Security

Built to protect confidential legal information

Legum AI Pak applies modern, enterprise-grade security practices throughout the platform — designed for the sensitivity of legal data.

Last updated: 28 June 2026

Security at a glance

Encryption & transport

HTTPS/TLS everywhere; HSTS and a strict security-header policy.

Authentication

Hashed passwords, signed HttpOnly session cookies, optional 2FA.

Access control

Role-based access control and per-participant authorisation checks.

Secure file uploads

Type/size validation, UUID storage, signed downloads, malware-scan hook.

Abuse protection

Rate limiting, brute-force lockout and login protection.

Audit & monitoring

Audit logs and activity monitoring for sensitive events.

Platform protections

  • HTTPS encryption for all traffic between you and the platform.
  • Secure authentication with hashed passwords and signed, HttpOnly, same-site session cookies.
  • Password hashing using industry-standard algorithms — credentials are never stored in plain text.
  • Role-based access control (RBAC) enforced on pages, actions and APIs.
  • Secure sessions with expiry, session management and the ability to log out of all devices.
  • Secure file uploads — MIME and extension allowlists, size limits and random storage names.
  • Malware-scan hook for uploaded documents before they are made available.
  • Secure APIs with request validation, input sanitisation and same-origin (CSRF) protection.
  • Rate limiting across sensitive endpoints to prevent abuse.
  • Login & brute-force protection with progressive delays and temporary lockout.
  • Audit logs & activity monitoring for sensitive administrative and security events.
  • Secure infrastructure, regular security updates and dependency checks.
  • OWASP practices guiding our defences against the most common web risks.

Strict data isolation

Confidentiality is enforced by design, not just by policy:

  • Every user's data is isolated to their own account.
  • Lawyers cannot access another lawyer's data.
  • Clients cannot access another client's data.
  • Administrators cannot view confidential Matter Management conversations, uploaded documents, AI conversations or legal files.
Administrators manage, they do not participate
Admin tooling is limited to operational metadata (status, verification, moderation, aggregated analytics). Confidential legal content stays private to the client and the assigned lawyer.

Private AI & Matter Management

AI sessions are isolated per account — no AI conversation is visible to another user, lawyer or administrator. Matter Management workspaces, including documents, milestones, invoices and communications, are accessible only to the assigned client and lawyer.

Identity & account verification

Security starts at the door. Every account is protected by CNIC verification and a minimum age requirement of 18+. Lawyers and law firms complete an admin verification process — including CNIC (front and back), bar council documents and a professional photograph (and, for firms, registration, office proof and the authorized representative's documents) — before they are approved, made public or granted a verified badge.

  • CNIC verification and uniqueness checks across the platform.
  • Minimum age requirement (18+) enforced at registration.
  • Manual admin verification of lawyers and law firms before approval.
  • Verification documents are confidential — visible only to the applicant and authorized verification administrators.

Device & session security

Each account may stay signed in on one desktop and one mobile device at a time (maximum two concurrent sessions). Every login generates a trusted device fingerprint from the device type, browser, operating system, approximate location, IP address and login time.

  • Device login limits — 1 desktop + 1 mobile; a new device of the same type replaces the old one, which is signed out immediately.
  • Session replacement confirmation — you are warned before a login replaces an existing trusted device.
  • Suspicious-login detection — new country, distant region, unknown or modified device, or poor IP reputation triggers OTP verification.
  • Active Devices & login history — review trusted devices and your recent login events (with status), and sign out any device.
  • Secure sessions with inactivity expiry, log-out-of-all-devices, trusted-device removal and forced re-authentication after a password change.
  • Security notifications — email and in-app alerts when a device is added or replaced, your password changes, a suspicious login is detected, or all sessions are terminated.
  • Account-sharing protection — repeated suspicious activity escalates from warning to temporary login restriction to admin review.
Admins see metadata, never content
The admin panel exposes only security metadata — active sessions, device count, login history, failed attempts and suspicious flags. Administrators never access user conversations, Matter Management data, AI history or uploaded documents.

Trust & safety: complaints, warnings & suspensions

A structured complaint workflow lets users report lawyers or clients. Our team reviews complaints, verifies facts, and may issue warnings or apply temporary or permanent suspension for confirmed or repeated violations. A permanently banned CNIC cannot be used to register again.

Fair usage, credits & storage

Subscription plans define AI-credit quotas, lifetime storage limits and fair-usage boundaries. Storage included with a plan (and any purchased add-ons) does not reset on renewal; when the limit is reached, uploads pause with options to free space or buy more lifetime storage.

Secure documents, proposals & invoices

Uploaded documents are validated, stored with randomised names outside public directories, and served only to authorised participants through access-checked, signed downloads. Proposals and invoices are generated within the platform and shared only with the client and assigned lawyer or firm.

Responsible disclosure

If you believe you have found a security issue, please email [email protected] with details. We appreciate responsible disclosure and will investigate promptly.