in, wear badges and are escorted in secure areas.

  • Cloud provider physical access review

    Hosting providers' physical access controls are validated in an annual vendor review.

Deployment is a purchase gate. Let’s clear it.

Tell us where your data is allowed to live and we will show you the deployment that fits.