- Home
- Legal
- Security
LEGAL
Security
This page summarises how Lawnise protects the Service and your data. It describes our current measures; it is not a certification.
1. Hosting
The platform and its database run in Singapore, with the cloud and database providers listed on our Subprocessors page. Both providers encrypt stored data at rest with industry-standard encryption, and connections to the database must be encrypted. Connections to the Service use HTTPS with HSTS; connections to our cache use TLS and authentication.
2. Separating organisations
Each organisation's data is labelled with its organisation, and the application checks a person's organisation and project permissions before giving access. For many database tables, the database itself also limits each request to the organisation it is acting for. The application's database accounts have no superuser or row-security bypass rights, and the service refuses to start if they do.
3. Signing in
- Passwords are stored only as one-way hashes (bcrypt).
- Multi-factor authentication (authenticator app) with recovery codes; organisations can require it.
- Single sign-on with your organisation's identity provider.
- Repeated failed sign-ins are limited per account and per network address.
- Sessions expire after 8 hours; signing out revokes the session.
4. Connected AI applications
AI applications connect through OAuth 2.1 with PKCE. You approve which projects and capabilities each connection gets. Access tokens are short-lived (1 hour); refresh tokens rotate and are revoked if reused; authorisation codes, refresh tokens and application secrets are stored only as one-way hashes. You can disconnect any application on the Connections page. Your organisation decides whether changes an application proposes take effect directly or wait for a person's approval.
5. Protecting sensitive data
- Certain sensitive fields — multi-factor secrets and conversations from your own AI assistants — are encrypted in the database with per-organisation keys (AES-GCM).
- Text submitted for verification checks is redacted of recognised personal data before it is sent to an AI provider or stored. Redaction reduces personal data; it does not make text anonymous.
- Web pages you ask us to check are fetched with protections against being redirected to internal systems.
6. Records and audit
Sign-ins, settings changes, approvals and actions taken through connected AI applications are recorded with who acted and when. Several audit records are chained with hashes so later changes can be detected. Verdicts recorded by an AI application under your organisation's "direct" setting are stored as made by the AI application, separately from verdicts approved by a person.
7. People and access
Administrative access to the production cloud and database accounts is held by Lawnise's founder only. Engineering automation reads production data only through read-only tools. Software changes reach production through the reviewed release process; other changes to production settings are made by the founder.
8. Incidents
If we become aware of a security incident affecting your data, we investigate, contain it and notify affected customers and authorities as the law requires.
9. Reporting a vulnerability
Please report security issues to support@lawnise.com with "Security" in the subject.
DOCUMENT HISTORY
Changelog
2 versions · last updated 2026-10-03Start with what fits.
Talk to our team about verifying the AI that answers for your enterprise — request access for a scoped engagement, or book a briefing for a working session.
Scoped access for regulated teams.
For procurement and Enterprise scope.