Security
Built with serious practices in mind.
Legal data carries obligations. Lexora is designed so firm data stays separated, financial actions are controlled, and the record of what happened is kept.
Tenant isolation
Every record is scoped to the firm and enforced in the database, not only in the interface.
Role-based permissions
What a person can see and do follows their role in the firm.
Multi-factor authentication
MFA is supported for accounts that require a second factor.
Audit trails
Sensitive actions — particularly financial and trust actions — are written to an insert-only log.
Encrypted connections
Traffic between the browser and the platform is encrypted in transit.
Secure OAuth integrations
Provider connections use the provider's own authorisation; credentials are stored encrypted.
Controlled financial permissions
Trust and billing actions are permission-gated and support maker-checker separation.
Backup architecture
Matter documents can be backed up to the firm's own cloud storage.
Lexora does not currently hold ISO 27001, SOC 2 or Australian government security accreditation, and no such certification is claimed. Firms should assess these controls against their own professional, privacy and client obligations.
Review Lexora with your own checklist.
We are happy to walk through the platform's security model, permissions and audit behaviour with your firm.