Skip to content

Trust & security

Built for confidential matters.

Client confidentiality isn't a feature. It's the practice. Here is the honest posture behind how Lagelia handles the most sensitive material your firm holds.

Security & Compliance

Your client file never leaves our hands.

Most legal AI runs your privileged documents through someone else’s model. Ours doesn’t. Every model we use runs on infrastructure we operate, so there is no third party in the chain to retain your work, train on it, or be subpoenaed for it.

What we have not built yet

Encryption at rest, multi-factor authentication, and audit logging are on our security roadmapahead of general availability, not in the product today. SOC 2 Type II is on the same roadmap; no audit has started and we won’t claim the certification until it is issued. We would rather you read that here than discover it in a security questionnaire.

No outside model ever sees your file

Every model runs on infrastructure we operate. Your documents are never sent to OpenAI, Anthropic, or Google.

No third party can train on your data

No outside provider receives your client documents, so none of them can retain or train on your work.

Firm-scoped by design

Every matter, document, and record carries the owning firm's identifier, and data access is scoped to it.

Your documents stay out of our logs

Application logs and error reports never capture document text or client identifiers.

Hardened at the application layer

Parameterized database queries, path containment on every file route, and cryptographically random share links.

Role-based administration

Owner, admin, and member roles govern who can change firm settings and membership.

Our posture, stated plainly

No hand-waving. Here's exactly how your data is handled.

No outside model provider is in the chain

Language model inference and embedding generation run on infrastructure we operate. Your documents are never transmitted to OpenAI, Anthropic, Google, or any other model provider. There is no third party to retain your work, train on it, or be served with a subpoena for it.

Firm-scoped by design

Every matter, document, and record carries the owning firm's identifier, and data access is scoped to it. Requests run through a default-deny gate with an explicit allowlist of public routes.

Your data never trains a model

Client documents are used to answer your questions and nothing else. They are not used to train any model, ours or anyone else's. That holds by default, and in the contract.

You own your data

Set your own retention. Export or delete on your terms. A signed Data Processing Addendum backs every commitment on this page, and states plainly what we have not built yet.

What we have not built yet: encryption of stored data at rest, multi-factor authentication, audit logging of record access, and independent penetration testing are on our security roadmap ahead of general availability. They are not in the product today, and we will not describe them as though they are. SOC 2 Type II certification is on the same roadmap; no audit has commenced, and we will not claim the certification until it is issued. Section 5 of our Data Processing Agreement separates what is in place from what is committed, so your security reviewer can see both.

See Lagelia on your own matter.

Bring a live case. We'll demo on your actual facts, documents, and deadlines, and show you exactly how the next 90 days of work change.

Request a demo