Per-tenant data isolation
Every firm's data is strictly isolated. No shared tables, no shared AI context. One tenant cannot read another's anything.
Lexivo is architected for the confidentiality, integrity, and auditability your practice demands. Real tenant isolation. Real encryption. Real audit logs. Not a compliance checkbox.
How the system is put together — the controls that don't require trusting us, they require checking us.
Every firm's data is strictly isolated. No shared tables, no shared AI context. One tenant cannot read another's anything.
AES-256 for data at rest. TLS 1.3 in transit. Keys are rotated regularly and stored in a managed KMS.
Granular roles for partners, senior lawyers, associates, paralegals, and accountants — enforced at the API layer, not just the UI.
Firms can require MFA for all users. Sessions are device-aware and can be revoked at any time.
Not a policy document — the screen an office admin actually opens. Who signed in, what they read, what they exported, and from where.
Office admin, accountant, lawyer, client — enforced on the server, not hidden with CSS on the screen.
Lawyers see their work; they do not see rates, margins or firm revenue. That wall is built in, not a setting you must remember.
A client account can reach exactly one thing: their own case. Every portal endpoint is checked against that, every time.
Two-factor sign-in with a single active session, so a forgotten login on a shared machine does not stay open.
Views, edits, exports, shares and sign-ins recorded with actor, time and address — written to be read back years later.
Sensitive fields encrypted at rest, everything in transit over TLS, and backups encrypted the same way.
Consent records and full data exports on request, so a privacy enquiry is a report, not a project.
Keep the firm's data in the region you need it to sit in, on infrastructure you can point to in a tender.
Lexivo is built against these control frameworks. Attestation is in progress; in-region hosting and bespoke DPAs are available to Enterprise tenants.
Controls aligned to Trust Services Criteria for security, availability, and confidentiality.
Information security management aligned to ISO/IEC 27001.
DPA available. Right-to-erasure, export, and audit tooling is built in.
Encryption, access controls, and audit logging meet HIPAA technical safeguards for firms serving healthcare clients.
Frameworks listed reflect controls the platform is designed against. External attestation status is available on request.
An immutable audit log records every access, edit, share, and export across your firm. Search, filter, and export audit trails for compliance reviews or incident response.
Lexivo is a data processor for your firm. You decide what gets stored, who can access it, and when it leaves.
Our security team is happy to walk you through architecture, sub-processors, pen-test reports, and enterprise controls.