LeadLex
SECURITY / Always on. Always secure.

Built for confidentiality from day one.

IP firms hold their clients’ most valuable unpublished information. LeadLex is designed so that adopting AI does not widen the firm’s risk surface.

EU-hosted, Frankfurt · GDPR with a DPA per firm · No model training · A partner approves every send

THE CONTROLS

Six controls, and what each one is worth. Enforced in the product, or held by contract — and which is which.

ControlWhat it means in the productAssurance
Isolated per firmEvery firm runs its own Lexi instance — dedicated infrastructure, its own memory, its own credentials. Nothing is shared between firms.Enforced in product
EU data residencyStored and processed in Frankfurt, with no replication outside the EU. Encrypted in transit on TLS 1.2+ and at rest, including backups.Enforced in product
Approval before every sendDrafts queue in the AI Inbox. No email, message or invite leaves the firm until a partner has read it and released it.Enforced in product
Conflict wallsAny contact, deal or matter can be walled off entirely, so a conflict or a privileged matter never enters Lexi’s context in the first place.Enforced in product
Append-only audit trailEvery extraction, draft and sent action is logged with its source and its approver. Records cannot be edited or removed.Enforced in product
No model trainingYour data is never used to train any AI model — the providers’ commercial terms, not best-effort. Prompts are logged briefly by the provider for abuse detection only, and never enter a training set.Contractual

Enforced in product means the control is implemented in LeadLex and cannot be turned off by a user. Contractual means it is governed by an agreement with a third party rather than by our code. We separate the two because the distinction is the one your risk team is trying to establish, and it is the one most vendors leave blurred.

Certified and compliant

Built on certified infrastructure, hosted in the EU, and audited on a schedule we publish — including what is still in progress.

  • ISO 27001

    Our infrastructure is ISO 27001 certified. LeadLex’s own certification audit is in progress.

    Infrastructure certified
  • SOC 2 Type 2

    Our platform provider is SOC 2 Type 2 audited. LeadLex’s own report is in progress.

    Provider audited
  • GDPR

    A data processing agreement is signed with every firm, with a documented lawful basis for each processing activity.

    DPA per firm
  • EU hosting

    Frankfurt, Germany. Data is not replicated outside the European Union at any point.

    Frankfurt · Germany
THE DETAIL

Who else touches the data, and who at the firm can see what.

A current sub-processor list is maintained for every firm under the DPA, and material changes are notified in advance.

Sub-processors
  • Supabase, EU region

    Database, authentication and storage, on ISO 27001 and SOC 2 Type 2 certified infrastructure.

  • AI model providers

    Inference only. No training on customer data under the providers’ commercial terms.

  • Email and calendar providers

    Microsoft and Google, connected by the firm through OAuth with scoped permissions it can revoke.

Access control
  • Role-based access

    Partner, fee-earner and business-services roles, with separate visibility on accounts and pipelines.

  • SSO and MFA

    Microsoft and Google SSO supported; multi-factor authentication enforced on password accounts.

  • Scoped connectors

    Lexi reads only the mailboxes and calendars a user connects, and the firm can revoke that access at any time.

QUESTIONS FIRMS ASK

Security is the first conversation, not the last. These are the questions IT and risk teams put to us before a pilot.

  • Our infrastructure is ISO 27001 and SOC 2 Type 2 certified. LeadLex’s own ISO 27001 and SOC 2 Type 2 audits are in progress, and we will publish those reports when they complete rather than imply them now. If your risk team needs the infrastructure certificates before a pilot, we can share them.

  • The current list is maintained for every firm under the DPA and published at /subprocessors. Material changes are notified in advance, so the firm has the opportunity to object before they take effect.

  • The firm can export its records and request deletion at any time under the DPA. Deletion covers the live instance and its backups on the documented retention cycle.

Bring your risk team to the first call.

We will walk your IT and risk leads through hosting, model terms, audit logging and the approval ladder before anything is connected.

We take on a small number of firms at a time. Nothing is sent to a client until a partner has read it. Not this quarter? Join the waitlist.

We onboard law firms one at a time.

Applications open. Reviewed every Tuesday.