Security & trust
Security built for privileged work.
Your matters hold other people's secrets. Legasus is SOC 2 compliant and HIPAA compliant, signs a BAA with any firm that needs one, and never uses client data to train AI models.
- SOC 2 compliant
- HIPAA compliant
- BAA for any firm
No. 01Access
Only the people you invite get in.
People sign in through your firm's identity provider, or through Legasus with a second factor. Admins decide who joins, what they can change, and whether that second factor is optional.
The path from sign-in to a matter
Step 01
Your identity provider
SAML or OIDC, with Okta, Microsoft Entra ID, Google Workspace, or another provider.
Step 02
Verified domain
A DNS record proves the firm's email domain belongs to you.
Step 03
Second factor
A one-time passcode or a security key, required when your admins say so.
Step 04
Admin or Member
Two roles, and only admins change how the firm signs in.
Step 05
The matter
Your firm's work, and only your firm's.
01·a
Your directory stays in charge
Connect SCIM and people are added and updated from your identity provider. With auto-membership on, a colleague's first SSO sign-in places them in the firm.
01·b
A second factor, on your terms
Admins can require a second factor for everyone, allow one-time passcodes, security keys, or both, and exempt email domains that already sign in through SSO.
01·c
Two roles, clear lines
Members do the firm's work. Admins also manage sign-in, security policies, and ethical walls.
No. 02Walls
Screens inside the firm, too.
When a conflict comes up, an admin can wall a colleague off from a matter's email. The wall holds until someone releases it, and both moves are written to the audit log.
Matter mail
Johnson v. Midwest Logistics
M. Reyes sees
Member- Re: Dispatch logs for Oct 3Oct 14Opposing counsel
- Fwd: Driver roster and hoursOct 12Client
- Deposition dates, safety managerOct 9Court reporter
D. Okafor sees
Member- Re: Dispatch logs for Oct 3Oct 14Opposing counsel
- Fwd: Driver roster and hoursOct 12Client
- Deposition dates, safety managerOct 9Court reporter
Mail audit log
No walls on this matter.
Admins only
Only a firm admin can place a wall or release one.
Holds until released
The wall covers every email tied to the matter and stays until an admin lifts it.
On the record
Placing and releasing a wall are both written to the mail audit log, with who did it and when.
No. 03AI
Your files don't teach anyone's model.
Client data is never used to train AI models. When the assistant reads your documents, it reads them for your firm, and the search index it builds stays inside your firm's space.
Diagram: your documents go to the Legasus assistant, which answers your team. There is no path from your data to model training; that branch is taped off and marked not used.
Never used for training
Client data is never used to train AI models, ours or anyone else's.
An index that stays home
The search index built from your documents is scoped to your firm and never pooled with other customers.
Suggestions wait for a person
When the assistant suggests new tasks or changes to a matter, they wait in a queue until someone on your team approves them.
Budgets you set
Admins set monthly AI budgets for the firm and for individual people.
No. 04Foundations
The parts no one sees, done properly.
None of this should be interesting. It should just be true, every day, whether or not anyone is looking.
SOC 2
Compliant
HIPAA
Compliant
BAA
Available to any firm that needs one
- Item 01
In transit
Every connection is encrypted. Browsers are told to use HTTPS only, and never to load Legasus inside another site's frame.
- Item 02
At rest
The database and file storage that hold your matters are encrypted at rest.
- Item 03
Connected tools
Keys and sign-in tokens for the tools you connect are encrypted on their own, apart from your records.
- Item 04
Webhooks
Messages from connected services are checked for a valid signature before Legasus accepts them.
- Item 05
Files
Documents open through short-lived signed links, and only for people in your firm.
- Item 06
Firm scope
Requests are tied to your firm through the signed-in session on our servers, not through anything a browser sends.
- Item 07
Audit trail
Each matter keeps a history of who changed what and when, and it exports as CSV, JSON, or PDF.
No. 05Questions
Security questions, answered plainly.
The questions IT teams and general counsel ask first. If yours isn't here, send it to our security team.
No. 01Is Legasus SOC 2 compliant?
Yes. Legasus is SOC 2 compliant. If your review needs documentation, contact our security team and we'll take your IT or compliance group through it.
No. 02Is Legasus HIPAA compliant, and will you sign a BAA?
Yes to both. Legasus is HIPAA compliant, and we sign a Business Associate Agreement with any firm that needs one. That matters for personal injury, medical malpractice, and workers' compensation practices that handle health records.
No. 03Do you use our data to train AI models?
No. Client data is never used to train AI models, ours or anyone else's. The search index built from your documents is scoped to your firm and isn't shared with other customers.
No. 04Can the AI change our records on its own?
Suggested tasks and changes to a matter don't save on their own. They wait in a queue until someone on your team approves or dismisses them. Admins can also set monthly AI budgets for the firm and for each person.
No. 05Can we sign in with our own identity provider?
Yes. Admins connect a SAML or OIDC identity provider, such as Okta, Microsoft Entra ID, or Google Workspace, from Legasus settings. SCIM keeps people in sync with your directory, and auto-membership adds a colleague to the firm on their first SSO sign-in.
No. 06Can we require a second factor for everyone?
Yes. Admins can require a second factor across the firm, allow one-time passcodes, security keys, or both, and exempt email domains that already sign in through your identity provider.
No. 07How do ethical walls work in Legasus?
An admin picks a person and a matter, and that person can no longer see any email tied to the matter. The wall stays until an admin releases it, and placing or releasing it is recorded in the mail audit log. Walls apply to a matter's email.
No. 08How do we send a security questionnaire or report a vulnerability?
Use our contact form with the Security subject. It's the right place for questionnaires, BAA requests, and suspected vulnerabilities; for a vulnerability, include the steps to reproduce it and we'll follow up with you directly.
Bring us your security questionnaire.
We'll walk your IT team through SOC 2, HIPAA and the BAA, and exactly how client data is handled.