Security.
Last updated January 13, 2026Protecting the confidentiality of your practice is our highest priority. Lexpal is built on an enterprise-grade security foundation designed to meet the rigorous standards of the legal profession.
1. Security Philosophy
We employ a "Defense in Depth" strategy, layering multiple security controls to protect your data. We assume that user endpoints may be compromised and design our systems to protect the core data assets regardless.
2. Encryption & Data Protection
Your firm's data is encrypted at every stage:
- Data at Rest: All database volumes and object storage buckets are encrypted using AES-256 (Advanced Encryption Standard).
- Data in Transit: All network traffic is encrypted via TLS 1.3. We support HSTS (HTTP Strict Transport Security) to force secure connections.
- Key Management: We use AWS KMS (Key Management Service) with automatic key rotation.
3. Infrastructure & Compliance
Lexpal is hosted on Amazon Web Services (AWS) in the Mumbai (ap-south-1) region, ensuring data residency compliance.
- Physical Security: AWS data centers are protected by biometric surveillance and 24/7 armed guards.
- Standards: Our infrastructure aligns with ISO 27001, SOC 2 Type II, and PCI-DSS Level 1 standards.
4. Identity & Access Control
We provide granular controls to manage your firm's internal access:
- Role-Based Access Control (RBAC): Define custom roles (Partner, Associate, Paralegal) with specific permissions.
- Two-Factor Authentication (2FA): Mandatory for all administrative accounts.
- Audit Logs: Detailed immutable logs of every file access, download, and modification event.
5. Monitoring & Incident Response
Our security team employs automated intrusion detection systems (IDS) and web application firewalls (WAF) to block threats in real-time. We conduct regular penetration testing (VAPT) with third-party security firms.
6. Vulnerability Reporting
If you identify a potential security vulnerability, please contact our Security Team immediately at security@lexpal.in using our PGP key.