Security we can demonstrate.
Certified, externally audited and documented openly. Here we show how Lextract protects, processes and controls client data.
No training on client data.
Processed separately
Lextract does not use client data to train models. Every data room is processed separately per client, and what arises on one matter is not reused for another.
Configuration to your standards
You store your templates, settings and review logic as configuration. Lextract then works to your standards without any model learning from your data.
Built around the requirements of professional conduct.
Contractually, technically and organisationally, Lextract is built around the requirements on confidentiality, use of service providers and access control — among other things through provider agreements, contractual confidentiality undertakings and traceable processing.
Data lifecycle, from import to deletion.
Intake
Documents are uploaded directly or taken over from connected systems.
Processing
Lextract extracts, structures and analyses content to produce findings, references and draft reports.
Separation
Client data is processed in logical separation and made available only to authorised users.
Security
Access is role-based and limited on the least-privilege principle; authentication runs through Auth0 with MFA.
Deletion
Data is removed at the end of the project, or on the client’s request, under the agreed deletion processes.
Data protection and security at a glance.








What security officers ask most often.
Is Lextract GDPR-compliant?+
Is there a BRAO certification?+
What happens to the data when the project ends?+
The documents we provide.
Firms assess the use of service providers against their own standards.
- ISO/IEC 27001 certificate
- Data processing agreement with technical and organisational measures
- List of sub-processors
- Report on the most recent penetration test
- Deletion policy