MXLEX handles the most sensitive material a firm has: client matters, contracts, and privileged research. Security is not a feature bolted on at the end: it is how the product is built. Here is exactly how your work is protected, and what we are doing next.
Your matters, documents, and queries are never used to train any model. Your work is yours; it stays that way, by policy and by contract.
All data is encrypted in transit (TLS) and at rest, with strict access controls on every request.
PostgreSQL row-level security isolates every firm's matters and documents at the database. Role-based access (owner, admin, attorney, paralegal) and per-matter visibility are enforced on every request.
Every answer is grounded in the law, each citation resolves to its official source, an independent model checks that each claim is supported, and the system abstains when the corpus is not enough.
Four-surface security review complete, with no critical or high findings outstanding.
Runs on ISO 27001-certified cloud infrastructure.
AES-256 at rest, TLS 1.2+ in transit.
Card data is handled only by PCI DSS Level 1 processors and never stored on our servers.
Row-level security isolates every firm's data, verified by an automated suite on every release.
Regional hosting and a Data Processing Agreement on request.
Security is a program, not a checkbox. An independent four-surface security review is complete with no critical or high findings outstanding, tenant isolation is enforced by row-level security and verified by an automated suite on every release, and our Data Processing Agreement is published at /dpa. We pursue formal certification on the schedule your firm's procurement requires. If you need specific documentation now, contact us.
Talk to us about security