Enterprise-Grade Security

Security lawyers can trust

We understand that legal professionals handle sensitive matters. Security and privacy are foundational to everything we build.

Enterprise security standards

The security controls legal teams expect

SOC 2 Type II Certified

Annual third-party audits verify our security controls meet the highest industry standards.

End-to-End Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). AI keys encrypted with AES-256-GCM.

US-Based Infrastructure

All data stored in US data centers. No international data transfers.

Access Controls

Role-based access control (RBAC). SSO/SAML available for Enterprise plans.

Audit Logging

Complete audit trail of all user actions. Available on Firm and Enterprise plans.

Regular Backups

Automated daily backups with point-in-time recovery.

Data Privacy

Our privacy commitments

Clear, unambiguous promises about how we handle your data

We never train AI on your data

Your bill tracking data, search queries, and organization information are never used to train machine learning models.

BYOK AI keeps your queries private

When using AI features with your own API key, prompts and responses go directly to your chosen provider. We don't see or log them.

You own your data

Export anytime in CSV, JSON, or PDF. Delete anytime. We don't keep hidden copies.

Minimal data collection

We only collect data necessary to provide the service. No selling to third parties.

Transparent practices

Our privacy policy clearly explains what data we collect, why, and how long we keep it.

GDPR compliant

Data minimization, purpose limitation, and respect for data subject rights including deletion.

Data Ownership

Your data belongs to you

Your organization owns everything you create in LawSignals: categories, watchlists, reports, notes, and settings.

Export anytime

CSV, JSON, or PDF formats

Delete anytime

Complete deletion. No hidden copies.

No lock-in

Cancel anytime; data accessible for 30 days

What we store vs. what we don't

We store (encrypted):

  • Account information
  • Categories and keywords
  • Alert preferences
  • Generated reports

We never store:

  • AI prompts or responses
  • Your AI API keys in plain text
  • Client information
  • Search query logs

Important Disclaimer

LawSignals is not a law firm and does not provide legal advice. Information is for informational purposes only.

AI-generated content is a research aid only. AI outputs should be independently verified.

Legislative data is aggregated from official government sources. Always verify critical information against primary sources.

Questions about security?

Our team is happy to discuss security practices, share our SOC 2 report under NDA, or answer compliance questions.