Skip to content
Legalithm logoLegalithm logo
Plans
Log inGet started
  • Platform

    What it does

    • Assessment
    • AI inventory
    • The compliance record
    • Exports

    How it works

    • Platform overview
    • Methodology
    • Rules and corpus
    • Honest limits
    • Security
    • Developer tools
  • Regulations

    AI Act

    • AI Act guide
    • Assessment
    • Deadline tracker
    • Quick risk quiz
    • Article 50 disclosures

    CRA

    • CRA overview
    • Are you in scope?
    • Reporting readiness
    • Reporting checklist
    • Annex I requirements

    EAA

    • EAA rules
    • Rules changelog
  • Solutions
    • Technology leaders
    • Legal teams
    • Privacy and DPO
    • Medical AI
  • Advisors
    • For advisory firms
    • CRA partner briefing
    • Advisor directory
  • Resources

    Learn

    • Blog
    • AI Act guide
    • Templates
    • Downloads

    Tools

    • All tools
    • Quick risk quiz
    • Article 50 disclosures
    • Omnibus tracker

    Company

    • About
    • Press
    • Contact
  • Plans
  • Log in
  • Get started

Site links

Legalithm logoLegalithm logo

The EU AI Act compliance layer for teams building AI. Classify risk, map obligations, and keep a dated, cited compliance record.

hello@legalithm.com•security@legalithm.com

The free tools stay free, with no account. Paid plans start at €1,500 per product, per year. Billing is not live yet, so both begin with a conversation.

Product

  • Overview
  • AI Act Assessment
  • Quick Risk Quiz
  • Deadline Tracker
  • Pricing
  • Founding Program

Solutions

  • Technology Leaders
  • Legal Teams
  • Privacy & DPO

Resources

  • Blog
  • AI Act Guide
  • Templates
  • Free Downloads

Company

  • About
  • Contact
  • Press

Legal disclaimer: Legalithm provides automated, rule-based compliance analysis for informational purposes only. Our analysis requires human validation and does not constitute legal advice. Always consult with qualified legal counsel for specific compliance matters. For data protection inquiries, contact our DPO at dpo@legalithm.com.

  • Privacy Notice
  • Terms of Service
  • Cookie Policy
  • DPA
  • Subprocessors
  • Acceptable Use
  • AI Transparency
  • Accessibility
  • Imprint
© 2026 Legalithm. Built for EU AI Act & GDPR assurance.
Loading consent preferences...
Trust Center

Trust, Security, and Compliance Transparency

Key information for evaluating Legalithm’s security practices, compliance posture, and AI transparency approach.

GDPR Compliant
EU-Hosted (Frankfurt)

At-a-glance

  • • EU-focused hosting for launch operations
  • • Encryption in transit and at rest
  • • Consent-aware analytics and privacy-first defaults

Contact

  • • Security: security@legalithm.com
  • • Privacy & DPO: dpo@legalithm.com
  • • General: hello@legalithm.com
    Home/Security & Compliance

Security

Encryption, access isolation, incident handling, and a plain statement of the controls we do not have.

View details →

Compliance

EU AI Act and GDPR-aligned documentation, controls, and policy references.

View details →

Availability

Hosting locations and recovery approach. There is no uptime SLA today; one is contractual and arrives with paid plans.

View details →

AI Transparency

Model governance, EU AI Act risk classifications, human oversight, and evaluation.

View details →

Privacy & DSAR

Data processing, retention, DSAR workflow, and data subject rights commitments.

View details →

Legal & Policies

Master Agreements, DPA, cookie policy, accessibility, and regulatory disclosures.

View details →

Security Controls

Legalithm is designed with defense-in-depth principles across infrastructure, access management, monitoring, and secure delivery practices.

Encryption in transit and at rest

  • TLS 1.3 in transit, terminated by Vercel
  • Encryption at rest as provided by Supabase, not a Legalithm-specific control
  • Secrets in environment variables, never in the repository

Access and isolation

  • Row-level security on every table in the public schema
  • Least-privilege access, with MFA available on accounts
  • No shared production credentials

What we do not have

  • No SOC 2, ISO 27001 or ISO 42001 certification
  • No third-party penetration test, and no paged on-call rotation
  • Stated here rather than left for you to discover in a questionnaire

Responsible disclosure

  • Report a vulnerability to security@legalithm.com
  • Acknowledged within 24 hours, high-severity issues prioritised
  • There is no paid bug bounty

Policies and hosting

Policy pages and hosting facts for the current launch scope. Legalithm holds no security certifications; what is and is not in place is set out in full on this page.

GDPR-aligned by design

Policy

Privacy by design, data minimisation, and data subject rights support. This is our own assessment, not a certification, and no certification of GDPR compliance exists to hold.

View documentation →

EU-hosted application data

In place

Application data is stored and processed in Frankfurt (Supabase EU). Analytics, email delivery and DNS run through separate processors, listed in the sub-processor register.

View documentation →

GDPR Art. 28 DPA

In place

Data Processing Agreement covering processor obligations and contractual safeguards.

View documentation →

EU AI Act transparency

Policy

Our own Article 50 disclosure for the AI features in this product, plus the classification methodology behind them.

View documentation →

AI Transparency & EU AI Act Compliance

Legalithm documents AI-assisted workflow behavior to support EU AI Act transparency, risk management, and human oversight expectations.

Model Inventory & Risk Classification

  • AI
    AI-assisted classification supports unacceptable, high, limited, and minimal risk outcomes.
  • AI
    Results include rationale and legal references for reviewer validation.
  • AI
    Workflow outputs are designed for operational use, not final legal determination.
Read AI transparency policy →

Human Oversight & Evaluation

  • AI
    Every AI output requires human review prior to enforcement.
  • AI
    Critical decisions should be validated by qualified legal/compliance stakeholders.
  • AI
    Transparency language is included across user-facing AI output touchpoints.
Read AI transparency policy →

Transparency & Documentation

  • AI
    AI usage and limitation disclosures are surfaced in product flows.
  • AI
    Documentation outputs include context for legal and procurement review.
  • AI
    Policies are maintained on trust and legal pages for external verification.
Read AI transparency policy →