Security
Documented controls. Explicit assurance boundaries.
Review application admission, matter access, infrastructure and provider safeguards for the deployment you intend to use.
Documented production security posture
These controls describe the published service posture. Request current evidence for your proposed deployment; this website redesign does not independently test the application.
- Google OIDC is used as the current production identity provider.
- An explicit email allowlist controls admission to the private application surface.
- Matter access is governed separately through per-user matter membership and roles.
- The application is served through TLS at app.legalragpro.com; the Streamlit application port is not directly published to the public internet.
- The application container uses a read-only root filesystem with reduced privileges, while required data and secret paths are mounted separately.
- The OpenAI API credential is supplied as a Docker secret rather than embedded in the application image.
- Production matter storage is encrypted at rest, with fail-closed binding to the encrypted data volume.
- Encrypted off-site backup is configured in Europe and an isolated selected-file restore has been verified successfully.
- Application-side matter closure and disposal controls have passed the full automated disposal regression suite.
Matter isolation and access control
A user who is allowed into LegalRAG does not automatically gain access to every matter. The matter repository resolves the authenticated identity against active matter membership, and roles distinguish owner, solicitor, reviewer and read-only access.
LegalRAG Pro describes matter isolation as a designed and tested control, not as an absolute guarantee that no software defect could ever cause cross-matter exposure. Assurance is maintained as the product evolves.
AI provider and confidentiality boundary
The configured OpenAI API account has training use disabled. LegalRAG Pro’s governed Responses API boundary explicitly uses store=False. OpenAI states that API data is not used to train or improve its models unless a customer explicitly opts in to data sharing.
Under the current standard OpenAI profile, abuse-monitoring logs may contain customer content and are retained for up to 30 days, subject to OpenAI’s stated exceptions. LegalRAG Pro submitted a request for Zero Data Retention on 4 October 2026. That request is pending, so LegalRAG Pro does not currently claim ZDR.
Inputs and outputs should be limited to what is necessary for the authorised workflow, and confidential or privileged use remains subject to customer approval, appropriate data-processing arrangements and the applicable professional confidentiality obligations.
Backup and resilience boundary
Production matter data is stored on encrypted storage and encrypted off-site backup is configured in Europe. An isolated restore of backed-up application data has been verified successfully without altering the live matter. This proves selected-file recoverability; it is not yet a claim that a complete service can be restored within a stated recovery-time objective. Full-service recovery evidence remains open.
Due-diligence information for firms
Before confidential client material is introduced, a firm should be able to review the controls and assumptions that apply to its intended use. A pilot can therefore include a documented review of authorised users, matter membership, provider configuration, data-processing terms, retention and deletion expectations, resilience boundaries and the proposed exit process.
LegalRAG Pro does not use certification language as a substitute for evidence. Where an assurance, control or provider setting is not independently certified or contractually established, it should be treated as a point for due diligence rather than implied by the website.
Need a security review for a pilot?
A controlled pilot can include a documented security, confidentiality and data-processing review before client material is introduced.