Legal Engine Trust Centre

Built for firms where confidentiality is the product.

Legal Engine runs voice-led AI agents inside law firms. That means we hold client-confidential matter information, and we are assessed on it by every firm we work with. This page sets out the standards we operate to, the independent assurance behind them, and how to obtain our documentation.

ISO/IEC 27001:2022 · Certified since September 2025 · as at 21 September 2026
Standards and assurance

What we hold, and who checked it.

Each item below is independently assessed. Where a document exists, you can ask us for it using the form further down this page.

Certified since September 2025

ISO/IEC 27001:2022

Information security management system, certified and independently audited.

Legal Engine has operated a certified ISO/IEC 27001:2022 information security management system since September 2025.

In August 2026 we completed a full certification audit with A-LIGN and were formally recommended for certification. A-LIGN is finalising the audit report and we expect the new certificate by the end of October 2026.

Because we moved to a new certification body for this cycle, the audit is classed as initial certification rather than recertification. The scope is unchanged, and our ISMS continues to operate exactly as audited.

Available on request: A-LIGN's letter of recommendation for certification, and the certificate itself once issued.

Registered with the ICO

UK GDPR and EU GDPR

Registered data controller and processor, with a documented lawful basis for every processing activity.

Legal Engine Ltd is registered with the Information Commissioner's Office under reference ZB917162, current until 18 June 2027.

We contract with firms on a written data processing agreement, process client data only on documented instructions, and support data subject rights, retention limits and deletion on request.

Available on request: Our data processing agreement, privacy notice, and the current sub-processor list.

Most recent test September 2026

Independent penetration testing

Annual third-party testing of the applications firms actually use, with findings tracked to closure.

Our applications are penetration-tested by an independent specialist. The most recent test was carried out by URM in September 2026 against dedicated test environments that mirror production.

Findings are recorded as corrective actions against our ISMS, assigned an owner and a date, and tracked to closure through the same process our certification auditor reviews.

Available on request: A penetration-test summary, shared under NDA.

In force

Professional indemnity and cyber insurance

Professional indemnity and cyber liability cover held with UK-market insurers.

Legal Engine carries both professional indemnity and cyber liability insurance. Certificates showing the current limits and policy periods are provided on request, so that what you receive is the policy in force on the day you ask rather than a figure on a web page.

Available on request: Certificates of insurance for professional indemnity and cyber liability.

Data handling

How we handle your data

The commitments below are the ones we are audited against, and the ones we write into contracts. Each is enforced in the product, not just in a policy document.

Residency and retention

  • Client data is hosted and processed in the EU by default, on Google Cloud in Belgium (europe-west1). UK hosting in London (europe-west2) is available on request.
  • Sub-processors are selected for EU data residency. The current list, setting out each one's residency position and certifications, is available on request.
  • Retention is configurable per firm, including deployments that retain nothing beyond the life of the conversation.
  • Deletion on request is supported, and the runbook for carrying it out is a documented part of our ISMS.

Confidentiality of your content

  • Your data is never used to train our models, or anyone else's. This is contractually enforced with each model provider, not merely a setting.
  • Our enterprise inference agreements carry zero customer data retention on the provider side.
  • Voice is held to the same standard as text: recordings are encrypted on capture, processed in isolated environments, and can be deleted automatically after processing.

Access and identity

  • Firms sign in with their own identity provider through single sign-on, so the multi-factor and conditional-access rules that apply are the ones your firm already enforces, and access follows your joiners and leavers process rather than ours.
  • Access to client environments is role-based and least-privilege.
  • User access is reviewed as a scheduled ISMS activity rather than on an ad-hoc basis, and the review is evidenced to our auditor.

Engineering and operations

  • All data is encrypted in transit and at rest using current industry-standard protocols.
  • Every production change is made through a version-controlled pull request in a protected repository, and the full change history is retained as audit evidence.
  • We maintain documented incident response and business continuity plans, with a risk register behind them.
  • Vulnerability management, dependency patching and infrastructure hardening run continuously and are evidenced to our auditor.
Documentation

Request our documentation

Tell us what your firm's due-diligence process needs and we will send it. Documents that describe our controls in detail are shared under NDA; we will say so when we reply.

What would you like? Select all that apply

We use these details only to answer your request. Documents that describe our controls in detail are shared under NDA.

Reporting a security concern

If you believe you have found a vulnerability in a Legal Engine service, or you need to reach us about a security matter urgently, use the form above and mark it urgent in the notes. We will acknowledge it and route it to our security team.