Built to protect confidential legal information
Legum AI Pak applies modern, enterprise-grade security practices throughout the platform — designed for the sensitivity of legal data.
Last updated: 28 June 2026
Security at a glance
HTTPS/TLS everywhere; HSTS and a strict security-header policy.
Hashed passwords, signed HttpOnly session cookies, optional 2FA.
Role-based access control and per-participant authorisation checks.
Type/size validation, UUID storage, signed downloads, malware-scan hook.
Rate limiting, brute-force lockout and login protection.
Audit logs and activity monitoring for sensitive events.
Platform protections
- HTTPS encryption for all traffic between you and the platform.
- Secure authentication with hashed passwords and signed, HttpOnly, same-site session cookies.
- Password hashing using industry-standard algorithms — credentials are never stored in plain text.
- Role-based access control (RBAC) enforced on pages, actions and APIs.
- Secure sessions with expiry, session management and the ability to log out of all devices.
- Secure file uploads — MIME and extension allowlists, size limits and random storage names.
- Malware-scan hook for uploaded documents before they are made available.
- Secure APIs with request validation, input sanitisation and same-origin (CSRF) protection.
- Rate limiting across sensitive endpoints to prevent abuse.
- Login & brute-force protection with progressive delays and temporary lockout.
- Audit logs & activity monitoring for sensitive administrative and security events.
- Secure infrastructure, regular security updates and dependency checks.
- OWASP practices guiding our defences against the most common web risks.
Strict data isolation
Confidentiality is enforced by design, not just by policy:
- Every user's data is isolated to their own account.
- Lawyers cannot access another lawyer's data.
- Clients cannot access another client's data.
- Administrators cannot view confidential Matter Management conversations, uploaded documents, AI conversations or legal files.
Private AI & Matter Management
AI sessions are isolated per account — no AI conversation is visible to another user, lawyer or administrator. Matter Management workspaces, including documents, milestones, invoices and communications, are accessible only to the assigned client and lawyer.
Identity & account verification
Security starts at the door. Every account is protected by CNIC verification and a minimum age requirement of 18+. Lawyers and law firms complete an admin verification process — including CNIC (front and back), bar council documents and a professional photograph (and, for firms, registration, office proof and the authorized representative's documents) — before they are approved, made public or granted a verified badge.
- CNIC verification and uniqueness checks across the platform.
- Minimum age requirement (18+) enforced at registration.
- Manual admin verification of lawyers and law firms before approval.
- Verification documents are confidential — visible only to the applicant and authorized verification administrators.
Device & session security
Each account may stay signed in on one desktop and one mobile device at a time (maximum two concurrent sessions). Every login generates a trusted device fingerprint from the device type, browser, operating system, approximate location, IP address and login time.
- Device login limits — 1 desktop + 1 mobile; a new device of the same type replaces the old one, which is signed out immediately.
- Session replacement confirmation — you are warned before a login replaces an existing trusted device.
- Suspicious-login detection — new country, distant region, unknown or modified device, or poor IP reputation triggers OTP verification.
- Active Devices & login history — review trusted devices and your recent login events (with status), and sign out any device.
- Secure sessions with inactivity expiry, log-out-of-all-devices, trusted-device removal and forced re-authentication after a password change.
- Security notifications — email and in-app alerts when a device is added or replaced, your password changes, a suspicious login is detected, or all sessions are terminated.
- Account-sharing protection — repeated suspicious activity escalates from warning to temporary login restriction to admin review.
Trust & safety: complaints, warnings & suspensions
A structured complaint workflow lets users report lawyers or clients. Our team reviews complaints, verifies facts, and may issue warnings or apply temporary or permanent suspension for confirmed or repeated violations. A permanently banned CNIC cannot be used to register again.
Fair usage, credits & storage
Subscription plans define AI-credit quotas, lifetime storage limits and fair-usage boundaries. Storage included with a plan (and any purchased add-ons) does not reset on renewal; when the limit is reached, uploads pause with options to free space or buy more lifetime storage.
Secure documents, proposals & invoices
Uploaded documents are validated, stored with randomised names outside public directories, and served only to authorised participants through access-checked, signed downloads. Proposals and invoices are generated within the platform and shared only with the client and assigned lawyer or firm.
Responsible disclosure
If you believe you have found a security issue, please email [email protected] with details. We appreciate responsible disclosure and will investigate promptly.