Trust Center

What we do with your documents, stated plainly

Legal documents are the most confidential material most organisations hold. This page says what happens to them, what we are and are not certified for, and how to run LexCore where nothing leaves your building.

Encryption

AES-256 at rest and TLS 1.3 in transit. Keys are managed per tenant, and document bodies are isolated from tenant metadata.

No training on your data

Your documents are never used to train or fine-tune any model, ours or a provider's. This is a contractual term, not a toggle we could quietly change.

Sovereignty tier

Run the entire pipeline on models inside your environment. Documents are never transmitted. Air-gapped deployments are supported.

What we claim, and what we refuse to claim

Legal AI is sold with a lot of absolutes. Here is the line we hold, published so you can hold us to it.

We say
We never say
Every finding is traced to the exact clause; uncited findings are rejected.
Zero hallucinations. 100% accurate.
NDPR-aware, CAMA-aware, with NG jurisdiction profiles.
NDPR certified.
We measure and document sufficient human supervision per task — auditable.
LAM guarantees correctness.
Run fully on local models; documents never leave your environment.
The cloud tier is on-premises.

Controls in place

Tenant isolation at the storage and index layer
Role-based access with per-matter scoping
Immutable audit trail of every action and override
Configurable retention with hard purge
Residency panel showing active region and egress events
Sub-processor register published and versioned

In progress, and named as such

Independent penetration test — scheduled, report will be published
SOC 2 Type II readiness assessment underway; not yet certified
Case-management RBAC wiring is roadmap
Customer-managed encryption keys, sovereignty tier first
If a control matters to your procurement process and it is on this list rather than the one on the left, tell us — we will give you a date, not a maybe.

Send us your security questionnaire

We answer them directly, in writing, before the commercial conversation. Report a vulnerability to security@lexcore.ng.