LegalSpark Home
LegalSpark

Security Policy

Effective as of November 1, 2024. Last updated on November 1, 2024.

At LegalSpark.AI, we take the security and privacy of your data seriously. As a platform serving legal professionals, we understand the importance of maintaining the highest standards of data protection and confidentiality.

1. Data Ownership and Control

You retain full ownership and control of your data at all times. We process your data only to provide and improve our Services. You can export or delete your data at any time through your account settings.

2. Technology Overview

Our platform is built on modern, secure infrastructure using industry-leading cloud providers. We employ multiple layers of security to protect your data at every level of our technology stack.

3. Encryption

We use industry-standard encryption to protect your data:

  • In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
  • At Rest: Stored data is encrypted using AES-256 encryption.
  • Backups: All database backups are encrypted and stored securely.

4. Authentication

We support secure authentication methods including:

  • Google login (OAuth 2.0)
  • Magic link email authentication
  • Secure session management with automatic timeout

5. Development Practices

Our development team follows secure coding practices:

  • Agile development methodology with security reviews
  • Continuous integration and continuous deployment (CI/CD) pipelines
  • OWASP Top 10 awareness and mitigation
  • Peer code review for all changes
  • Automated code analysis and vulnerability scanning

6. Vulnerability Management

We maintain an active vulnerability management program that includes regular security assessments, dependency scanning, and prompt patching of identified vulnerabilities.

7. Incident Response

We have a documented incident response plan that includes detection, containment, investigation, and notification procedures. In the event of a security incident, we will notify affected users in accordance with applicable laws and regulations.

8. Third-Party Security

We carefully evaluate the security posture of all third-party services we use. Our key vendors maintain SOC 2 compliance and industry-standard security certifications.

9. Contact Us

If you have security concerns or want to report a vulnerability, please contact us at [email protected].