Legalspot← Back to Legalspot
Security

Security, built into Legalspot.

The controls a General Counsel and an IT team expect — present from day one, not bolted on later.

01 · Data protection

How we protect your data.

End-to-end encryption

All data is transmitted over an encrypted TLS 1.3 connection. Documents are stored encrypted (AES-256).

Our own servers in Warsaw

The application runs on our own servers located in Warsaw, Poland. Your data never goes to third-party cloud providers.

Access control

Strict permission control — for both platform users and the internal Legalspot team.

24/7 monitoring

Threat-detection systems run continuously. Every anomaly is analysed immediately.

Backups

Automatic daily backups kept in isolated environments, with fast recovery.

Microsoft sign-in

Authentication via Microsoft Entra ID — the secure standard used by the world's largest organisations.

02 · Deployment

On-premise installation

Legalspot on your own servers. For organisations with heightened security requirements, we offer installation of Legalspot within the client's infrastructure. Your data never leaves your environment.

Full control over data and infrastructure
Compliance with internal IT security policies
Integration with your existing Microsoft environment
Dedicated implementation support
03 · Verification

Security testing

Regular penetration testing

Legalspot regularly commissions external penetration tests from an independent, specialised firm. This independent verification lets us ensure the platform meets the highest standards of resilience against attacks. Findings are analysed and rolled out as improvements.

04 · Response

Incident response

1
Detection & assessment

Immediate analysis of every report or detected anomaly.

2
Notification within 72h

In the event of a breach, we notify users and supervisory authorities in line with GDPR requirements.

3
Remediation & report

We remove the cause of the incident and prepare a detailed final report.