Built to be verified — and built to be trusted.
Intelligence integrity first: findings verified to the Meridian™, never AI-authored. Then enterprise platform controls for procurement and legal review. Sufficiency of your program remains counsel’s judgment.
Prefer to see the output? Free Sample Report →

Trust & security
Legal evaluates the citations. Security evaluates the controls.
288 binding laws · 3,051 obligations — As of August 23, 2026. Primary source, not model paraphrase.
Verified · never AI-authored
Intelligence you can check against the statute.
Findings ship from curated templates and deterministic rules applied to your intake. Security posture and provenance sit side by side — so Legal and Security can both evaluate LegisGate™.
Intelligence integrity
Regulatory findings are produced by a Validated Template or a Deterministic Rule — never AI-authored. Each citation is verified to the Meridian™: the reference resolves to and matches the authoritative source it points to — binding regulation, official guidance, enforcement precedent, or recognized standard. That is not legal sign-off on your deployment; qualified counsel makes the final determination.
| How it is produced | Authority type | Example mapping |
|---|---|---|
| Validated Template | Binding Regulation | GDPR Art. 28 processor obligations |
| Deterministic Rule | Official Guidance | EU AI Act Annex III deployer duties |
| Validated Template | Enforcement Precedent | Regulator action mapped to deployment context |
| Deterministic Rule | Recognized Standard | Sector standards cross-walk where applicable |
Business Associate Agreement required before any PHI flows to the model.
45 CFR § 164.504(e)
Disclose material AI use in consumer-facing decisions.
FTC AI Guidance (2024)
Two-axis provenance on findings: how it was produced (Validated Template · Deterministic Rule) and what authority it rests on (Binding Regulation · Official Guidance · Enforcement Precedent · Recognized Standard).
Enterprise controls for procurement and trust review.
Encryption, tenant isolation, access control, and honest assurance status — only controls that are live appear as highlights. Architecture, data handling, subprocessors, and disclosure policies follow below for procurement and legal review.
- Encryption in transit (TLS) and at rest (AES-256)
- Multi-tenant isolation with Postgres row-level security
- Role-based access; platform admin gated separately
- Deployment metadata only — not your document corpus or source code
- Model inference excluded from foundation-model training; findings are templates-only
- Hardened browser security headers (HSTS, framing, MIME sniffing)
- Use-case prose redacted from unstructured server logs
- Application-layer AES-GCM for use-case prose when field encryption key is configured
SOC 2 Type I — formal engagement in progress. This is not a completed certification report.
Trust center
Trust & Security
Clear, direct answers about how LegisGate™ handles your data, our compliance posture, and our security controls. Detailed legal language and technical diagrams live in linked documents.
Live security controls
Only controls that are implemented in production appear here — sourced from the customer-data-posture register.
- Encryption in transit (TLS) and at rest (AES-256)
- Multi-tenant isolation with Postgres row-level security
- Role-based access; platform admin gated separately
- Deployment metadata only — not your document corpus or source code
- Model inference excluded from foundation-model training; findings are templates-only
- Hardened browser security headers (HSTS, framing, MIME sniffing)
- Use-case prose redacted from unstructured server logs
- Application-layer AES-GCM for use-case prose when field encryption key is configured
Your data
Where it’s stored, how long it’s kept, and who can access it.
Where is customer data stored?
Customer data is stored in our production database and encrypted at rest and in transit. Attachments are not required for assessments; if used, they remain scoped to your tenant. We do not use customer content to train AI models.
How long is data retained?
Data is retained for the duration of your subscription and can be deleted on request. Backups follow a rolling retention window aligned to operational recovery needs. Contractual retention terms can be provided in a DPA.
Who can access it?
Access is restricted via role-based access controls and audited. Your users can only access your organization’s data. Support access is permissioned and time-bound when required to resolve issues.
Compliance & certifications
Status and ready-to-use contractual artifacts.
SOC 2 Type I
Formal SOC 2 Type I engagement is in progress. This is not a completed certification report.
DPA (GDPR)
Our full GDPR Article 28 Data Processing Agreement — including all annexes and transfer mechanisms — is published on the DPA page and available to download as HTML.
Security
Encryption
Encryption in transit (TLS) and at rest (industry-standard encryption) is enforced for customer data.
Access controls
Role-based access controls, tenant isolation, and audit logging are used to control and trace access.
Incident response
We maintain incident response procedures and will coordinate with customers for security incidents. Response SLAs and notification commitments are available in contractual documents where applicable.
Sub-processors & contacts
A clean registry plus direct contacts for legal, security, and support.
Sub-processor registry
| Provider | Data type | Location |
|---|---|---|
| Supabase, Inc. | All LegisGate™ application data | US (AWS us-east-1) — EU region available |
| Anthropic, PBC | Report intake data, vendor public information, organizational context (sent per-request for AI analysis, not stored by Anthropic) | US |
| Vercel, Inc. (if applicable) | Application delivery, static assets | Global CDN (Edge network) |
| Resend, Inc. (if applicable) | Email addresses, notification content | US |
Need the full Article 28(2) language and change notification terms? View the full DPA →
Contacts
