Back to Legeva

Draft policy

Security and Product Trust

This draft describes the local protected-app security model and the controls required before Legeva processes production customer legal content.

Last updated: June 20, 2026

Current readiness status

Legeva has a local protected app foundation with server-side route guards, organization-aware navigation, role and permission helpers, matter access policies, and audit event planning. It is not yet connected to production auth, database, storage, AI, email, or observability providers.

No provider resource, production environment variable, production migration, paid service, or live AI processing is approved by this page.

Tenant and access model

Protected app routes require a server-resolved product session and organization context before rendering app workspaces.

Permissions are role based and checked server side for protected pages and server action boundaries. Matter access supports direct membership, organization owner and admin access, explicit allow or deny rules, team-scoped rules, and ethical-wall overrides.

Customer content boundaries

Legal matter files, extracted text, source snippets, prompts, model outputs, review tables, drafts, work packets, and client portal materials are treated as sensitive customer content when the protected app is activated.

Public demo and support email channels are not approved for confidential matter files or privileged material. Customer content intake requires an approved protected workflow, storage provider, retention policy, audit path, and support process.

AI and provider processing

AI providers are deferred until auth, tenancy, permissions, audit, data classification, model policy, provider review, DPA review, environment handling, and customer-data approvals are complete.

Model execution, embeddings, extraction, drafting, agents, and high-volume processing must preserve source boundaries, human review gates, and metadata minimization before any live customer data is processed.

Audit and observability

Meaningful protected actions are designed to produce minimized audit events that record actor, organization, target, action, decision, and provider-gate metadata without storing raw legal content, prompts, outputs, secrets, headers, or cookies.

Production observability and protected app analytics remain approval-gated. Runtime diagnostics must use scrubbed metadata-only signals before any provider DSN, event capture, replay, or alert routing is enabled.

Enterprise readiness gates

Before enterprise pilots, Legeva requires legal review of privacy, terms, cookies, support, and security content; a product DPA and subprocessor register; approved provider choices; reviewed migrations; backup and incident readiness; and tested data export and deletion workflows.

Security reports should be sent to the contact below with affected URLs, reproduction steps, observed impact, and safe contact details. Do not access private data, disrupt service, or test outside authorization.