Security Policy
Effective as of November 1, 2024. Last updated on November 1, 2024.
At LegalSpark.AI, we take the security and privacy of your data seriously. As a platform serving legal professionals, we understand the importance of maintaining the highest standards of data protection and confidentiality.
1. Data Ownership and Control
You retain full ownership and control of your data at all times. We process your data only to provide and improve our Services. You can export or delete your data at any time through your account settings.
2. Technology Overview
Our platform is built on modern, secure infrastructure using industry-leading cloud providers. We employ multiple layers of security to protect your data at every level of our technology stack.
3. Encryption
We use industry-standard encryption to protect your data:
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- At Rest: Stored data is encrypted using AES-256 encryption.
- Backups: All database backups are encrypted and stored securely.
4. Authentication
We support secure authentication methods including:
- Google login (OAuth 2.0)
- Magic link email authentication
- Secure session management with automatic timeout
5. Development Practices
Our development team follows secure coding practices:
- Agile development methodology with security reviews
- Continuous integration and continuous deployment (CI/CD) pipelines
- OWASP Top 10 awareness and mitigation
- Peer code review for all changes
- Automated code analysis and vulnerability scanning
6. Vulnerability Management
We maintain an active vulnerability management program that includes regular security assessments, dependency scanning, and prompt patching of identified vulnerabilities.
7. Incident Response
We have a documented incident response plan that includes detection, containment, investigation, and notification procedures. In the event of a security incident, we will notify affected users in accordance with applicable laws and regulations.
8. Third-Party Security
We carefully evaluate the security posture of all third-party services we use. Our key vendors maintain SOC 2 compliance and industry-standard security certifications.
9. Contact Us
If you have security concerns or want to report a vulnerability, please contact us at [email protected].