Built for confidentiality from day one.
IP firms hold their clients’ most valuable unpublished information. LeadLex is designed so that adopting AI does not widen the firm’s risk surface.
EU-hosted, Frankfurt · GDPR with a DPA per firm · No model training · A partner approves every send

Six controls, and what each one is worth. Enforced in the product, or held by contract — and which is which.
| Control | What it means in the product | Assurance |
|---|---|---|
| Isolated per firm | Every firm runs its own Lexi instance — dedicated infrastructure, its own memory, its own credentials. Nothing is shared between firms. | Enforced in product |
| EU data residency | Stored and processed in Frankfurt, with no replication outside the EU. Encrypted in transit on TLS 1.2+ and at rest, including backups. | Enforced in product |
| Approval before every send | Drafts queue in the AI Inbox. No email, message or invite leaves the firm until a partner has read it and released it. | Enforced in product |
| Conflict walls | Any contact, deal or matter can be walled off entirely, so a conflict or a privileged matter never enters Lexi’s context in the first place. | Enforced in product |
| Append-only audit trail | Every extraction, draft and sent action is logged with its source and its approver. Records cannot be edited or removed. | Enforced in product |
| No model training | Your data is never used to train any AI model — the providers’ commercial terms, not best-effort. Prompts are logged briefly by the provider for abuse detection only, and never enter a training set. | Contractual |
Enforced in product means the control is implemented in LeadLex and cannot be turned off by a user. Contractual means it is governed by an agreement with a third party rather than by our code. We separate the two because the distinction is the one your risk team is trying to establish, and it is the one most vendors leave blurred.
Built on certified infrastructure, hosted in the EU, and audited on a schedule we publish — including what is still in progress.
ISO 27001
Our infrastructure is ISO 27001 certified. LeadLex’s own certification audit is in progress.
Infrastructure certifiedSOC 2 Type 2
Our platform provider is SOC 2 Type 2 audited. LeadLex’s own report is in progress.
Provider auditedGDPR
A data processing agreement is signed with every firm, with a documented lawful basis for each processing activity.
DPA per firmEU hosting
Frankfurt, Germany. Data is not replicated outside the European Union at any point.
Frankfurt · Germany
Who else touches the data, and who at the firm can see what.
A current sub-processor list is maintained for every firm under the DPA, and material changes are notified in advance.
Supabase, EU region
Database, authentication and storage, on ISO 27001 and SOC 2 Type 2 certified infrastructure.
AI model providers
Inference only. No training on customer data under the providers’ commercial terms.
Email and calendar providers
Microsoft and Google, connected by the firm through OAuth with scoped permissions it can revoke.
Role-based access
Partner, fee-earner and business-services roles, with separate visibility on accounts and pipelines.
SSO and MFA
Microsoft and Google SSO supported; multi-factor authentication enforced on password accounts.
Scoped connectors
Lexi reads only the mailboxes and calendars a user connects, and the firm can revoke that access at any time.
Security is the first conversation, not the last. These are the questions IT and risk teams put to us before a pilot.
Our infrastructure is ISO 27001 and SOC 2 Type 2 certified. LeadLex’s own ISO 27001 and SOC 2 Type 2 audits are in progress, and we will publish those reports when they complete rather than imply them now. If your risk team needs the infrastructure certificates before a pilot, we can share them.
The current list is maintained for every firm under the DPA and published at /subprocessors. Material changes are notified in advance, so the firm has the opportunity to object before they take effect.
The firm can export its records and request deletion at any time under the DPA. Deletion covers the live instance and its backups on the documented retention cycle.
Bring your risk team to the first call.
We will walk your IT and risk leads through hosting, model terms, audit logging and the approval ladder before anything is connected.
We take on a small number of firms at a time. Nothing is sent to a client until a partner has read it. Not this quarter? Join the waitlist.