← Linoscore Legal

Trust & Security

Linoscore Legal holds privileged client material, so this page answers the questions that matter: who can access it, where it travels, how long it's retained, and what happens if something goes wrong. Operated by Linos LLC, Allen, Texas.

Security FAQCompleted security questionnaireRequest a security call

Where your data lives

Your firm's data — clients, matters, documents, and messages — is hosted on managed cloud infrastructure in the United States (New York). The application and its PostgreSQL database run in DigitalOcean's US-East region. Client data does not leave the United States.

Tenant isolation

Every firm is a separate tenant. All data — every record, document, and query — is scoped to a firm identifier and filtered at the application layer on every request, so one firm can never see or reach another firm's data.

Encryption

All traffic is encrypted in transit with TLS (HTTPS). Data is encrypted at rest by our managed database and storage providers.

Access controls & production access

In your firm: role-based access control (Admin, Partner, Associate, Paralegal) governs who can perform sensitive actions — deleting matters, exporting client data, changing roles, and managing billing. Roles are enforced server-side, not just hidden in the UI.

On our side: production access is limited to authorized Linos LLC personnel on a need-to-know basis, over encrypted channels, only to operate and support the service. We do not access client matter content except as needed to provide support you request or to meet a legal obligation.

AI data handling

AI features (case summaries, document drafting, the assistant, and intake qualification) send the relevant matter data to Anthropic's Claude API to generate a response. Text embeddings for the optional “similar matters” search use OpenAI. Both are processed in the United States.

  • No training on your data. We do not use client matter content to train shared AI models, and our AI providers do not train their models on data submitted through their business APIs.
  • Decision-support only. AI output is a draft or a suggestion; it never reaches a client without an attorney's review and approval.
  • Scoped. Only the data needed for a given task is sent — not your entire database.

Subprocessors

We use a small number of vetted subprocessors to run the service, each under data-protection terms:

ProviderPurposeLocation
DigitalOceanCloud hosting, managed PostgreSQL database, and file storageUnited States (New York)
Anthropic (Claude)AI features — case summaries, drafting, intake qualification, assistantUnited States
OpenAIText embeddings for “similar matters” search only (no generative use)United States

We do not currently use a third-party email, analytics, or advertising subprocessor. We'll update this list and notify firms before adding a subprocessor that processes client data.

Backups, retention & deletion

The managed database takes automated daily backups with point-in-time recovery over a rolling 7-day window, used only for disaster recovery.

When you delete a record, or a client's data via the in-app export/erase tools, it is removed from the live system promptly and ages out of backups within the backup window (about 7 days), after which it is permanently unrecoverable. On account closure we provide a full export and then delete your firm's data on the same timeline.

Audit logging

An immutable, firm-scoped audit log records who did what and when — record creation and deletion, data exports, permission and role changes, and billing changes. Firm admins can inspect it in Settings, and export it for their own records.

Your data is portable — no lock-in

Firm admins can export client and matter data at any time from within the app, and request a full account export on closure. You are never locked in.

Incident response

We maintain an incident-response process for security events. If a confirmed incident affects your firm's data, we will notify you without undue delay — and within 72 hours of confirming the incident — with what we know, what we're doing, and what (if anything) you should do. Report a concern any time to [email protected].

Professional-responsibility safeguards

  • Attorney approval gate. Nothing the AI produces — engagement letters, drafts, replies — reaches a client until an attorney reviews and sends it. Drafts are labeled as drafts for attorney review.
  • Conflict checks are a screening aid. The automated conflict check surfaces potential matches against your existing clients and adverse parties; it is not a legal conclusion and does not replace your professional conflict-of-interest analysis.
  • AI is decision-support, not legal advice. AI features may be incomplete or incorrect; you remain responsible for all professional judgments. We make no claim that AI replaces a lawyer's judgment.

Agreements

Our Terms of Service, Privacy Policy, and Data Processing Addendum are published in full. A countersigned DPA and a Master Services Agreement are available on request for firms that require them before onboarding — contact [email protected].

What we're working toward

We believe in being specific about what is and isn't in place. Currently on our security roadmap:

  • Multi-factor authentication (MFA) for firm users and administrators.
  • An independent penetration test, with a summary available to firms under NDA and critical findings remediated.
  • SOC 2 readiness. We do not currently hold SOC 2 or other certifications, and we don't claim any we don't have.

Questions from your security or compliance team? Email [email protected] and we'll set up a call. Linos LLC provides software, not legal services.