Key information for evaluating Legalithm’s security practices, compliance posture, and AI transparency approach.
Encryption, access isolation, incident handling, and a plain statement of the controls we do not have.
EU AI Act and GDPR-aligned documentation, controls, and policy references.
Hosting locations and recovery approach. There is no uptime SLA today; one is contractual and arrives with paid plans.
Model governance, EU AI Act risk classifications, human oversight, and evaluation.
Data processing, retention, DSAR workflow, and data subject rights commitments.
Master Agreements, DPA, cookie policy, accessibility, and regulatory disclosures.
Legalithm is designed with defense-in-depth principles across infrastructure, access management, monitoring, and secure delivery practices.
Policy pages and hosting facts for the current launch scope. Legalithm holds no security certifications; what is and is not in place is set out in full on this page.
Privacy by design, data minimisation, and data subject rights support. This is our own assessment, not a certification, and no certification of GDPR compliance exists to hold.
View documentation →Application data is stored and processed in Frankfurt (Supabase EU). Analytics, email delivery and DNS run through separate processors, listed in the sub-processor register.
View documentation →Data Processing Agreement covering processor obligations and contractual safeguards.
View documentation →Our own Article 50 disclosure for the AI features in this product, plus the classification methodology behind them.
View documentation →Legalithm documents AI-assisted workflow behavior to support EU AI Act transparency, risk management, and human oversight expectations.