Trust & security

Built to be verified — and built to be trusted.

Intelligence integrity first: findings verified to the Meridian™, never AI-authored. Then enterprise platform controls for procurement and legal review. Sufficiency of your program remains counsel’s judgment.

Prefer to see the output? Free Sample Report →

Verified to Meridian™Cited findings · never AI-authored
LegisGate Compass™ Report — table of contents

Trust & security

Legal evaluates the citations. Security evaluates the controls.

288 binding laws · 3,051 obligations — As of August 23, 2026. Primary source, not model paraphrase.

Verified · never AI-authored

Integrity

Intelligence you can check against the statute.

Findings ship from curated templates and deterministic rules applied to your intake. Security posture and provenance sit side by side — so Legal and Security can both evaluate LegisGate™.

SourceCitations resolve to authoritative instruments.
No LLMRegulatory finding substance is never model-authored.
One corpusSame library behind the product suite surface.
CounselSufficiency remains your counsel's judgment.

Intelligence integrity

Regulatory findings are produced by a Validated Template or a Deterministic Rule — never AI-authored. Each citation is verified to the Meridian™: the reference resolves to and matches the authoritative source it points to — binding regulation, official guidance, enforcement precedent, or recognized standard. That is not legal sign-off on your deployment; qualified counsel makes the final determination.

How regulatory findings are produced and cited
How it is producedAuthority typeExample mapping
Validated TemplateBinding RegulationGDPR Art. 28 processor obligations
Deterministic RuleOfficial GuidanceEU AI Act Annex III deployer duties
Validated TemplateEnforcement PrecedentRegulator action mapped to deployment context
Deterministic RuleRecognized StandardSector standards cross-walk where applicable
Binding Regulation

Business Associate Agreement required before any PHI flows to the model.

45 CFR § 164.504(e)

Verified to the Meridian™Deterministic Rule
Official Guidance

Disclose material AI use in consumer-facing decisions.

FTC AI Guidance (2024)

Verified to the Meridian™Validated Template

Two-axis provenance on findings: how it was produced (Validated Template · Deterministic Rule) and what authority it rests on (Binding Regulation · Official Guidance · Enforcement Precedent · Recognized Standard).

Platform security

Enterprise controls for procurement and trust review.

Encryption, tenant isolation, access control, and honest assurance status — only controls that are live appear as highlights. Architecture, data handling, subprocessors, and disclosure policies follow below for procurement and legal review.

  • Encryption in transit (TLS) and at rest (AES-256)
  • Multi-tenant isolation with Postgres row-level security
  • Role-based access; platform admin gated separately
  • Deployment metadata only — not your document corpus or source code
  • Model inference excluded from foundation-model training; findings are templates-only
  • Hardened browser security headers (HSTS, framing, MIME sniffing)
  • Use-case prose redacted from unstructured server logs
  • Application-layer AES-GCM for use-case prose when field encryption key is configured

SOC 2 Type I — formal engagement in progress. This is not a completed certification report.

Trust center

Trust & Security

Clear, direct answers about how LegisGate handles your data, our compliance posture, and our security controls. Detailed legal language and technical diagrams live in linked documents.

Live security controls

Only controls that are implemented in production appear here — sourced from the customer-data-posture register.

  • Encryption in transit (TLS) and at rest (AES-256)
  • Multi-tenant isolation with Postgres row-level security
  • Role-based access; platform admin gated separately
  • Deployment metadata only — not your document corpus or source code
  • Model inference excluded from foundation-model training; findings are templates-only
  • Hardened browser security headers (HSTS, framing, MIME sniffing)
  • Use-case prose redacted from unstructured server logs
  • Application-layer AES-GCM for use-case prose when field encryption key is configured

Your data

Where it’s stored, how long it’s kept, and who can access it.

Where is customer data stored?

Customer data is stored in our production database and encrypted at rest and in transit. Attachments are not required for assessments; if used, they remain scoped to your tenant. We do not use customer content to train AI models.

How long is data retained?

Data is retained for the duration of your subscription and can be deleted on request. Backups follow a rolling retention window aligned to operational recovery needs. Contractual retention terms can be provided in a DPA.

Who can access it?

Access is restricted via role-based access controls and audited. Your users can only access your organization’s data. Support access is permissioned and time-bound when required to resolve issues.

Compliance & certifications

Status and ready-to-use contractual artifacts.

SOC 2 Type I

Formal SOC 2 Type I engagement is in progress. This is not a completed certification report.

In progress

DPA (GDPR)

Our full GDPR Article 28 Data Processing Agreement — including all annexes and transfer mechanisms — is published on the DPA page and available to download as HTML.

Security

Encryption

Encryption in transit (TLS) and at rest (industry-standard encryption) is enforced for customer data.

Access controls

Role-based access controls, tenant isolation, and audit logging are used to control and trace access.

Incident response

We maintain incident response procedures and will coordinate with customers for security incidents. Response SLAs and notification commitments are available in contractual documents where applicable.

Sub-processors & contacts

A clean registry plus direct contacts for legal, security, and support.

Sub-processor registry

ProviderData typeLocation
Supabase, Inc.All LegisGate™ application dataUS (AWS us-east-1) — EU region available
Anthropic, PBCReport intake data, vendor public information, organizational context (sent per-request for AI analysis, not stored by Anthropic)US
Vercel, Inc. (if applicable)Application delivery, static assetsGlobal CDN (Edge network)
Resend, Inc. (if applicable)Email addresses, notification contentUS

Need the full Article 28(2) language and change notification terms? View the full DPA →

Talk to usWe're here to help
Trust & Security - How We Protect Your Deployment Facts