Skip to content

Security

Built with serious practices in mind.

Legal data carries obligations. Lexora is designed so firm data stays separated, financial actions are controlled, and the record of what happened is kept.

Tenant isolation

Every record is scoped to the firm and enforced in the database, not only in the interface.

Role-based permissions

What a person can see and do follows their role in the firm.

Multi-factor authentication

MFA is supported for accounts that require a second factor.

Audit trails

Sensitive actions — particularly financial and trust actions — are written to an insert-only log.

Encrypted connections

Traffic between the browser and the platform is encrypted in transit.

Secure OAuth integrations

Provider connections use the provider's own authorisation; credentials are stored encrypted.

Controlled financial permissions

Trust and billing actions are permission-gated and support maker-checker separation.

Backup architecture

Matter documents can be backed up to the firm's own cloud storage.

Lexora does not currently hold ISO 27001, SOC 2 or Australian government security accreditation, and no such certification is claimed. Firms should assess these controls against their own professional, privacy and client obligations.

Review Lexora with your own checklist.

We are happy to walk through the platform's security model, permissions and audit behaviour with your firm.