Lawden

Security

Security

Enterprise-grade security built in from day one.

Architecture

Security at every layer.

From physical infrastructure to application-level controls. Nothing is left to chance.

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3.

SOC-2 Readiness

Lawden is built to SOC-2 Type II standards. We maintain rigorous security controls, access management, and incident response procedures.

Access Control

Granular, role-based permissions at the organization, matter, folder, and document level. Google OAuth available when configured.

Audit Log

Every state change, document access, permission modification, and login is logged with a timestamp, user attribution, and IP address. Logs are exportable.

Infrastructure

Hosted on AWS. Data is isolated per tenant at the database level. Automated backups with point-in-time recovery.

Identity Management

Each user belongs to exactly one organization. Cross-organization access is impossible by design. Invitation-only signup for client portals.

Monitoring

24/7 infrastructure monitoring with automated threat detection and Sentry error tracking. Intrusion detection, anomaly alerts, and immediate incident response.

Compliance

GDPR-compliant data processing with self-service account deletion and data export. Data processing agreement (DPA) available upon request. Data hosted in US-East.

Compliance

Standards we meet.

  • SOC-2 Type II (in progress)
  • GDPR compliant with self-service deletion and export
  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • ISO 27001 aligned controls
  • Data Processing Agreement (DPA) available

Data

Your data, your control.

  • Multi-tenant with strict database-level isolation
  • Automated daily backups with 30-day retention
  • Point-in-time recovery available
  • GDPR self-service account deletion and data export
  • Automated data retention: 90d for deleted accounts, 30d for expired sessions, 365d for activity and audit logs

Permissions

Granular access, complete control.

Every user gets exactly the access they need — nothing more, nothing less.

Firm Admin

Full access to all matters, users, settings, and billing. Can configure permissions and invite users.

Lawyer

Access to assigned matters. Can create documents, manage tasks, and invite external collaborators.

Paralegal

Access to assigned matters. Can upload documents, manage checklists, and view activity logs.

Client

Portal access to assigned matters only. Can view documents, upload requested files, and comment.

External Counsel

Access to specific matters only. Configurable read/write/comment permissions per room.

Super Admin

Platform-level access across organizations. User management, billing oversight, global settings.

Ready to transform your deal workflow?

Join hundreds of law firms using Lawden to close deals faster.