Security questionnaire
A completed questionnaire covering the questions security and compliance teams ask before entrusting privileged client data. Current as of the effective date on our Trust Center. For a version signed and returned on your own template, email [email protected].
Company & scope
Who operates the service, and where are you based?
Linoscore Legal is operated by Linos LLC, a Texas limited liability company based in Allen, Texas. It is a legal practice-management product for law firms.
What data does the service process?
Firm account data (users, roles), and the client/matter data a firm enters — contacts, matters, documents, deadlines, billing, and messages, including the personal data of the firm's clients and opposing parties. The firm is the data controller; we are the processor.
Data protection & residency
Where is data hosted and stored?
On managed cloud infrastructure (DigitalOcean) in the United States — the application and PostgreSQL database run in the US-East (New York) region. Client data does not leave the United States.
Is data encrypted in transit and at rest?
Yes. All traffic is encrypted in transit with TLS (HTTPS). Data is encrypted at rest by our managed database and storage providers.
Is client data isolated between firms?
Yes. Every firm is a separate tenant; all data is scoped to a firm identifier and filtered at the application layer on every request, enforced server-side.
Access control & authentication
How is access controlled within a firm?
Role-based access control with four roles (Admin, Partner, Associate, Paralegal). Sensitive actions — deleting matters, exporting data, changing roles, managing billing — are gated by role and enforced server-side.
Do you support multi-factor authentication?
Yes. TOTP-based two-factor authentication (compatible with Google Authenticator, 1Password, Authy) with one-time backup codes. A firm admin can require MFA for all users; unenrolled users are forced to set it up before they can continue.
Who at Linoscore can access client data?
Production access is limited to authorized personnel on a need-to-know basis, over encrypted channels, only to operate and support the service. We do not access client matter content except to provide support you request or to meet a legal obligation.
AI & subprocessors
Which AI providers receive data, and for what?
Anthropic (Claude) for summaries, drafting, the assistant, and intake qualification; OpenAI for text embeddings used only by the optional 'similar matters' search. Both process data in the United States.
Is our data used to train AI models?
No. We do not use client matter content to train shared AI models, and our AI providers do not train their models on data submitted through their business APIs.
Who are your subprocessors?
DigitalOcean (hosting, database, storage), Anthropic (AI features), and OpenAI (embeddings) — all in the United States. We do not currently use a third-party email, analytics, or advertising subprocessor. The current list is published at /trust and we notify firms before adding a subprocessor that processes client data.
Backups, retention & deletion
How are backups handled?
The managed database takes automated daily backups with point-in-time recovery over a rolling 7-day window, used only for disaster recovery.
What happens when data is deleted?
Deleted records are removed from the live system promptly and age out of backups within the backup window (about 7 days), after which they are permanently unrecoverable.
Can a firm export its data and close its account?
Yes. Admins can export all firm data (portable JSON) and the audit log (CSV) at any time, and can permanently close the account — which deletes the firm and all its data. Firms are never locked in.
Auditability & monitoring
Do you keep an audit log firms can review?
Yes. An immutable, firm-scoped audit log records authentication events (including failed sign-ins), record creation and deletion, data exports, permission and role changes, billing changes, and courier/court filings — who, what, when, and the source IP for logins. Admins can inspect and export it.
Incident response
What is your breach-notification commitment?
We maintain an incident-response process. If a confirmed incident affects a firm's data, we notify the firm without undue delay and within 72 hours of confirming the incident, with what we know, what we're doing, and any action needed. Concerns: [email protected].
Professional responsibility
Does AI output ever reach a client automatically?
No. Every AI output — engagement letters, drafts, replies — requires an attorney's review and approval before it is sent; drafts are labeled as drafts. The automated conflict check is a screening aid, not a legal conclusion. AI is decision-support and does not replace a lawyer's professional judgment.
Compliance & agreements
Do you hold SOC 2 or other certifications?
Not currently, and we do not claim any we do not hold. An independent penetration test and SOC 2 readiness are on our roadmap; a pentest summary will be available to firms under NDA once completed.
Can we sign a DPA and a Master Services Agreement?
Yes. Our Terms, Privacy Policy, and Data Processing Addendum are published in full, and a countersigned DPA and MSA are available on request before onboarding. Contact [email protected].
Linos LLC provides software, not legal services. Questions? [email protected].