Security & Data Governance

Privileged material demands more than a checkbox.

LexCor is built from first principles for criminal defence work. Privately deployed AI, UK-hosted infrastructure, and structural governance enforced in the system — not hoped to be followed.

"Your client's most sensitive disclosures, your strategy, your work product — none of it should pass through a public AI service. LexCor was designed from day one so it never has to."— LexCor founding principle
Security architecture

Six structural safeguards. Not policies. Architecture.

The security model is built into the system — not described in a document and hoped to be followed.

Privately deployed AI models

LexCor runs on self-hosted AI models inside your infrastructure. No case data is processed by OpenAI, Anthropic, Google or any public AI provider. Your data stays inside your environment.

End-to-end encryption

All data is encrypted in transit and at rest. Encryption is not optional or configurable — it applies to everything, everywhere, by default, using current cryptographic standards.

Strict tenant isolation

Each firm's deployment is structurally isolated. There is no shared infrastructure between tenants at the data or model layer — another firm's solicitors cannot see your data.

Immutable audit log

Every user action, AI output, document access and system event is written to an immutable, timestamped log. It cannot be edited or deleted — available for SRA audit and internal supervision.

UK GDPR by design

Designed around UK GDPR — data minimisation, purpose limitation, and subject access. Your DPA with Intellectual Bunch Ltd covers the full processor relationship with standard contractual safeguards.

Role & matter-level permissions

Access is controlled at role level and per-matter assignment. Restricted cases and conflicted parties are protected structurally — not by a field in a form that can be overlooked.

Compliance

Built to meet the standards that matter in criminal practice.

Regulatory alignment is designed into the product from the start.

GDPR

UK GDPR alignment

Full compliance with UK GDPR as retained in domestic law post-Brexit. Data processing agreements, legitimate interest assessments, breach notification procedures and SAR workflows are all in scope.

UKGDPR — DPA included
SRA

SRA Standards & Regulations

Designed to support compliance with SRA Standards and Regulations, including client confidentiality, supervision, and the safe use of technology in legal practice.

SRAStandards — aligned
ISO

ISO 27001 roadmap

LexCor operates to ISO 27001 principles as part of our information security management programme. Formal certification is on the roadmap following general availability.

ISO27001 — Principles applied · Cert on roadmap
CE

Cyber Essentials programme

Cyber Essentials certification is targeted for the period leading up to general availability. Infrastructure is currently being assessed against scheme requirements.

NCSCCyber Essentials — In progress
AI governance

The principles behind every AI decision in LexCor.

Each principle is enforced in the system architecture — not a statement of intent.

Always human-in-the-loop

No AI output reaches a court, client or third party without explicit human review. Enforced architecturally.

Transparent operation

Every AI action is logged: prompt, model version, response, and what the human reviewer did with the output.

Configurable trust boundaries

Firms configure which workflows are AI-assisted. AI is never on by default in any sensitive process.

No cross-firm AI training

Your case data trains nothing. Models are private, isolated, and never used to improve capabilities for other firms.

Governed by design

Trust built into every layer.

Request early access and see how LexCor handles your firm's data — transparently, privately and auditably.