We are pleased to show you our new website
    §1
    / Compliance
    / Compliance · Confidentiality

    Security we can demonstrate.

    Certified, externally audited and documented openly. Here we show how Lextract protects, processes and controls client data.

    GDPR-compliant ISO/IEC 27001 since October 2025 EU hosting No training on client data Annual penetration test External data protection officer
    §2
    / Client data
    / Safe for client data

    No training on client data.

    Processed separately

    Lextract does not use client data to train models. Every data room is processed separately per client, and what arises on one matter is not reused for another.

    Configuration to your standards

    You store your templates, settings and review logic as configuration. Lextract then works to your standards without any model learning from your data.

    §3
    / Professional conduct
    / Compatible with professional conduct rules

    Built around the requirements of professional conduct.

    Contractually, technically and organisationally, Lextract is built around the requirements on confidentiality, use of service providers and access control — among other things through provider agreements, contractual confidentiality undertakings and traceable processing.

    There is no certification under the BRAO, the German Federal Lawyers’ Act, for legal tech providers. Lextract does not replace the professional conduct assessment in the individual case; the judgement on any given matter remains yours.
    §4
    / Data lifecycle
    / Data lifecycle

    Data lifecycle, from import to deletion.

    1

    Intake

    Documents are uploaded directly or taken over from connected systems.

    2

    Processing

    Lextract extracts, structures and analyses content to produce findings, references and draft reports.

    3

    Separation

    Client data is processed in logical separation and made available only to authorised users.

    4

    Security

    Access is role-based and limited on the least-privilege principle; authentication runs through Auth0 with MFA.

    5

    Deletion

    Data is removed at the end of the project, or on the client’s request, under the agreed deletion processes.

    §5
    / Audit
    / Data protection

    Data protection and security at a glance.

    Certification
    ISO/IEC 27001, since 2025
    ISMS scope
    development, operation and management of the Lextract platform
    GDPR
    data processing agreement, technical and organisational measures and EU hosting for processing, deletion, access and supplier control
    Penetration test
    external, grey-box method, carried out in July 2025 and repeated in August 2026; the finding identified has been remedied
    Testing standard
    OWASP Web Security Testing Guide, OWASP ASVS, OWASP LLM Top 10
    Hosting
    EU-based cloud environments; data encrypted in transit and at rest
    Authentication
    Auth0 with MFA, role-based on least privilege
    Data protection officer
    Dr Sebastian Kraska, IITR Datenschutz GmbH, Munich
    Ecosystem
    Auth0 by Okta
    Deutsche Telekom
    Legal Tech Verband
    NVIDIA Inception Program
    Legal Tech Colab
    Handelsregister
    Microsoft Azure
    Google
    §6
    / Questions
    / FAQ

    What security officers ask most often.

    Is Lextract GDPR-compliant?+
    As a processor, Lextract provides a data processing agreement, technical and organisational measures and EU hosting. The data protection assessment depends on the specific deployment.
    Is there a BRAO certification?+
    No. Lextract provides technical, organisational and contractual documentation so that firms can assess its use within their own professional conduct requirements.
    What happens to the data when the project ends?+
    It is deleted or returned under the contractually agreed processes.

    Frequently asked questions

    §7
    / Documents
    / For your assessment

    The documents we provide.

    Firms assess the use of service providers against their own standards.

    • ISO/IEC 27001 certificate
    • Data processing agreement with technical and organisational measures
    • List of sub-processors
    • Report on the most recent penetration test
    • Deletion policy

    See how Lextract handles client data.

    ISO/IEC 27001certifiedEU hostingData stays in the EUClient datano model training