← Trust & Security

Security FAQ

Straight answers to what lawyers ask before uploading privileged client material. For the full detail see the Trust Center and the security questionnaire.

If I upload privileged client material, who can access it?

Only your firm's own users, according to their role. On our side, access is limited to authorized personnel on a need-to-know basis for operating and supporting the service — we don't read client matter content otherwise. Other firms can never see your data; every firm is isolated as its own tenant.

Where does my data live, and does it leave the US?

It's hosted in the United States (DigitalOcean, New York) — application and database both. Client data does not leave the US. AI processing (Anthropic, OpenAI) also runs in the US.

Do you use my client data to train AI?

No. We never use client matter content to train shared AI models, and our AI providers don't train on data sent through their business APIs. AI only ever sees the specific data needed for a task you trigger, and its output is a draft for your review — nothing reaches a client without an attorney's approval.

Is my data encrypted?

Yes — encrypted in transit with TLS, and encrypted at rest by our managed database and storage providers.

Is there two-factor authentication?

Yes. TOTP two-factor (Google Authenticator, 1Password, Authy) with backup codes, and a firm admin can require it for everyone in the firm.

Can I see who did what?

Yes. An immutable, firm-scoped audit log records logins (and failed logins), record changes, deletions, exports, role changes, and court filings — with timestamps and source IP for sign-ins. Admins can review and export it as CSV.

What happens if there's a security incident?

We notify affected firms without undue delay and within 72 hours of confirming an incident, with what happened and any action needed. You can reach our security contact any time at [email protected].

How long do you keep data, and what about backups?

Backups use a rolling 7-day point-in-time window for disaster recovery. When you delete data it's removed from the live system promptly and purged from backups within about 7 days, after which it's permanently unrecoverable.

Can I get my data out / am I locked in?

You're never locked in. Admins can export all firm data as portable JSON and the audit log as CSV at any time, and can permanently close the account (which deletes your data) on demand.

Do you have SOC 2 or a penetration test?

We don't hold SOC 2 today and we won't claim certifications we don't have. An independent penetration test and SOC 2 readiness are on our roadmap; a pentest summary will be available under NDA once complete.

Can we sign a real agreement and DPA, not just website terms?

Yes. Our Terms, Privacy Policy, and DPA are published in full, and a countersigned DPA and Master Services Agreement are available on request before you onboard.

Can I try it with fake data first?

Yes — we recommend evaluating with fictional matters before entering live client data, and we're happy to set up a walkthrough. Email [email protected] to arrange a security call.

Still have questions? Email [email protected] and we'll set up a call. Linos LLC provides software, not legal services.